ASI Alliance & SingularityNET Hack
What happened
On September 19–20, 2026, an attacker used compromised SingularityNET bridge and NuNet deployer private keys to drain $FET and mint unauthorized supplies of $AGIX,$NTX, $WMTx, and $CGV on Ethereum. The attacker extracted ~$1.44M to $1.67M in liquid ETH before project teams paused bridges and revoked minting authorities.
The exploit resulted from compromised private signing keys rather than smart contract logic bugs. On September 19, the attacker called conversionIn on Fetch.ai's TokenConversionManagerV3 using a stolen SingularityNET authorizer signature to drain 8.72M $FET (~$1.53M) and swap it for ETH. Minutes later, a compromised NuNet deployer account minted 408.53M $NTX to reach its 1 billion supply cap.
On September 20, the attacker used the SingularityNET bridge authority to mint 260M $AGIX, 53.84M $WMTx, and ~500M$CGV. High slippage on low liquidity pools limited total extracted value to 546–649 ETH (~$1.44M–$1.67M), while token market prices collapsed by 65% to 99%. Affected protocols responded by pausing bridges, revoking signing authorities, and contacting exchanges to freeze funds.
Attacker Address: 0x2dcc1085…c21dfE
NuNet Deployer Address: 0x863F13e5…092165
Fetch.ai Conversion Contract: 0xab424A43…ADF3A3
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.