A security incident spanning SingularityNET-linked bridge infrastructure and several connected ecosystem tokens has become one of September’s most complex token-supply events.
The same attacker cluster is linked to a direct drain of FET and large unauthorized mints of NTX, AGIX and WMTx, with independent analysis also tracing CGV supply creation to the cluster.
The core accounting rule for this incident is simple:
Unauthorized token supply is not equivalent to realized theft.
The attacker can mint a large nominal quantity while real economic extraction is limited by the liquidity available to sell it.
What happened first: 8.7 million FET drained
The first clear cash event occurred on September 19.
Current on-chain reconstruction shows a call to Fetch.ai’s Ethereum TokenConversionManagerV3 moved approximately:
8,721,530 FET
into the attacker cluster.
Security analysis valued the drain around $1.5–$1.6 million at the time.
The funds were later swapped, with independent analysis describing approximately 523 ETH received from the FET sale.
Valid signature, compromised authority
The dangerous part of the incident is that the converter reportedly accepted a valid authorizer signature.
Fetch.ai’s later preliminary analysis attributed that valid signature to a compromised SingularityNET bridge authorizer key.
This is different from breaking signature verification mathematically.
If the private signing key is stolen, a forged instruction can still look cryptographically valid to the contract.
NuNet: 408.5 million NTX minted
Roughly half an hour after the FET drain, the NuNet deployer account minted approximately:
408.5 million NTX
and transferred the newly created supply into the same attacker-linked cluster.
Fetch.ai’s preliminary analysis described this as a separate compromised NuNet mint key operating in the same incident window.
The mint materially damaged NTX supply integrity and was followed by severe token-price deterioration.
SingularityNET: 260 million AGIX minted
On September 20, security monitoring identified approximately:
260 million AGIX
minted without authorization on Ethereum.
The attacker did not necessarily sell all of those tokens.
That distinction is essential because a 260 million-token mint can destroy circulating-supply credibility even if only a fraction can be monetized through available liquidity.
World Mobile: 53.838 million WMTx minted
The same cluster was also linked to approximately:
53.838 million WMTx
minted on Ethereum.
World Mobile confirmed that the SingularityNET bridge had been exploited and that WMTx had been minted without authorization.
The project said it was working with exchanges and security partners to freeze affected deposits and revoke minting authorities.
CGV and the broader 2.3 billion-token estimate
Independent Bitquery research traced roughly:
2.3 billion newly created token units
across AGIX, NTX, CGV and WMTx to the same attacker cluster.
That number spans multiple tokens and chains and should not be translated into a single dollar loss.
Some counterfeit supply may be economically unsellable because market depth is too thin.
What the $16.77 million figure means
One security-monitor snapshot valued the attacker cluster’s Ethereum holdings at approximately:
$16.77 million
including large AGIX balances, ETH and WMTx.
This figure is best described as:
attacker-cluster holdings / marked inventory at that snapshot
not:
confirmed realized loss.
For CEXVia, the clean loss taxonomy is:
- FET drain: real asset extraction;
- unauthorized NTX/AGIX/WMTx/CGV: counterfeit/unbacked supply;
- attacker holdings: mark-to-market inventory;
- realized proceeds: what the attacker actually converts into liquid assets.
What Fetch.ai has said
Fetch.ai said its own contracts were not under threat and that FET continued to operate normally.
The team said the attack targeted SingularityNET contracts, primarily the Ethereum–Cardano bridge, and that unauthorized mints used that path.
As a precaution, Fetch.ai paused:
- AGIX-to-FET conversions;
- its Ethereum-side bridge.
The team said there was no indication that the Fetch.ai bridge itself was vulnerable.
Exchange and market impact
The event triggered defensive exchange action.
Some exchanges suspended FET deposits or withdrawals during the security review.
Unauthorized token supply also created severe price-discovery problems for NTX, AGIX and WMTx because exchanges and DEXs must distinguish legitimate circulating supply from exploit-created inventory.
Why this incident is structurally important
Bridge systems frequently rely on privileged signing authorities for:
- minting;
- burning;
- conversion approvals;
- cross-chain message validation.
If one signing key has authority over large token supply, key compromise can bypass otherwise-correct contract logic.
The control problem is therefore not just contract code. It includes:
- key custody;
- multisig threshold design;
- hardware security modules;
- role separation;
- rate limits;
- mint caps;
- emergency revoke paths;
- anomaly monitoring.
Evidence Status
Confirmed / Project Statements
- Fetch.ai says its own core contracts remain safe.
- Fetch.ai says the primary exploit path involved SingularityNET bridge infrastructure.
- AGIX-to-FET conversions and the Ethereum-side Fetch.ai bridge were paused as precautions.
- World Mobile confirmed unauthorized WMTx minting through the SingularityNET bridge and began freeze/revocation work.
On-chain / Security Analysis
- ~8.7M FET drained from the converter.
- ~408.5M NTX minted to the linked cluster.
- 260M AGIX and 53.838M WMTx unauthorized mints identified.
- Independent analysis links additional CGV minting.
- ~2.3B newly created token units estimated across the broader cluster.
- ~$16.77M Ethereum-holdings snapshot reported by a security monitor.
Developing
- Full root-cause report from SingularityNET.
- Reconciled cross-chain counterfeit supply.
- Realized attacker proceeds.
- Recovery/freezes.
- Token migration/reissuance plans.
- Holder compensation.
Risk Assessment
Critical.
The incident combines direct theft, privileged-key compromise and supply-integrity failure across multiple connected assets.
What to Watch Next
Signing-key revocation, full incident post-mortem, exchange deposit rules, legitimate/counterfeit token reconciliation, supply snapshot policy, bridge reopening, recovery and compensation.
FAQ
How much FET was drained?
Approximately 8.7 million FET.
Were 260 million AGIX actually sold?
Not necessarily. The figure refers to unauthorized minting, not confirmed sales.
Is $16.77 million the final loss?
No. It is a reported snapshot of attacker-cluster holdings.
Was Fetch.ai itself fully compromised?
Fetch.ai says its core contracts remain safe and attributes the main exploit path to SingularityNET bridge infrastructure.
Why did valid signatures not protect the bridge?
A cryptographic signature is only trustworthy if the signing key itself remains secure. A stolen authorizer key can create valid-looking malicious instructions.
Which tokens are implicated?
FET, NTX, AGIX and WMTx are directly documented in current incident reporting; independent analysis also links CGV to the same cluster.