< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Fetch.ai-linked bridge exploit causes $16.77M in losses

A compromised signing key linked to the Fetch.ai and SingularityNET bridge has resulted in losses exceeding $16.77 million. On September 19, 2026, attackers exploited the TokenConversionManagerV3 contract, which serves as the Ethereum-side component of the official bridge connecting Ethereum and Cardano.

On-chain analysis indicates that a single authorized call to the conversionIn function allowed an attacker to drain approximately 8.72 million FET, valued at roughly $1.55 million. The transaction was validated by a legitimate cryptographic signature from the bridge’s conversion authorizer, suggesting the breach occurred within the signing service or key custody rather than through a flaw in the contract code itself.

Two specific design weaknesses exacerbated the impact: the conversionIn function lacked per-conversion limits, and the signed digest did not bind the recipient address, allowing a valid signature to be used for any destination. Following the FET drain, the same wallet received 408.5 million newly minted NTX tokens—representing about 42% of NuNet’s total supply—using a minter key that had been dormant since March 2023.

Entities

Cardano · Ethereum · Fetch.ai · NuNet · SingularityNET