The attacker only created a single signature and then drained all the FET from the cross-chain bridge.
The issue was with the FET redemption contract of the AI Super Alliance. This contract accepts only one authorization, but it never double-checks whether the authorized tokens were actually locked or burned. Once the attacker obtained the private key behind that signature, he generated his own authorization. With a single transaction, he cleared the bridge’s balance.
He withdrew 8.72 million FET, worth about $1.54 million. The same cluster of wallets then also received 408.5 million newly minted NTX, worth about $463,000. Taken together, the two transactions totaled just over $2 million, and the NTX price dropped by 95% immediately.
At first, it was just a vulnerability in one project; at the end, it dragged in two. The destination address for both funds was the same, tying the two incidents together. Their actions were swift and decisive, suggesting they didn’t intend to leave any story behind on-chain.
From another angle, this is also how the business is priced. Users want convenience, while the project team wants traffic. The saved verification step means everyone who leaves money in the bridge ends up paying for it together.
The vulnerability itself is small—so small it’s just an omitted check that should have been written. What’s expensive is where that gap sits: all of the bridge’s funds are queued behind it. So a tiny crack is equivalent to a big door. This bridge business profits from tolls, but what gets paid out is everything—someone’s entire stash.
In code, the most expensive line is never the one written incorrectly. It’s the one that isn’t written.
#链上安全 #DeFi
The issue was with the FET redemption contract of the AI Super Alliance. This contract accepts only one authorization, but it never double-checks whether the authorized tokens were actually locked or burned. Once the attacker obtained the private key behind that signature, he generated his own authorization. With a single transaction, he cleared the bridge’s balance.
He withdrew 8.72 million FET, worth about $1.54 million. The same cluster of wallets then also received 408.5 million newly minted NTX, worth about $463,000. Taken together, the two transactions totaled just over $2 million, and the NTX price dropped by 95% immediately.
At first, it was just a vulnerability in one project; at the end, it dragged in two. The destination address for both funds was the same, tying the two incidents together. Their actions were swift and decisive, suggesting they didn’t intend to leave any story behind on-chain.
From another angle, this is also how the business is priced. Users want convenience, while the project team wants traffic. The saved verification step means everyone who leaves money in the bridge ends up paying for it together.
The vulnerability itself is small—so small it’s just an omitted check that should have been written. What’s expensive is where that gap sits: all of the bridge’s funds are queued behind it. So a tiny crack is equivalent to a big door. This bridge business profits from tolls, but what gets paid out is everything—someone’s entire stash.
In code, the most expensive line is never the one written incorrectly. It’s the one that isn’t written.
#链上安全 #DeFi
