EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Fetch.ai bridges vulnerabilities: What FET, AGIX and NTX holders must now check

2026-09-24 00:15:23
Bookmark

Note to investors who hold FET, AGIX or NTX: Two things need to be clearly distinguished

If you hold FET, AGIX or NTX, there are two key facts that need to be clarified at this time: The tokens in your wallet have not been attacked. What was attacked was a cross-chain bridge (Bridge) used to convert old AGIX positions into FETs. Since September 19, this conversion feature has been frozen, and any user who attempts to do this cannot complete the transaction.

On the evening of September 19, 2026, the TokenConversionManagerV3 contract on Ethereum was hacked and all FET liquidity was cleared. Within hours, hundreds of millions of tokens belonging to three other projects were minted at the same address. The following is a summary of events based on verifiable data and their implications for German investors.

What happened to TokenConversionManagerV3 on September 19

TokenConversionManagerV3 is the core component of the official SingularityNET Cross-Chain Bridge on the Ethereum side. Cross-chain bridges are a contractual mechanism that collects tokens on one chain and releases an equal amount of corresponding tokens on another chain. The bridge protocol connects Ethereum and Cardano, and also serves the function of converting the old version of AGIX into FET.

Based on existing on-chain data analysis, the attacker called the conversionIn function once at 20:21:47 UTC (block height 26,013,913) and paid 8,721,530.40 FETs to the controlled address. According to estimates from different sources, its value is approximately US$1.53 million to US$1.55 million. Less than half an hour later, at 20:50:11 UTC, the attacker minted another 408.53 million NuNet project tokens NTX, reportedly worth approximately US$462,730.

One of the key points in interpreting this incident is that no user wallets were cracked and no mnemonic words were leaked. The attacker used a valid authorization signature. Analytics firm SlowMist pointed out that the infrastructure's signature keys have been compromised.

Why a single signature can cause damage: Vulnerability in the conversionIn() function

The technical core is worth understanding in brief, because such problems are common in cross-chain bridges. According to SlowMist's analysis, the conversionIn() function only accepts the signature of a single external account as a basis for authorization. The so-called externally Owned account (EOA) is a common address with a unique private key. From the perspective of the contract, the person holding the private key is the legal counterparty.

The second point that causes the loss to expand is that the corresponding conversion output function conversionOut() has an amount upper limit check, but conversionIn() does not. Therefore, there is no limit for a single call. The leakage of the key and the lack of amount verification resulted in the loss of funds in one step.

这与之前的案例极为相似。今年夏天 Arbitrum 上发生的两起永续合约去中心化交易所(DEX)事件中,决定性因素同样是“谁掌握了密钥”,而非协议是否自称去中心化。只要存在单一的信任假设,一个原本构建良好的系统就可能在一击之下崩塌。

未经授权铸造:4.08亿 NTX、2.6亿 AGIX 和 5380万 WMTx

9月20日,事件范围进一步扩大。据 PeckShield 报道,同一地址还在以太坊上额外铸造了 2.6 亿枚 AGIX 和 5383.8 万枚 WMTx。WMTx 是 World Mobile Chain 的代币;该项目已确认 WMTx 是通过 SingularityNET 桥接协议未经授权的铸造行为。

截至 UTC 时间 9月20日 09:21,PeckShield 估计攻击者集群持有的资产总值约为 1677 万美元。具体构成如下:约 1.983 亿枚 AGIX(价值约 1442 万美元)、649 枚 Ether(价值约 167 万美元)以及 3353.8 万枚 WMTx(价值约 627,350 美元)。同一天 Bitquery 在 UTC 时间 17:20 的分析显示,AGIX、NTX、CGV 和 WMTx 合计未经授权的铸造总量约为 23 亿单位。

The difference between these two numbers is not a contradiction, but a result of different measurement standards. US$16.77 million is the market value at a given moment; while 2.3 billion is the number of tokens. The increase in the number of tokens out of thin air means the same thing for all existing holders: their share of the total supply shrinks overnight. Unauthorized coins minted have no value support and will dilute all existing positions.

What measures has Fetch.ai taken: Suspend AGIX to FET and Ethereum bridging services

According to Fetch.ai's official instructions, they have activated two measures: first, suspend AGIX to FET services indefinitely; second, suspend the bridging services on the Ethereum side for preventive purposes, and stated that there was no indication that there was a loophole in its own contract. After coordinating with SingularityNET, the affected wallets and contracts have been disabled.

The actual impact of

on you is that if you still have an old version of AGIX and have not yet converted to FET, you cannot currently perform this operation. Officials have not announced a specific date for the reopening of the conversion. Those who view deadlines as unlimited should start paying close attention to the process rather than waiting passively.

Are you affected? Five-step self-examination of wallet and exchange status

The honest answer for most people is that it may not be directly affected. In the narrow sense, what is affected is bridging liquidity, not your positions. Even so, there are still five things you can verify in minutes:

  1. Verify the tokens you actually hold: FET、AGIX、NTX、WMTx 和 CGV 是本次涉及的代币。如果您的持仓中不包含上述任何一种,那么此次事件对您而言只是一次警示,而非直接影响。
  2. 检查是否有待完成的转换:如果您持有尚未兑换为 FET 的 AGIX,目前该兑换通道已关闭。
  3. 查看交易所状态:发生此类事故后,交易平台通常会暂停个别代币的充值和提现。这通常显示在提供商的状态公告中,而非价格窗口内。
  4. 撤销旧的授权批准:如果您曾授予桥接合约无限的代币授权额度,建议立即审查并撤销。无论是否发生此次事故,这都是良好的安全实践。
  5. 警惕钓鱼诈骗:每次重大事故后都会伴随虚假的退款表格和所谓的客服渠道。任何 reputable(信誉良好)的项目都不会通过私信要求您输入助记词或连接钱包以进行退款。

FET、NTX 和 WMTx 的价格反应:数据说明了什么

各代币的价格反应截然不同,这种差异具有指示意义。FET 在资金被盗时交易价格接近 0.18 美元,9月20日报价为 0.172 美元,24小时内下跌约 5%。NTX 的波动则极为剧烈:根据不同窗口和来源,跌幅在 65% 到 95% 之间,据报道于 9月20日创下 0.00004075 美元的历史新低。WMTx 在同一分析期间下跌约 43%。

The reason for this price difference lies in the different mechanisms. For FETs, existing liquidity was withdrawn, but the total supply remained unchanged. For NTX, new tokens were created, causing a sudden surge in supply. The loss of funds undermines market confidence; unauthorized casting not only undermines confidence, but also further dilutes every existing position. This is why in such incidents, small-cap tokens are often hit more severely than the ecosystem's main assets.

Buying in Germany: FET, MiCA regulations and regulated trading venues

Since the end of the MiCA (EU Crypto Asset Market Regulation) transition period, anyone purchasing these tokens from Germany must trade through a licensed provider. MiCA is the European Union's regulatory framework for the crypto asset market; serving customers here requires a CASP (Crypto Asset Service Provider) license. In practice, this means that the choice of trading venues is narrowed and status communication is often more binding. For which institutions hold licenses, please refer to our overview of regulated crypto exchanges.

There are two points to distinguish when it comes to purchases: whether the token is tradable on a regulated exchange has nothing to do with the bridging security of its project operations. In addition, a suspension of deposits or withdrawals does not mean that your exchange is under attack, but is usually a precaution when unauthorized tokens may be in circulation.

The process of converting AGIX to FET was stalled before the bridge service was restored.

German Tax: Holding Period, Losses and FET-Related Losses Deduction

According to current German law, crypto assets held by individuals fall under private disposal transactions as stipulated in Article 23 of the Income Tax Act. In this scenario, three tax consequences become particularly practical:

  • A loss is incurred on a sale within one year: If a loss is incurred on a sale within one year after the acquisition, the loss can be used for tax deductions, but only to offset gains from other private disposal transactions in the same year, or by carrying forward to future years or backdating to previous years.
  • Hold for more than one year: If the token is held for more than one year, the income generated is tax-exempt, and likewise, the loss at this time is not tax-related.
  • Tax exemption threshold: The tax exemption for profits from private disposal transactions is € 1,000 per year; once this threshold is exceeded, all profits are subject to tax.

People now considering realizing a loss and buying it back shortly afterwards should be aware of the side effect: the repurchase will restart the calculation of the holding period of the new unit. Therefore, if you plan to buy back in the short term, you will defer the point when future earnings will be tax-free again. In addition, for whatever reason: Please clearly record the date of receipt and the number of tokens, because the burden of proof lies on you.

Bridging Hosting After Being Hacked: What Self-Hosting Really Protects

此次事件揭示了一个令人不安的教训:对于通过桥接交换的用户而言,硬件钱包并不能提供保护,因为攻击目标并非用户密钥,而是基础设施的签名密钥。自我托管仅在代币由您自己保管时才保护您的持仓。一旦您将代币交给他人的合约,适用的就是该合约的安全级别,而非您的安全级别。

实践建议:将长期持有的资产与用于交互的资产分开。长期持仓应使用硬件钱包,而合约交互使用单独的地址。这样做成本极低,却能将对您实际承担风险的资金损失限制在最小范围内。对于日常交互,只要余额较小,正确设置的软件钱包通常就足够了。

将桥接风险置于背景中:此案揭示了跨链桥的什么问题

多年来,跨链桥一直是代币生态中最脆弱的部分,原因是结构性的。跨链桥必须在一侧收集资产,在另一侧释放资产。在这中间,有一个授权机构来批准流程。该机构的权力越集中,一旦崩溃带来的杠杆效应就越大。单一签名且无金额上限的情况,正是这一尺度上最窄端的体现。

对于评估一个项目而言,这意味着要问一个很少出现在营销宣传中的问题:谁有权批准支付?需要多少把密钥?每笔交易是否有上限?如果答案是“一把密钥,无上限”,那么无论其余技术质量如何,都存在固有风险。这并不是对相关人员诚信的质疑,而是对架构缺陷的陈述。

后续处理同样重要。能够识别并冻结未经授权铸造的代币的项目可以限制损失;而无法做到这一点的项目,这些代币将永久在流通中造成损害。这一区别将在未来几周体现在这三个受影响的代币上。

Fetch.ai 漏洞总结:您需要带走的信息

  • 先理清自己的持仓,再看价格:检查您是否持有 FET、AGIX、NTX、WMTx 或 CGV,您的侧是否有待开放的转换,以及您的交易平台是否已暂停充值和提现。在德国可通过持牌平台交易的地方,请参阅我们的加密货币交易所对比。
  • 将长期持仓与合约交互分离:您计划长期持有的资产应存放在未授予第三方合约任何批准的地址上。哪些设备适用于此,请参阅硬件钱包对比。
  • 有意识地决定税务策略,不要匆忙:在出售前,检查您的单位是否处于一年持有期内,以及回购对该期限的影响。清晰的日期记录可以避免日后与税务局的争论;相关工具可在加密货币税务软件中找到。

事件来源:The Crypto Times 对铸造和集群持仓的分析,以及 Cryptopolitan 对签名密钥泄露的 accounts 和官方声明。(截至2026年9月23日。本文不构成投资建议。价格和费用结构会发生变化;购买前请与提供商核实条款。)

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP