Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsRWA MarketEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs

Fetch.ai Bridge Exploit: What FET, AGIX and NTX Holders Must Check Now

bullish:

0

bearish:

0

If you hold FET, AGIX or NTX, two things need to be kept apart right now. The tokens in your own wallet were not attacked. What was attacked is the bridge used to convert legacy AGIX holdings into FET. That conversion has been frozen since September 19, and anyone who still has it ahead of them cannot get through at the moment.

On the evening of September 19, 2026, the TokenConversionManagerV3 contract on Ethereum was drained of its entire FET liquidity. In the hours that followed, the same address minted hundreds of millions of new tokens belonging to three further projects. Here is the sequence, with the figures that can be evidenced, and what it means for you as an investor in Germany.

What happened in TokenConversionManagerV3 on September 19

The TokenConversionManagerV3 is the Ethereum side of the official SingularityNET bridge. A token bridge is a contract that collects tokens on one chain and releases a matching amount on the other. This bridge connected Ethereum with Cardano and also served to swap legacy AGIX holdings into FET.

According to the available on-chain analysis, a single call to the conversionIn function went through at 20:21:47 UTC in block 26,013,913, paying out 8,721,530.40 FET to an address controlled by the attacker. Depending on the source, the value is put at roughly $1.53 million to $1.55 million. Less than half an hour later, at 20:50:11 UTC, came the minting of 408.53 million NTX, the token of the NuNet project, with a reported value of about $462,730.

One point matters for the interpretation: no wallet was cracked here and no seed phrase was harvested. The attacker used a valid authorisation signature. Analytics firm SlowMist concludes that the infrastructure's signing keys had been compromised.

Why a single signature was enough: the flaw in conversionIn()

The technical core is quickly told and worth understanding, because it recurs across bridges. On SlowMist's analysis, the conversionIn() function accepted the signature of a single external account as sole authorisation. An external account, an Externally Owned Account or EOA in the jargon, is an ordinary address with exactly one private key behind it. Whoever holds that key is, as far as the contract is concerned, the legitimate counterparty.

A second point is what made the damage large: the counterpart function conversionOut() checks an amount limit, and conversionIn() did not. There was therefore no ceiling to cap any single call. A compromised key plus a missing amount check add up to a drain in one step.

The comparison with earlier cases is close at hand. In the two perp DEX incidents on Arbitrum over the summer, the decisive question was likewise who holds the keys, rather than whether a protocol calls itself decentralised. A single trust assumption is enough to bring an otherwise cleanly built system down in one move.

Unauthorised minting: 408m NTX, 260m AGIX, 53.8m WMTx

On September 20 the incident widened. According to PeckShield, the same address additionally minted 260 million AGIX and 53.838 million WMTx on Ethereum. WMTx is the token of World Mobile Chain; the project has confirmed that WMTx was minted without authorisation via the SingularityNET bridge.

PeckShield put the attacker cluster's holdings at about $16.77 million as of 09:21 UTC on September 20. The breakdown on that analysis: roughly 198.3 million AGIX worth about $14.42 million, 649 Ether worth about $1.67 million, and 33.538 million WMTx worth about $627,350. An analysis by Bitquery the same day, at 17:20 UTC, arrived at roughly 2.3 billion units created without authorisation across AGIX, NTX, CGV and WMTx combined.

The gap between the two figures is not a contradiction but a question of what is being measured. The $16.77 million is a market value at a point in time; the 2.3 billion is a unit count. And a unit count out of nowhere means the same thing for every existing holder: the share their stack represents of total supply has shrunk overnight.

Industrial minting press stamping out blank metal discs that spill uncontrolled over the collection bin
Tokens minted without authorisation come into being with nothing behind them and dilute every existing holding.

What Fetch.ai halted: AGIX-to-FET conversion and the Ethereum bridge

By its own account, Fetch.ai flipped two switches. First, the conversion of AGIX into FET was paused until further notice. Second, the Ethereum-side bridge was halted as a precaution, alongside the statement that there is no indication its own contract is vulnerable. In coordination with SingularityNET, affected wallets and contracts were disabled.

In practical terms for you: if you still hold legacy AGIX and have been putting off the swap into FET, you cannot execute it at the moment. No date has been given for when the conversion reopens. Anyone who has treated the deadline as open-ended should start watching the process rather than leaving it to sit.

Are you affected? How to check your wallet and exchange in five steps

The honest answer for the large majority is: probably not directly. What is affected in the narrow sense is the bridge liquidity, not your holdings. Even so, there are five things that can be settled in a few minutes.

  1. Check what you actually hold. FET, AGIX, NTX, WMTx and CGV are the tokens in question. If none of them is in your stack, the case is a lesson for you rather than an event.
  2. Check for open conversions. If you hold AGIX that has not yet been swapped into FET, that route is closed for now.
  3. Check the status at your exchange. Trading venues routinely suspend deposits and withdrawals for individual tokens after incidents like this. It appears in the provider's status notice, not in the price window.
  4. Revoke old approvals. If you ever granted the bridge contract an unlimited token approval, it deserves a review. That is good practice independently of this incident.
  5. Expect phishing now. Every major incident is followed by fake reimbursement forms and supposed support channels. No reputable project will ask you by direct message to enter a seed phrase or connect a wallet for a refund.

FET, NTX and WMTx price reaction: what the numbers show

The prices reacted very differently, and the difference is instructive. FET was trading near $0.18 at the time of the drain and was quoted at $0.172 on September 20, down about 5 percent over 24 hours. For NTX the move was dramatic: the figures range from 65 percent to about 95 percent down, depending on the window and the source, with a reported all-time low of $0.00004075 on September 20. WMTx lost about 43 percent on the same analyses.

The reason for the spread lies in the mechanics. With FET, existing liquidity was withdrawn and supply stayed the same. With NTX, new tokens were created and supply grew abruptly. A drain costs confidence; an unauthorised mint costs confidence and dilutes every existing share on top. That is why smaller tokens are hit harder in such cases than an ecosystem's main asset.

Buying in Germany: FET, MiCA and regulated trading venues

Anyone trading from Germany has bought these tokens through licensed providers since the MiCA transition period expired. MiCA is the EU regulation on markets in crypto-assets; serving customers here requires a CASP licence. In practice that means the choice of trading venues has narrowed and status communication has as a rule become more binding. Which houses hold a licence is set out in our overview of regulated crypto exchanges.

Two things should be kept apart on the buying side. Whether a token is tradable on a regulated exchange says nothing about the security of the bridges its project operates. And suspended deposits or withdrawals are not a sign that your exchange was attacked, but as a rule a precaution while units minted without authorisation may be in circulation.

Descending steel shutter closing a conveyor tunnel on which metal coins are backing up
The conversion of AGIX into FET is at a standstill until the bridge is released again.

German tax: holding period, losses and loss offsetting on FET

Under current German law, crypto-assets held privately are private disposal transactions under Section 23 of the Income Tax Act. Three points follow that become practical in this situation.

If you sell at a loss within one year of acquisition, that loss can be used for tax purposes, but only against gains from other private disposal transactions in the same year, against a carry-forward or in a carry-back. If you hold the tokens for more than a year, a gain is tax free, and by the same token the loss is then irrelevant for tax. The exemption threshold for gains from private disposal transactions is 1,000 euros per calendar year; once it is exceeded, the entire gain is taxable.

Anyone now considering realising a loss and buying back shortly afterwards should know the side effects: the repurchase restarts the holding period for the new units. So if you want to buy back in the short term, you are pushing out the point from which a later gain would be tax free again. And regardless of that: document acquisition dates and unit counts cleanly, because the burden of proof is on you.

Custody after a bridge hack: what self-custody really protects

One uncomfortable lesson can be drawn from this incident. A hardware wallet would have protected nobody here who swapped via the bridge, because the target was not the user keys but the infrastructure's signing keys. Self-custody protects your holdings for as long as they sit with you. The moment you hand tokens to someone else's contract, that contract's security level applies, and no longer yours.

In practice: separate holdings you are keeping from holdings you are moving. A hardware wallet for the long-term stack and a separate address for contract interactions cost little effort and limit the damage to what you actually put at risk. For day-to-day interaction a properly set up software wallet is often enough, as long as only small amounts sit there.

Putting bridge risk in context: what this case shows about token bridges

Bridges have been the most vulnerable part of the token landscape for years, and the reason is structural. A bridge has to collect something on one side and release something on the other. In between sits an authority that authorises the process. The narrower that authority, the greater the leverage when it falls. A single signature with no amount cap is the narrowest conceivable end of that scale.

For assessing a project, that means asking a question that rarely appears in the marketing: who may authorise a payout, how many keys are needed for it, and is there a ceiling per transaction? Where the answer is "one key, no cap", that is a risk that exists independently of the quality of the rest of the technology. This is not a statement about the integrity of the people involved, but about architecture.

The question of what comes afterwards matters just as much. Projects able to identify and freeze units minted without authorisation limit the damage. Projects that cannot carry it in circulation permanently. That distinction will be readable off the three affected tokens over the coming weeks.

Fetch.ai exploit check: what to take away

  1. Settle your own holdings before you look at the price. Check whether you hold FET, AGIX, NTX, WMTx or CGV, whether a conversion is open on your side, and whether your trading venue has suspended deposits and withdrawals. Where you can trade under a licence in Germany is shown by our comparison of crypto exchanges.
  2. Separate your long-term stack from contract interaction. What you intend to hold for years belongs on an address that has granted no approvals to third-party contracts. Which devices cover that is set out in the hardware wallet comparison.
  3. Decide on tax deliberately, not in a hurry. Before selling, check whether your units sit inside or outside the one-year period, and what a repurchase does to that period. Clean records of those dates spare you the discussion with the tax office later; tools for it are listed under crypto tax software.

Sources on the incident: the analysis of the mints and the cluster holdings at The Crypto Times, and the account of the compromised signing keys and the official statement at Cryptopolitan.

(As of September 23, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.