Fetch.ai loses $2 million due to security flaw in bridge
Fetch.ai has been hit by a hack in which around $2 million in FET tokens were stolen. The attacker exploited a security flaw in the bridge’s TokenConversionManagerV3, according to security firm SlowMist.
In brief:
- Attacker stole around $2 million in FET tokens via the Fetch.ai bridge
- The vulnerability involved insufficient checks when converting tokens
- A leaked private key was used to approve the transaction
How the hack took place
The vulnerability was in the conversionIn() function of TokenConversionManagerV3. This part of the bridge relied entirely on a signature from a single authoriser as a security measure. Unlike the conversionOut() function, crucial checks were missing, such as limit validation and verification of on-chain burn or lock proofs.
The attacker managed to obtain a private key from the authoriser and used it to sign a new message to their own address. Because the only check consisted of validating that signature, the transaction was approved. The attacker was then able to drain the bridge’s entire FET balance in a single transaction.
Relevant details of the attack
The attacker address (0x1572f2af7696b39c85e3221cde8efb640f86c362) forwarded the stolen tokens to address 0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe. The vulnerable contract is located at 0xab424a430cc09864fa1277a38193111705adf3a3.
This incident underlines the importance of multi-layered security checks in blockchain applications. Particularly for critical functions such as token bridges, validation must take place on multiple levels, not just with a single signature.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.