# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-20 07:54 UTC)
## @SlowMist_Team (SlowMist) · 09-20 02:47 · ♥23 ↻1 💬3 🚨SlowMist TI Alert🚨 💸 @Fetch_ai Loss: ~$2M
🔍 Root Cause: TokenConversionManagerV3's conversionIn() leaves single-EOA ECDSA signature as the sole authorization check. It lacks the checkLimits(amount) modifier present in conversionOut(), and does not verify any on-chain burn/lock proof. Using the leaked authorizer private key, the attacker signed a fresh message for their own address, passed the check, and drained the bridge's entire FET balance in one call.
📌 Attacker: 0x1572f2af7696b39c85e3221cde8efb640f86c362 📌 Recipient: 0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe 📌 Victim/Vulnerable Contract: 0xab424a430cc09864fa1277a38193111705adf3a3
Powered by https://t.co/Mz5jOnx997 Tx: https://t.co/o14Ad4G8Ce https://x.com/SlowMist_Team/status/2101503515877396639