A Dormant Key Minted 42% of NuNet's Supply 29 Minutes After a $1.55M FET Drain
Two compromised keys, one receiving wallet, and a signed message that trusted the caller a little too much. The Sept. 19 bridge attack cost roughly $1.55 million in FET, but the 408.5 million NTX created 29 minutes later is the number that actually matters for anyone holding the ASI stack.
Someone minted 42% of NuNet's documented supply in a single transaction, and it took 29 minutes to connect that mint to a $1.55 million bridge drain sitting in the very same wallet.
The Sept. 19 operation wasn't one exploit. It was two compromised credentials, one receiving address, and a signed authorization that the contract trusted a little too much.
The Trail, Read Backward
Forensics like this always start at the money and walk upstream. At 19:36 UTC, 45 minutes before anything drained, the NuNet minter sent 0.3667 ETH straight to the wallet that would later collect the stolen FET. A separate attacker-linked account pushed 24.3 million NTX into that same address around the same time. And NTX sales through MetaMask's swap router were already firing before the bridge got touched.
So the operation was live well before the headline theft. That sequencing matters.
Then, 29 minutes before the mint, 8,721,530 FET left SingularityNET's Ethereum-side conversion contract. About $1.55 million at spot. The contract, TokenConversionManagerV3, is the legitimate lock-and-release piece of SingularityNET's bridge, and its verified source matches the public repository. No attacker bypassed anything. A valid signature from an address the contract was configured to trust simply told itsconversionInfunction to release the entire FET balance to a wallet the caller chose.
At 20:50 UTC, the NuNet minter woke up and created 408,532,878 NTX. That key hadn't moved since March 2023. Roughly 42% of NuNet's documented supply, into the same receiving address as the FET.
Then the attacker started selling. The FET went through MetaMask's swap infrastructure, mostly into ETH. Over 217 million NTX hit decentralized liquidity venues. By 1:10 UTC on Sept. 20, the central wallet held 547.89 ETH, worth about $1.44 million, plus another 230 million NTX.
Then liquidity became the wall. Four later sales totaling 38.55 million NTX added only about 0.30 ETH to the attacker's balance. A 10 million NTX route through Mayan Protocol produced roughly 940 USDT. That's a dumping operation running out of buyers in real time.
The disruption spilled past FET and NTX too. Bitvavo suspended WMTX deposits and withdrawals on Sept. 20 after flagging an active security incident, then halted trading. The exchange said customer balances stayed safe, and the available forensics don't establish that WMTX was hit through the same mechanism. Fetch.ai paused AGIX-to-FET conversions and its Ethereum-side bridge as a precaution, while noting the affected infrastructure belonged to SingularityNET and that its own contracts kept running.
The Dollar Figure Is the Wrong Scoreboard
$1.55 million is a rounding error for this market. So if that's your takeaway, you're reading the wrong number.
The real damage is the mint. A governance key that had authority to create 408.5 million tokens sat dormant for two and a half years and still worked. That's not a sophisticated exploit. That's a housekeeping failure with a nine-figure blast radius, and it tells you something uncomfortable about how many protocols are one forgotten credential away from a supply shock.
The contract design makes it worse. The 1 million FET transaction cap applied to tokens moving out of Ethereum but wasn't enforced onconversionIn. So the cap guarded the door nobody was kicking down. What's the point of a withdrawal limit that doesn't apply to the function that actually moves the funds? And the signed message never bound the eventual recipient, which means a legitimate authorization could point the tokens anywhere the caller wanted. Two checklist items, both missed.
The skew tells a different story than the spot print. Bridge risk in this part of the market trades like a non-directional event, not a directional one, so the positioning read is less about FET falling and more about vol repricing across the whole alliance complex. Under neutral conditions, a signed-withdrawal exploit usually doesn't move funding much. It moves the term structure.
Here's my bigger gripe. This wasn't a novel attack surface. Compromised backend authorizer keys are the most predictable failure mode in bridge design, and the industry keeps rebuilding the same single point of trust. Every bridge that leans on one signature is, effectively betting on one key never leaking.
Then there's the remediation question. The first tracking window found both the FET bridge authorizer and the NuNet minter credentials hadn't been rotated or revoked roughly five hours after the attack, with the FET contract already empty. Refilling that conversion contract while the same authorizer stays trusted isn't fixing anything. It's reloading an ATM.
What to Watch
Three concrete markers will settle whether this gets contained or compounds.
First, credential rotation. You can't restart the FET bridge safely until the authorizer that signed the malicious transaction is dead and replaced. Same for the NuNet wallet with mint authority. Nothing else matters until that's done.
Second, Fetch.ai's AGIX-to-FET conversion service and its Ethereum-side bridge. Those are the clearest operational signals of restored confidence.
Third, Bitvavo's WMTX trading and transfers, which stay restricted while the exchange assesses the incident.
The honest read is that the market has seen dozens of these and prices them fast. The harder damage is structural. A dormant mint key that still carried authority is a proxy for sloppy key management across the whole alliance, and that's the kind of thing institutions quietly reprice into their cost basis. Professional traders are pricing in the remediation now, not the hack. Watch whether the authorizer key gets replaced before any liquidity returns. That's the whole trade.
Key Terms Explained
An Ethereum Layer 2 that offers native yield on ETH and stablecoins deposited on the chain.
A protocol that lets you move tokens between different blockchains.
The original price you paid for an asset, including fees.
Not controlled by any single entity, authority, or server.