-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0171 ============================================================ Advisory-ID: 0xCERT-2026-0171 Severity: Critical Published: 2026-09-19T00:00:00.000Z Updated: 2026-10-08T22:46:35.791Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0171 Title: ASI Alliance SingularityNET Bridge Key Compromise Summary - ------- A compromised bridge signing key let an attacker drain FET and mint AGIX, NTX and WMTx across the ASI Alliance's Ethereum token-conversion contracts, amassing roughly $16.77 million in tokens. Details - ------- Summary A compromised bridge signing key let an attacker drain FET and mint AGIX, NTX and WMTx across the ASI Alliance's Ethereum token-conversion contracts, amassing roughly $16.77 million in tokens. Incident - - Victim: ASI Alliance - - Date (UTC): 2026-09-19 - - Estimated loss: $16.8M - - Chain(s): Ethereum - - Attack type: bridge exploit - - Funds status: stolen Recommended actions - - Revoke token approvals granted to ASI Alliance contracts until the project confirms they are safe - - Integrators: pause or delist affected assets and monitor for attacker fund movements - - Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only Source & attribution Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/asi-alliance-2026. Primary sources: https://mpost.io/key-compromise-behind-fetch-ai-linked-bridge-attack-drives-losses-to-16-77m/ ; https://www.kucoin.com/blog/en-fetch-ai-fet-exploit-1-56m-drained-from-token-converter-after-signing-key-compromise ; https://www.cryptotimes.io/2026/09/21/singularitynet-bridge-hack-widens-260m-agix-53-8m-wmtx-minted-16-77m-held-by-attacker/. References - ---------- - - https://www.blockchainbreaches.com/en/breaches/asi-alliance-2026 - - https://mpost.io/key-compromise-behind-fetch-ai-linked-bridge-attack-drives-losses-to-16-77m/ - - https://www.kucoin.com/blog/en-fetch-ai-fet-exploit-1-56m-drained-from-token-converter-after-signing-key-compromise - - https://www.cryptotimes.io/2026/09/21/singularitynet-bridge-hack-widens-260m-agix-53-8m-wmtx-minted-16-77m-held-by-attacker/ Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRhIJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmeXPA0RlSkn5lydyVmlcIefoS8BuI2NcdgdlFIo satxmBYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAAC0RQEAhg7HmCAhNjUSA0N/ lRN770+E9GjZ2HbcsuB/4iuifJoA/iWG5xQSv+NMBduQS5rr03XG7rnODBc+ 7Ej5T0lB0NgN =lTIN -----END PGP SIGNATURE-----