Fetch.ai (FET) Exploit: $1.56M Drained From Token Converter After Signing Key Compromise

The Fetch.ai FET exploit has put renewed attention on crypto bridge security after approximately $1.56 million in FET was removed from an Ethereum-based token conversion contract on September 19, 2026. The incident began with the withdrawal of about 8.72 million FET before expanding into unauthorized activity involving NTX, AGIX, WMTx and CGV. On-chain investigations linked the wider event to compromised authorization infrastructure used across interconnected token migration and bridge systems. Readers following the token after the security incident can monitor current FET price and market data alongside updates from the projects involved.
The attack did not amount to a compromise of every FET token or the underlying Fetch.ai network. Instead, it exposed the risks created when privileged signing credentials control access to large token balances held by migration or bridge contracts. That distinction matters because the attacker appears to have used trusted authorization rather than breaking Fetch.ai's consensus mechanism or directly accessing ordinary user wallets. The investigation therefore centers on how the privileged credentials were compromised, how much value the attacker was actually able to realize, and what security changes may follow across the broader Artificial Superintelligence Alliance ecosystem.
What Happened in the Fetch.ai FET Exploit?
The Fetch.ai FET exploit occurred on September 19, 2026, when an attacker withdrew approximately 8,721,530 FET from the TokenConversionManagerV3 contract on Ethereum. The tokens were valued at roughly $1.53 million to $1.56 million at the time, making the transaction the clearest direct financial loss associated with the initial stage of the incident. On-chain analysis placed the main withdrawal at around 20:21 UTC, after which the stolen FET was rapidly swapped for approximately 523 ETH. The speed of the transfer and conversion increased the difficulty of containing the loss because much of the directly stolen FET had already been moved before affected infrastructure could be restricted.
The security incident soon extended beyond that original transaction. Investigators connected the same attack cluster to unauthorized token activity involving NuNet's NTX, SingularityNET's AGIX, World Mobile's WMTx and Cogito's CGV, turning what initially looked like an isolated FET converter exploit into a broader multi-token security event. The wider pattern pointed toward shared or connected bridge, conversion and authorization infrastructure rather than an issue limited to one token contract. Several migration and bridge functions were subsequently restricted while teams reviewed privileged permissions, compromised credentials and the scope of the unauthorized transactions.
How a Signing Key Compromise Drained $1.56M in FET
The $1.56 million FET drain appears to have involved compromised privileged signing infrastructure rather than an attack on individual FET holders. The attacker was able to submit a transaction carrying authorization that the conversion contract recognized as legitimate, allowing a large FET balance to leave the contract without the transaction appearing invalid at the smart-contract level. This distinction shifts the security focus away from ordinary token transfers and toward the mechanisms used to approve high-privilege conversion requests. It also helps explain why the incident is more accurately described as a signing-key or authorization compromise than a direct hack of the Fetch.ai blockchain.
Compromised Authorization
The attacker interacted with the TokenConversionManagerV3 conversionIn() function using a valid authorization signature, allowing approximately 8.72 million FET to leave the contract in a single transaction. Because the request contained credentials that the system recognized, the contract processed it instead of rejecting it as unauthorized. Preliminary security analysis linked the activity to a compromised bridge authorizer key associated with SingularityNET infrastructure, although blockchain records alone cannot reveal exactly how the attacker obtained control of that credential. Determining whether the key was exposed through an off-chain system, operational mistake or another compromise requires information beyond the on-chain transaction history.
The incident demonstrates why private key security becomes especially important when privileged credentials control smart-contract functions holding significant token balances. A compromised signer can allow malicious activity to appear technically valid because the transaction carries the same cryptographic authorization expected from a legitimate operator. In this case, the underlying blockchain continued processing transactions normally while the vulnerable point was the authorization infrastructure controlling the converter. That separation is essential for understanding why ordinary FET transfers were not equivalent to the compromised conversion mechanism.
Signing-Key Security
A privileged signing key effectively forms part of a smart contract's security perimeter. If an attacker gains control of such a credential, malicious instructions can potentially look identical to legitimate requests from the perspective of the contract. This creates a different type of security risk from a traditional smart-contract bug because the attacker may not need to manipulate the code itself. Instead, gaining access to the trusted signing process can provide a direct route to functions that were intentionally designed to move or release tokens.
The exploit therefore reinforces the importance of multi-party authorization, hardware-backed key storage, withdrawal limits, key rotation and real-time monitoring of privileged transactions. Additional controls can make it harder for a single compromised credential to authorize unusually large transfers without further verification. For bridge and token migration operators, limiting the authority of individual keys and monitoring abnormal transaction sizes can reduce the impact of a compromise even if one component of the signing infrastructure fails. These measures are particularly relevant for contracts that regularly hold large token balances on behalf of migration or interoperability systems.
How the Attack Spread to AGIX, NTX, WMTx and Other ASI Tokens
The Fetch.ai exploit expanded into a broader multi-token security incident shortly after the initial FET withdrawal. Cross-chain analysis tracked approximately 2.31 billion token units that were either drained or created without authorization across FET, NTX, AGIX, WMTx and CGV. The growing list of affected assets showed that the attack was not limited to one token converter and instead involved infrastructure capable of interacting with multiple projects. This wider scope made the event relevant to users following the Artificial Superintelligence Alliance ecosystem as well as the security of cross-chain token migration systems more generally.
Unlike the FET transaction, which involved existing tokens already held inside a converter, much of the later activity involved unauthorized token creation or conversion. That difference is important when comparing loss estimates because newly created supply does not automatically translate into an equal amount of cash that an attacker can realize. Several of the affected tokens traded in relatively thin markets, meaning that attempting to sell very large balances could rapidly push prices lower. As a result, the nominal value of the unauthorized tokens was much higher than the amount that could realistically be converted into liquid assets.
NTX
NuNet's NTX was among the first assets affected after the FET withdrawal. On-chain analysis recorded approximately 408.53 million NTX created in a single minting transaction less than 30 minutes after the main FET drain. The abrupt increase in available supply placed severe pressure on NTX liquidity and helped push early estimates of the combined incident toward roughly $2 million when the FET loss and NTX activity were considered together. The close timing between the two events also strengthened the case that they formed part of the same broader attack sequence rather than unrelated exploits.
The NTX episode also demonstrates why token supply and realized losses must be analyzed separately. Multiplying hundreds of millions of unauthorized tokens by a pre-attack market price can produce a very large theoretical figure, but that calculation assumes buyers are available at the same price for the entire supply. In a thin market, aggressive selling can rapidly exhaust liquidity and push the token price lower. For that reason, the amount of NTX created without authorization should not automatically be treated as cash successfully stolen by the attacker.
AGIX
SingularityNET's AGIX became another major part of the wider incident as investigators traced unauthorized activity across additional networks and contracts. Broader cross-chain analysis attributed approximately 895.96 million AGIX to unauthorized conversion activity, while earlier Ethereum-focused observations captured smaller amounts at earlier stages of the investigation. These different figures reflect variations in chain coverage, timing and methodology rather than necessarily representing contradictory reports. The evolving numbers demonstrate how the estimated size of a cross-chain exploit can change as analysts identify additional transactions.
The AGIX activity also placed greater scrutiny on AGIX-to-FET conversion infrastructure, which was paused while teams investigated the affected systems. That operational response was significant for users participating in the wider ASI token migration because normal conversion routes were disrupted even though ordinary FET ownership was not directly compromised. The pause also provided investigators with time to review signer permissions and determine whether compromised authorization could be reused against other contracts. Restoring those services securely will depend on confidence that vulnerable credentials and permissions have been replaced or revoked.
WMTx
The attack also affected World Mobile's WMTx infrastructure, adding another token to the expanding list of unauthorized activity connected to the incident. Broader cross-chain analysis tracked approximately 500.48 million WMTx, while earlier Ethereum-focused snapshots captured smaller amounts before investigators had reconstructed the full sequence. The difference illustrates why initial hack reports often change as more chains and transactions are reviewed. Cross-chain incidents can involve hundreds of transactions across different systems, making early estimates inherently incomplete.
The WMTx activity further highlights the gap between nominal token value and realizable value. Large attacker-controlled balances may appear extremely valuable when measured using a market price from before the exploit, but those prices assume normal liquidity conditions. Selling hundreds of millions of newly created tokens can overwhelm available buyers and drive the market sharply lower, reducing the proceeds available from each additional sale. This liquidity effect is one of the main reasons later headline valuations should not be treated as equivalent to confirmed financial losses.
CGV
Approximately 492.4 million CGV linked to Cogito was also included in the broader on-chain reconstruction. Its inclusion showed that the compromised authorization infrastructure could affect several interconnected assets rather than remaining isolated to one migration contract or project. The additional token activity expanded the scope of the investigation and increased pressure on connected projects to review signer permissions, token conversion mechanisms and cross-chain access controls. It also demonstrated how a compromise at the infrastructure level can create risks across multiple assets even when each underlying blockchain continues operating.
Taken together, the FET drain and unauthorized activity involving NTX, AGIX, WMTx and CGV illustrate why weaknesses in a blockchain bridge or migration system can create risks that extend well beyond one token. Cross-chain systems often depend on privileged components that authorize transfers or token issuance between networks, making those components attractive targets for attackers. The incident therefore places broader attention on signer design, permission management, transaction limits and the safeguards used to verify that cross-chain conversion requests correspond to legitimate activity.
How Much Was Really Lost in the Fetch.ai Hack?
The amount lost in the Fetch.ai hack depends on which part of the incident is being measured. The clearest direct figure is approximately $1.53 million to $1.56 million, representing the 8.72 million FET removed from TokenConversionManagerV3. Early reporting later pushed the estimated impact toward roughly $2 million after including unauthorized NTX activity and other early components of the attack. Broader on-chain analysis subsequently tracked hundreds of ETH in proceeds from sales involving multiple affected tokens, showing that the incident had grown beyond the initial FET transaction.
A later reconstruction estimated around $2.25 million in realized or liquid value across tracked attacker wallets at one point in the investigation. By contrast, some reports placed the attacker's holdings at approximately $16.77 million after large amounts of unauthorized AGIX, WMTx and other assets were included at quoted market prices. That larger figure represented a nominal valuation rather than confirmed cash profit, because available market liquidity could not necessarily support selling the full token balances at those prices. For readers comparing Fetch.ai exploit figures, the key distinction is therefore between the $1.56 million direct FET drain, the roughly $2 million early multi-token estimate, about $2.25 million in tracked liquid or realized value, and much larger theoretical valuations of unauthorized token holdings.
FET Security After the Exploit and What Comes Next
The exploit raised concerns about FET security, token migration and ASI Alliance bridge infrastructure, but available information does not indicate that the underlying Fetch.ai network was broadly compromised. The incident was concentrated around specific conversion, authorization and bridge systems rather than the normal operation of the token itself. FET continued to operate while teams restricted affected migration routes and investigated privileged credentials connected to the wider attack. This distinction is important for separating infrastructure risk from the security of ordinary token balances.
The longer-term significance of the event will depend on the final technical findings and how the affected projects strengthen their bridge and key-management architecture. Investors and token holders will be watching for evidence that compromised permissions have been revoked, vulnerable contracts have been upgraded and migration functions can safely resume. Any detailed post-mortem will also be important for establishing exactly how the signing infrastructure was compromised and whether the incident exposed weaknesses that could affect other connected systems. Until then, some aspects of the root cause remain preliminary.
FET Holder Security
The approximately 8.72 million FET involved in the exploit already existed inside the converter. The attacker did not create billions of new FET in the way unauthorized token supply appeared for several of the other affected assets. There is also no evidence that the incident broadly altered balances held in unrelated personal wallets or compromised normal transactions across the Fetch.ai network. This makes the security impact different from an exploit that directly targets user accounts or changes the underlying token supply.
FET holders should nevertheless continue following official notices covering bridge availability, token migration and exchange operations because those services can be restricted even when the underlying token remains functional. Traders monitoring how new security updates affect market conditions can also follow the FET/USDT trading market alongside official project announcements. Users should remain particularly cautious of fake recovery services, phishing links and unofficial migration instructions, as major crypto security incidents often create opportunities for secondary scams targeting concerned holders.
ASI Recovery
The next stage for Fetch.ai, SingularityNET and other affected projects centers on securing bridge infrastructure, replacing or revoking compromised credentials and reviewing privileged contract permissions. Precautionary restrictions on migration and bridge functions can help contain further exposure while investigators determine exactly which systems were affected. Teams may also need to review whether authorization models rely too heavily on individual signing keys and whether additional controls are required before cross-chain services can safely resume.
Attention will also focus on AGIX-to-FET migration, bridge restoration, key-management changes, smart-contract audits, asset recovery and a final security post-mortem. On-chain data can show which transactions occurred, which contracts were called and where funds moved, but determining exactly how a privileged signing key was obtained requires additional investigation beyond blockchain records. A detailed final report will therefore be important for establishing the root cause, explaining remediation measures and restoring confidence in the affected cross-chain infrastructure. The effectiveness of those changes will likely shape how the incident is viewed over the longer term.
-
One account for everything. Older platforms split your money across separate "spot," "margin," and "futures" accounts and expected you to understand why. KuCoin 5.0's unified account removes that entirely — deposit once, and everything is simply there.
-
Stocks, indices, and commodities. KuCoin 5.0 expands beyond crypto into global markets. When crypto chops sideways and equities rally (or the reverse), you rotate in minutes instead of opening a brokerage account and waiting days for fiat rails.
-
Real-world assets (RWA). Tokenized exposure to traditional assets like commodities, right inside your crypto account. One of the fastest-growing segments in global finance is no longer reserved for institutions — you access it from the same balance you trade with.
-
Earn while you learn. Not ready to trade? KCUSD lets your stablecoins earn daily, auto-compounding interest. The lowest-stress way to put your idle deposit to work for 4% yield.
-
An AI assistant in plain language. Ask questions, get market context, understand what you're looking at — built into the platform, no jargon required.
-
An app that doesn't overwhelm. Faster, cleaner, and consistent — intuitive from the first tap, not after a tutorial.
-
Safety you can check, not just trust. A MiCAR-licensed EU entity, Proof of Reserves you can verify yourself, and internationally certified security (SOC 2 Type II, ISO 27001:2022).
Conclusion
The Fetch.ai FET exploit began with the withdrawal of approximately 8.72 million FET worth about $1.56 million from an Ethereum token converter and later expanded into unauthorized activity involving NTX, AGIX, WMTx and CGV. The evidence points toward compromised privileged authorization rather than a failure of the Fetch.ai blockchain itself, showing how control of a trusted signing credential can expose bridge and migration infrastructure even when the underlying network remains operational. The wider incident also demonstrates how interconnected token systems can amplify the impact of a single authorization failure across several assets and chains.
The attack also shows why crypto exploit figures require careful interpretation. Directly stolen assets, realized proceeds and the nominal value of unauthorized token supply are different measurements, especially when affected markets have limited liquidity. For Fetch.ai and the broader ASI ecosystem, the next important developments will be the final investigation, stronger key-management controls, restoration of migration services and any further information about asset recovery. Those updates will provide a clearer picture of both the financial impact and the long-term security implications of the incident.
FAQs
1. When did the Fetch.ai FET exploit happen?
The main FET withdrawal occurred on September 19, 2026, at approximately 20:21 UTC on Ethereum. Investigators later identified additional unauthorized activity involving NTX, AGIX, WMTx and CGV as they reconstructed the wider attack across connected infrastructure. The incident therefore developed from a single high-value FET transaction into a broader multi-token security investigation.
2. How much FET was stolen in the Fetch.ai exploit?
Approximately 8.72 million FET was removed from the TokenConversionManagerV3 contract. The tokens were valued at roughly $1.53 million to $1.56 million at the time and were subsequently exchanged for approximately 523 ETH. This direct FET loss should be distinguished from larger estimates that include unauthorized activity involving other tokens.
3. Was the Fetch.ai blockchain itself hacked?
Available evidence does not indicate that the underlying Fetch.ai blockchain was compromised. The incident centered on Ethereum-based conversion, bridge and privileged authorization infrastructure rather than the normal operation of the Fetch.ai network. The attacker appears to have abused credentials trusted by specific contracts instead of breaking the blockchain's consensus mechanism.
4. Did the attacker create new FET tokens?
No. The 8.72 million FET involved in the exploit already existed inside the conversion contract and was transferred out. This differs from the unauthorized activity involving NTX, AGIX, WMTx and CGV, where large amounts of token supply were created or released through compromised infrastructure. That difference is important when comparing the financial impact across the affected assets.
5. Why do Fetch.ai hack loss estimates range from $1.56M to $16.77M?
The figures measure different parts of the incident. $1.56 million refers to the direct FET drain, roughly $2 million was an early estimate that included additional token activity, and around $2.25 million represented tracked liquid or realized value at one stage. The much larger $16.77 million figure represented a nominal valuation of attacker-controlled token holdings rather than confirmed realized profit, meaning it should not be interpreted as the amount successfully cashed out.
6. Were personal FET wallets affected?
There is no evidence that the incident broadly drained ordinary FET holders' wallets. The attacker targeted specific conversion, bridge and authorization infrastructure rather than normal FET balances. Users should still monitor official migration and exchange notices because operational restrictions can continue while security teams review affected systems and restore services.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment or trading advice. Crypto assets are volatile, and readers should conduct their own research before making financial decisions.
