ASI Alliance SingularityNET Bridge Key Compromise
A compromised bridge signing key let an attacker drain FET and mint AGIX, NTX and WMTx across the ASI Alliance's Ethereum token-conversion contracts, amassing roughly $16.77 million in tokens.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
A compromised bridge signing key let an attacker drain FET and mint AGIX, NTX and WMTx across the ASI Alliance's Ethereum token-conversion contracts, amassing roughly $16.77 million in tokens.
Incident
- Victim: ASI Alliance
- Date (UTC): 2026-09-19
- Estimated loss: $16.8M
- Chain(s): Ethereum
- Attack type: bridge exploit
- Funds status: stolen
Recommended actions
- Revoke token approvals granted to ASI Alliance contracts until the project confirms they are safe
- Integrators: pause or delist affected assets and monitor for attacker fund movements
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/asi-alliance-2026. Primary sources: https://mpost.io/key-compromise-behind-fetch-ai-linked-bridge-attack-drives-losses-to-16-77m/ ; https://www.kucoin.com/blog/en-fetch-ai-fet-exploit-1-56m-drained-from-token-converter-after-signing-key-compromise ; https://www.cryptotimes.io/2026/09/21/singularitynet-bridge-hack-widens-260m-agix-53-8m-wmtx-minted-16-77m-held-by-attacker/.
References
- https://www.blockchainbreaches.com/en/breaches/asi-alliance-2026
- https://mpost.io/key-compromise-behind-fetch-ai-linked-bridge-attack-drives-losses-to-16-77m/
- https://www.kucoin.com/blog/en-fetch-ai-fet-exploit-1-56m-drained-from-token-converter-after-signing-key-compromise
- https://www.cryptotimes.io/2026/09/21/singularitynet-bridge-hack-widens-260m-agix-53-8m-wmtx-minted-16-77m-held-by-attacker/
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-19 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0171/signed.txt | gpg --verify