Fusion disclosed a swap-wallet compromise
On September 28, 2019, the Fusion Foundation said its token-swap wallet had been compromised and 10 million native FSN tokens plus 3.5 million ERC-20 FSN tokens had been taken. Chief executive DJ Qian announced the incident in Fusion’s official Telegram group during the evening in the United States. The foundation’s written account, posted around the turn into September 29, dated the compromise to September 28.
The incident mattered because the affected wallet sat at a junction between two versions of the project’s asset. Fusion had launched its own mainnet and was migrating holders from the Ethereum-issued ERC-20 representation of FSN to native mainnet FSN. The swap wallet supported that conversion. Control of its private key therefore exposed inventory held for an operational migration process even though the foundation said the Fusion protocol itself had not been breached.
That distinction was important but preliminary. On September 28, Fusion said its investigation had found only the swap wallet affected and that it had received no reports of other holders’ wallets being compromised. Those were contemporaneous company claims, not conclusions from an independent forensic examination.
What the foundation said it knew
Fusion attributed the loss to theft of the wallet’s private key. It also said some of the stolen tokens had been sent to exchanges and sold, naming BitMax and Hotbit, while the remaining assets under its control were moved to cold storage. The team said it contacted exchanges and began tracing abnormal transfers.
The disclosed token count is clearer than the incident’s dollar value. Reports published immediately afterward estimated the haul near $6.4 million, while CoinDesk valued the same token count at about $3.75 million at its September 30 publication time. Those figures used different FSN price moments during a sharply moving, fragmented market. This reconstruction therefore treats 10 million native FSN and 3.5 million ERC-20 FSN as the verified loss measure and does not present a single dollar estimate as definitive.
Nor does it characterize the event as a protocol exploit. The available record describes compromise of a foundation-operated wallet credential. A stolen administrative key and a flaw in blockchain consensus are different failure modes: the first concerns custody and operational controls; the second would imply a defect in the network rules or code. As of September 28, the foundation asserted the former, but had not published enough forensic detail to independently establish how the key was obtained or who controlled it.
Why a migration wallet concentrated risk
The theft exposed a recurring design problem in token migrations. A project can operate a decentralized network while still depending on centralized wallets, signers and exchange relationships at conversion points. When both an old token representation and a new native asset pass through one controlled process, key management becomes a material part of the system’s security.
Fusion’s initial response also depended on centralized venues. Asking exchanges to suspend deposits or identify proceeds could restrict the attacker’s ability to sell, but it could not itself reverse completed transfers. On September 28, the amount recoverable, the identity of the attacker and the final treatment of stolen tokens remained unresolved.
Later confirmation
In an October 9 update, Fusion again stated that 10 million native FSN and 3.5 million ERC-20 FSN had been stolen. It said 3.9143 million native FSN and 1.978 million ERC-20 FSN then remained in identified attacker accounts, and outlined possible recovery paths, including no chain change, a state change, or a mainnet restart. That later statement confirms the original quantities but was not knowable on September 28 and does not resolve the missing event-day forensic evidence.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

