Fetch.ai and SingularityNET were breached by the same attacker in succession. Preliminary on-chain analysis by the official team confirms that leaked signing keys led to the theft of FET tokens. Affected wallets and contracts have been urgently disabled, and market attention on crypto project security has notably intensified.
Latest Attack Update: FET Stolen, Official Response Underway
Fetch.ai has suffered a major security attack. Preliminary on-chain analysis by the official team confirms that the attacker exploited leaked signing keys to breach the system and steal FET tokens. Affected wallets and contracts have been urgently disabled to prevent further asset losses. The incident directly involves user asset security and affects both Fetch.ai and SingularityNET, drawing rapidly growing market attention.
Root Cause Traced to Signing Key Leak, On-Chain Analysis Provides Preliminary Conclusions
According to the preliminary on-chain analysis released by Fetch.ai, the signing key leak is the direct cause of the FET theft. Signing keys are critical credentials used by blockchain projects to authorize on-chain transactions and manage smart contracts, representing the highest level of assets in a project's security system. Once a signing key is leaked, attackers can forge legitimate authorization signatures, bypass routine verification mechanisms, and transfer FET from wallets to addresses under their control. The official team has completed a preliminary trace of relevant on-chain data and transaction paths and has made the findings public. The direct cause of the incident has been identified as a signing key leak, making key management the core source of risk, which also provides a foundation for subsequent loss assessment and fund tracing.
Fetch.ai and SingularityNET Breached in Succession, Clear Attack Intent
A key detail of this attack is that Fetch.ai and SingularityNET were breached by the same attacker in quick succession. The fact that both projects were compromised within a short timeframe indicates that the attacker did not select targets randomly but carried out a targeted, deliberate campaign. Launching consecutive attacks on multiple projects typically suggests that the attacker had already obtained internal information about the projects and prepared reusable attack paths. The fact that both projects were breached by the same attacker within the same period means the impact of this security incident is no longer limited to a single project. The nature of the event has escalated from a vulnerability in one project to a series of attacks targeting a specific category of projects. The market now needs to assess not only the scale of FET losses but also whether similar projects face comparable risks. The official team has not yet disclosed the specific relationship between the two compromised projects, but the key fact of a shared attacker is enough to raise alarm across the board.
Urgent Disabling of Wallets and Contracts to Halt Further Losses
After completing the preliminary trace analysis, Fetch.ai moved quickly to disable affected wallets and contracts. The core purpose of this measure is to cut off the attacker's access to remaining assets and prevent losses from expanding during the investigation. For wallets and contracts involved in user fund storage and transfers, timely disabling is a standard response measure in security incidents. However, this measure also has practical consequences. The disabled wallets and contracts cannot be used normally during the investigation period, and some users may face temporary restrictions on deposits, withdrawals, and transactions. Balancing thorough security troubleshooting with maintaining a normal user experience is a real challenge the project team must address. The timeline for restoring related functionalities remains unclear until the investigation is complete.
User Asset Security Under Pressure, Market Trust Tested
This security incident directly affects FET token holders, especially users who store assets in the project's official wallets or interact with the project's contracts. A signing key leak means attackers can transfer assets without triggering routine alerts, making it difficult for users to detect anomalies in a timely manner. Following the incident, community concerns about the project's asset security capabilities have grown significantly, and market trust has been impacted. For FET holders, the most pressing questions revolve around several key points: the confirmed scale of stolen assets, whether more affected addresses exist, how the official team will handle the situation, and when the disabled wallets and contracts will be restored. The answers to these questions will directly influence the market's assessment of Fetch.ai's ability to continue operations.
Security Scrutiny of Crypto Projects Intensifies
The Fetch.ai incident comes at a time when market attention on related sectors is already elevated. This attack has prompted the market to re-examine the security bottom line of crypto projects. The cascading losses caused by a signing key leak once again demonstrate that security investment and institutional development at the project operations level are equally important. The fact that a single attacker was able to breach two projects in succession also indicates that some projects still have room for improvement in security protection. In the wake of the incident, the market has raised the bar for security audits, key management systems, and vulnerability response capabilities among similar projects. Whether project teams use multi-signature schemes, implement hot-cold key isolation, and conduct regular security audits is becoming an important reference for users and institutions when evaluating project risk.
Key Management Shortcomings Spark Industry-Wide Reflection
At the industry level, this attack once again exposes the long-standing weaknesses in key management among crypto projects. Blockchain technology itself features immutability and decentralization, but project operations rely heavily on centralized key management. Once private keys or signing keys are leaked, all on-chain security mechanisms face the risk of failure. This structural contradiction makes key management one of the most frequent sources of security incidents in the crypto industry. This incident provides a typical case study for reflection: insufficient security investment, imperfect key management systems, and missing emergency response mechanisms can all place projects at enormous risk. For project teams, establishing multi-level authorization and approval mechanisms, distributing key permissions, introducing third-party custody, and conducting regular audits are necessary measures to reduce similar risks. For users, avoiding long-term storage of assets in project official wallets, paying attention to official security announcements, and monitoring on-chain anomalies are also important ways to protect themselves.
What to Watch Next: Investigation Results, Fund Flows, and Security Hardening
As of now, Fetch.ai has released its preliminary on-chain analysis and implemented urgent disabling of affected wallets and contracts, but the full picture of the incident remains unclear. Key points for subsequent market attention include: the official team's further investigation into the attack timeline and attacker identity, the specific amount of stolen FET and its current flow, whether exchanges and on-chain security teams will flag and freeze related addresses, and what long-term security hardening measures the project team will introduce to restore community confidence. Until the official team discloses more information, the full impact of this incident remains to be assessed. The market will continue to track the subsequent developments of Fetch.ai and SingularityNET, watching whether the two projects can rebuild trust after the security crisis and whether this incident will push the crypto industry toward stricter standards in key security.



.jpg)