CryptoReal
CASE FILE — Sep 25, 2026

SingularityNET Bridge Incident Exposes Critical Vulnerabilities in AI Token Ecosystem

For years, SingularityNET positioned itself as a hub for decentralized AI services. But in September 2026, its infrastructure became the center of a high-profile security breach.

On September 19, an unauthorized script—unbeknownst to the SingularityNET team—became the most active participant on their platform.

The attacker leveraged signing credentials obtained through a compromise of the project’s cloud infrastructure, enabling them to drain FET liquidity from the Ethereum bridge with a single authorized transaction. Over the following nine hours, they proceeded to mint approximately 2.3 billion AGIX, NTX, WMTX, and CGV tokens without backing collateral or authorization (details).

Some initial reports valued the seized tokens at $16.77 million; however, transactional analysis indicates that only about $2.29 million was actually realized in liquid assets, as the majority of the newly created tokens remained unsold.

Every private key used was legitimate and every contract operated as intended, following the instructions provided.

The consequences extended beyond the initial financial loss, and as of several days after the incident, no complete post-mortem has been released by the stakeholders.

When the controls for multiple AI projects reside within a single cloud environment, it raises fundamental questions about operational oversight.

Credit: SingularityNET, SlowMist, Bitquery, Peckshield, ASI Alliance, Blockaid, Uniswap, Baltex, AMLBot, NuNet, Fetch.ai

Although FET was the first asset targeted, the scope of the damage expanded rapidly.

The FET converter was emptied at 20:21 UTC on September 19, and less than three minutes later, all 8.7 million FET were swapped for 522.78 ETH.

Blockaid flagged the FET outflow at 21:40 UTC, also noting that the same wallet had obtained a significant NTX mint from NuNet’s deployer. The alert referred to the event as a Fetch.ai exploit, but SingularityNET later clarified that its own infrastructure had been compromised.

What at first seemed isolated to Fetch.ai was soon shown to affect a broader set of tokens.

By 02:47 UTC, SlowMist had determined the attack vector: a single compromised authorizer key was sufficient to empty the bridge.

A leaked credential, and contracts that trusted it.

This is a recurring issue in bridge security.

The FET theft was only the beginning. At 20:50 UTC, the attacker exploited NuNet’s minting authority to directly create 408.5 million NTX tokens on the contract, bypassing bridge mechanics.

The most extensive unauthorized minting began at 03:13 UTC, with AGIX minted in batches of 10 million. This was followed by WMTX at 03:38, further AGIX minting until 04:21, and a sequence of 50 CGV mints from 04:34 to 04:38.

By the morning of September 20, multiple public alerts indicated that the event was not limited to a single bridge, but affected a range of tokens.

Early estimates of the attacker’s holdings valued them at $16.77 million, though this calculation assumed the new tokens could be sold at full market prices—a scenario that proved unrealistic.

The attack continued into the next day. At 13:10 UTC on September 20, a SingularityNET payout contract transferred its entire USDC balance (289,575.10 USDC) to a compromised wallet, and within seconds the funds were moved to the attacker’s secondary wallet.

The breach prompts questions about how a single signature could permit such a large withdrawal and why no on-chain mechanism halted the process.

Bridge Security Architecture and the Attack Vector

Tokens managed by SingularityNET’s bridge exist across both Cardano and Ethereum. For Cardano-to-Ethereum transfers, the process involves burning the token on Cardano, after which the bridge contract on Ethereum either mints or releases the corresponding asset.

On Ethereum, the bridge contract does not independently confirm the burn event on Cardano. Instead, it relies on a signature from a designated authorizer as proof that the event occurred.

Bitquery identified five separate authorizer addresses for the affected bridges, none of which had ever initiated an on-chain transaction, indicating their primary function was off-chain message signing.

SingularityNET later confirmed that an unauthorized individual had “gained access to part of our cloud infrastructure.”

The method of initial access was not disclosed.

This architecture concentrated each bridge’s trust in a single point: the holder of the signing key.

Ethereum FET converter contract, fully drained:
0xab424a430cc09864fa1277a38193111705adf3a3

Authorizer address whose signature enabled the withdrawal:
0x69e5446b07b23de0a76730062c3252152216c85c

Transaction draining 8,721,530.40 FET:
0xfe12c63b322d52727c615f3342222138d1563400a9880cebb516a9a162ac69e2

A forensic analysis by Athena, under the ASI Alliance, matched the withdrawal signature to the live authorizer, confirming that the authorizer had remained unchanged since September 2024.

Two aspects of the contract design increased the severity of the breach.

The function conversionIn() accepted a single EOA signature without additional validation and omitted the checkLimits(amount) safeguard present in conversionOut().

This meant the stated limits (100–1,000,000 FET) were not enforced for conversionIn(), allowing the attacker to withdraw 8.72 million FET—far above the intended maximum.

Athena’s report found that all 100 legitimate ConversionIn events used UUID-style IDs from SingularityNET’s backend, while the breach used a non-ASCII byte sequence, making it an outlier. The transaction did not resemble standard bridge usage.

The NTX exploit did not go through a converter. The attacker, with access to NuNet’s mint authority, directly executed mint() on the token contract, creating 408.5 million NTX.

NTX mint event, 408,532,878.13 tokens:
0xe14442f6171d8a652e79d44336e58c00cdab271bdb69c668493d420e03ee13ab

AGIX tokens were minted using SingularityNET’s deployer address.

SingularityNET Deployer:
0xA7A31d206042B8A3E81aa4cf8c68c1B76856eE48

The AGIX, WMTX, and CGV minting ended with atypical last-call sizes, suggesting an automated process that continued until a limit was reached.

World Mobile’s WMTX converter imposed a per-call cap, which required the attacker to break the minting into 503 separate transactions, mostly for 1 million WMTX each, sometimes several within a single block.

Bitquery’s timeline shows that 16 wallets were swept within 21 minutes before the first unauthorized minting, with related activity on BNB Chain. Four wallets were attributed to SingularityNET or NuNet staff, including the one used to deploy the original converters in 2022.

Multiple authorization pathways were compromised during the incident.

A recovery address was used to update authorizer configurations for NuNet, Cogito, and Rejuve, and later freeze NTX. AGIX and WMTX converters could not be updated in the same manner, as their controlling wallets were a Gnosis Safe and a 3-of-4 Safe, respectively.

Bitquery reports that unauthorized minting of AGIX and WMTX continued for about an hour during the handover process.

“Our systems are audited regularly and we follow industry security standards,” SingularityNET stated.

While audits can confirm smart contract logic, they do not inherently guarantee the safety of off-chain infrastructure or the private keys controlling critical functions.

The use of valid signatures from the affected projects’ authorization keys enabled the attacker to create a significant volume of new tokens.

How much of the reported value was truly liquid, and how much was simply notional paper value based on illiquid, freshly minted tokens?

Assessing Actual Losses vs. Inflated Figures

The terminology in this case requires clarification.

Tokens withdrawn from contracts without proper authorization constitute direct asset losses, while unauthorized minting increases total supply, diluting value.

ETH and stablecoins realized via swaps or transfers to attacker-controlled wallets represent actual proceeds; wallet balances marked at quoted prices do not necessarily equate to cash value.

Early reporting often conflated these categories.

While the creation of 2.3 billion tokens was straightforward, liquidation proved challenging.

The bridge drain was the single largest realized gain. The attacker used MetaMask to swap the drained FET for 522.78 ETH, accounting for transaction fees.

Sums referenced in this case file

FET sale transaction, 8.72 million FET for 522.78 ETH:
0x98f6e59b54fd4d2c086cc7cab4e7070edff6410210a1bf1fbaffd62da3b76d1c

Two principal wallets handled most of the realized proceeds and minted supply.

The main attacker address received the FET, minted NTX, and was the recipient of the initial AGIX and WMTX mints.

Main attacker address:
0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe

A secondary wallet received subsequent AGIX and WMTX mints, all CGV mints, and the USDC payout.

Secondary attacker wallet:
0x83f4424a401a9bb75f90314f21adaea6a9ce09c5

Bitquery traced early funding of the main wallet to ChangeNOW.

ChangeNOW funding transaction:
0xa99a8b71bd90d295db305639fc976339a057812c2693f3e44ae9288e5c13ebe1

Additionally, the main attack wallet’s history indicates an Across bridge deposit from September 1.

Across bridge fill, September 1:
0xb56d3b900b5ac694d56d6efb9552a89fc0a14641eceefa7e16107cb8ccb0ea6d

At 04:04 UTC on September 20, the secondary wallet received ETH for gas and began selling tokens shortly thereafter.

Secondary wallet gas receipt and first sale:
0x4e8894823caaf8fefaf0849cf69b30148ae5ddcee9e7f9bd0c1be0dae0c720c2

WMTX approval for MetaMask Swap Router (100,000 WMTX):
0x8fcaa005da0c1a5ab138898571e2974ba8aa8f0b9864381e5b2b98b81e702da9

First WMTX sale, 100,000 WMTX for 0.832455441 ETH:
0xcf4b119f38d0da10dccac787234e05c6cabe3440dfe303f4f407daa92ab8829e

This division complicates assessment. PeckShield initially estimated $16.77 million in assets linked to the attacker, comprised of 198.3 million AGIX, 649 ETH, and 33.538 million WMTX.

Sales activity revealed the liquidity gap. A swap of 10 million NTX via MetaMask and Mayan returned just 940.39 USDT. The secondary wallet used UniswapX orders, where third-party fillers provided ETH; the records do not clarify how fillers managed the acquired WMTX.

NTX sale, 10,000,000 NTX exchanged for 940.5087 USDT:
0xb6ecca4deeb2a616507a3f5779cb12db4fd986e5ee37c1832237fae2a1f1258

CGV was particularly illiquid: A swap of 246.2 million CGV produced only 0.0123 ETH.

CGV sale, 246,200,000 CGV for 0.0123 ETH:
0x69a28fb152b2b1b4158ec3db17f7baf565b644859a5150c38729bbb2d198bfad

A payout contract added 289,575.10 USDC to the secondary wallet, marking a significant inflow of stablecoins without requiring token sales.

Payout contract transfer, 289,575.1047 USDC:
0x869343d87a137a52aebce119c8c35e2fc3500205bf7a8c574ec2e8f4ab677c18

Intermediary transfer to secondary wallet:
0xca9facda3f3629fa72ff98b4c8e663d3b415011979d749fab96ed9eda287e66f

By September 22, analysis shows the attacker’s two principal wallets had received about 742.7 ETH-equivalent and $362,075 in stablecoins, excluding unsold tokens and accounting for gross, not net, receipts.

Much of the liquid value was quickly redistributed from the attacker wallets.

By September 21, three wallets had deposited 75,000 USDC to Chainflip, 75,000 USDC to Baltex, and 118,015.16 USDC to Chainflip.

Baltex offers non-KYC and Monero-based privacy options. Separately, AMLBot reported that a Chainflip broker refused an ETH deposit suspected to be from the attacker.

Chainflip transfer, 75,000 USDC:
0x3c8b12fedf147d82c8a5506edf3fcad4b7e25c8b96e4fb13b10cf2915aba0076

Baltex transfer, 75,000 USDC:
0x05d6d42c75356900e523116d34892b480e9f9134ba195db698d7b1448e0b0696

Chainflip transfer, 118,015.16 USDC:
0xea254b148da1a6d028050f3a59f87845e3dc177ca37ef6441c7eb6cff47eb8ed

Just before midnight UTC, the secondary wallet sent 93.70 ETH to an undisclosed recipient. The main attacker wallet dispatched two identical transfers of 100 ETH each about 40 minutes later.

Secondary wallet transfer, 93.70 ETH: 0x605d803890ae4eddc684f82f6de1a82c49a6a3f5646295c1a01fd897fa2a7577

Recipient wallet:
0x2fD3285C93437077EF5FA6cecc367FD24d0fF726

Main attacker wallet, 100 ETH transfer:
0xa8511628388c330db78fcdcfe7af5577e1f300adee795b578508fb21203b4756

Main attacker wallet, second 100 ETH transfer: 0x14399c61687de491461f76e961a91d2c0dcda4c6bb00ba332ec18b19d394822f

AMLBot later described two separate 100 ETH transactions, with one converted to about 266,000 USDC and routed through CCTP, Arbitrum, and Hyperliquid. The other was rejected by Chainflip, then swapped via THORChain for around 3.28 BTC. AMLBot did not provide source addresses.

Both main wallets received dusting and spoofed token transfers from lookalike addresses, suggesting possible address poisoning attempts.

As of September 25, the main attacker wallet retained roughly 433 ETH, 15.94 WETH, and 52,395 mUSD, consistent with AMLBot’s estimate, as well as 198.30 million AGIX and 33.54 million WMTX.

The secondary wallet held about 18,109 USDC, 625.86 million AGIX, 166.49 million WMTX, and 246 million CGV.

Displayed token values do not reflect their actual market liquidity. Attempting to sell large amounts would likely result in significant price drops and limited realized value.

Gross liquid proceeds from the operation are estimated at $2.29 million.

While this value was readily transferable, the remaining 1.27 billion tokens are illiquid. The eventual impact of their sale, if possible, remains uncertain.

Massive Unauthorized Supply

Price can rebound, but supply inflation is permanent.

Bitquery’s reconciliation found 1.28 billion AGIX across chains, with 895.96 million minted in the breach—roughly 70.1% of the total. The other 382.65 million represented pre-breach supply.

Similarly, unauthorized mints accounted for 81.1% of CGV, 32.4% of WMTX, and 29.0% of NTX supply.

The NTX exploit increased cross-chain holdings to 1.41 billion, above the one-billion-token maximum described in NuNet’s documentation.

About 40.1 million unauthorized NTX migrated to Cardano, with nearly all entering regular liquidity pools, making them indistinguishable from legitimate tokens once deposited.

FET’s issue was not excess supply, but the bridge’s inability to fulfill redemptions. The Ethereum converter holding FET was drained, while about 870 million FET remained on Cardano.

No FET transfers from Cardano to Ethereum have been attempted since the breach, so no user has yet been denied a payout due to an empty converter.

For NTX, the challenge is reversed: Unauthorized NTX tokens have entered Cardano liquidity pools and are now functionally indistinguishable from the authorized supply.

SingularityNET reported that compromised access has been revoked, impacted bridges and contracts have been disabled, and AGIX and NTX transfers on Ethereum have been paused. The bridges will remain offline pending a third-party security review.

Bitquery found that three of five authorizer keys remained unchanged as of September 20. With bridges deactivated, the effectiveness of these changes will only be tested upon reactivation.

Regarding AGIX, SingularityNET originally promised to provide a “legitimate, verified path forward for eligible holders.”

It has since declared its intention to retire the original AGIX token and introduce a replacement for affected users, though specifics regarding eligibility and distribution are still pending. AGIX on Ethereum remains inactive.

With roughly 70% of AGIX supply originating from the breach, determining eligibility remains complex: Any plan must address tokens that passed through regular markets after unauthorized minting.

Fetch.ai confirmed its contracts were not impacted.

The ASI Alliance acknowledged a $1.56 million FET loss and committed to a full report, though no compensation details have been shared for AGIX, NTX, or liquidity providers affected by counterfeit tokens.

All accepted signatures were valid, and contracts executed their logic as written; there was no on-chain verification that the claimed cross-chain events actually occurred.

In the case of NTX, the attacker exploited direct minting authority.

The event illustrates the risks of centralizing the ability to mint or release multiple assets within a single infrastructure.

If decentralized AI is the vision, who monitors the systems safeguarding these privileges?

Bridge and conversion contracts accepted signatures from their designated authorizers.

For cross-chain mints, these signatures were accepted as proof of events on other chains, with no independent on-chain verification.

The NTX mint was performed by directly invoking the token contract, utilizing the minting authority.

SingularityNET attributes the exploit to unauthorized access to its cloud infrastructure, which enabled minting and asset withdrawal via its bridges.

Fetch.ai reiterated that its own contracts were not compromised.

Public communications have not detailed the precise method of access or which authorities were exposed.

The blockchain provides a detailed record of actions performed by these authorities, but does not clarify how access was obtained or who made the relevant security decisions.

Bitquery’s analysis showed that the bridge-authorizer addresses had never conducted on-chain transactions, supporting their off-chain signing role. Contracts validated these signatures as authentic.

When signatures alone serve as proof, who verifies their legitimacy?

Bridge AttackSingularityNET
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.