Late on September 19, 2026, an Ethereum conversion contract tied to the ASI migration stack paid out millions of FET — and within hours the same attacker cluster was minting unauthorized AGIX, NTX, and WMTx. Security desks and the projects themselves are framing this as an alleged key compromise on the SingularityNET Ethereum–Cardano bridge path, not a classic “smart-contract bug” that anyone can replay from a public exploit PoC. The distinction matters: if signing keys authorize the transactions, the failure mode is custody.
On-chain and desk reporting from Crypto Times, Bitquery, KuCoin’s PeckShieldAlert roundup, and mpost tell a consistent story — with one number that keeps getting flattened in headlines and should not be.
What Hit the Converter First
Around 20:21 UTC on September 19, TokenConversionManagerV3 on Ethereum executed a conversionIn that paid approximately 8,721,530.40 FET to attacker wallet 0x2dcc…1dfe, per Crypto Times and Bitquery’s on-chain timeline. That is the converter-float drain — real FET leaving the migration/bridge architecture — not a synthetic ticker print.
The ASI Alliance later described an unauthorized party withdrawing about $1.56M in FET from that migration/bridge architecture and said it was investigating with security partners, according to mpost’s write-up of project statements. Fetch.ai’s own position, reported the same day, was blunt: Fetch contracts were not under threat, FET continued to operate normally, and the attack targeted SingularityNET contracts / the Eth–Cardano bridge. AGIX↔FET conversions and the Ethereum-side bridge were paused.
Unauthorized Mints: AGIX, WMTx, NTX
The same attacker cluster did not stop at the FET payout. Bitquery’s investigation timeline puts a large NTX mint — roughly 408.5M — around 20:50 UTC on September 19. September 20 activity expanded on Ethereum to unauthorized AGIX and WMTx (Bitquery also counts CGV in the broader counterfeit-supply cluster).
PeckShield’s September 20 alert, carried by KuCoin News and cited in mpost, attributed roughly 260M AGIX and 53.838M WMTx minted on Ethereum to the same exploiter. World Mobile Chain separately confirmed that the SingularityNET bridge had been exploited and that unauthorized WMTx had been minted on Ethereum, and said it was contacting exchanges and working to revoke mint authorities — per Crypto Times.
Bitquery Research’s framing is the operational punchline for desks: this was not a broken-contract bridge bug in the usual sense. Project signing / mint keys authorized the transactions. Across five ASI-family assets, Bitquery tallies on the order of ~2.3 billion units of counterfeit or unauthorized supply, and cites AGIX’s fake share on Ethereum + Cardano near ~70.1%.
Do Not Conflate $16.77M With $2.25M
Two dollar figures are circulating — and they measure different things.
- PeckShield ~$16.77M is a holdings mark on the attacker cluster at the time of the alert (roughly 198.3M AGIX ~$14.42M, 649 ETH ~$1.67M, 33.538M WMTx ~$627K). It is a pre-crash token-mark snapshot of what the cluster held, not a verified cash-out receipt.
- Bitquery ~$2.25M is the desk’s estimate of realized proceeds after the oversupply hit thin liquidity — the money that actually moved, not the mark-to-market of minted inventory.
Headlines that glue “$16.77M stolen” onto a realized-cash narrative are mixing a holdings valuation with an exit estimate. Keep them separate.
Exchange Deposit Pauses Are Ops — Not FET Breach Proof
Bitget and KuCoin reported FET deposit pauses around the incident window. That is an exchange operational response — isolating deposit risk while desks sort bridge/mint noise — not proof that the FET contract itself was breached. Fetch.ai’s public line remains that its own contracts were fine and that the SingularityNET bridge path was the target.
Fake Recovery DMs
Projects and security monitors have already flagged social-engineering follow-ons. Treat unsolicited “recovery,” “refund,” or “whitelist” DMs and lookalike support links as hostile until proven otherwise. No legitimate rescue starts in your DMs asking for a seed phrase, a private key, or a “verification” transfer.
Jamoraquai Take
When a cross-chain bridge rests on offline signing keys that never send a transaction, the failure mode is custody — not a smart-contract puzzle — and unauthorized mints that trash thin liquidity while a converter float is drained is how ASI-stack trust breaks in public.
The useful read is structural, not speculative. A converter paid out real FET under authorized-looking signatures; mint authorities then printed AGIX, NTX, and WMTx into markets that could not absorb the supply without cratering marks; PeckShield’s ~$16.77M holdings snapshot and Bitquery’s ~$2.25M realized-proceeds estimate answer different questions; and Fetch / ASI / World Mobile statements all point at the SingularityNET Eth–Cardano bridge key surface rather than a FET-core contract exploit.
None of that is a trade ticket. It is a reminder that “bridged” ASI-family liquidity is only as trustworthy as the offline keys that can mint and convert — and when those keys go public in the worst way, the market learns the custody lesson before any post-mortem finishes.
Sources: Crypto Times · Bitquery Research · KuCoin / PeckShieldAlert · mpost



