A compromised bridge signing key enabled an attacker to drain 8.7 million FET tokens and mint 260 million AGIX, 408.5 million NTX, and 53.8 million WMTx across the SingularityNET cross-chain bridge stack between September 19 and 20, 2026. PeckShield estimated the attacker's total holdings at $16....
"The majority of the signing keys have not been changed." — Bitquery, On-Chain Investigation Report, September 20, 2026
A compromised bridge signing key enabled an attacker to drain 8.7 million FET tokens and mint 260 million AGIX, 408.5 million NTX, and 53.8 million WMTx across the SingularityNET cross-chain bridge stack between September 19 and 20, 2026. PeckShield estimated the attacker's total holdings at $16.77 million as of September 21. AGIX collapsed 99% in 24 hours, erasing $93 million in market capitalization.
The exploit targeted the Ethereum-Cardano bridge infrastructure shared by members of the Artificial Superintelligence Alliance (ASI) — the 2024 merger entity combining SingularityNET, Fetch.ai, and Ocean Protocol (which later withdrew in October 2025). It represents the ninth major bridge exploit in 2026, pushing cumulative bridge-related losses for the year past $345 million. The root cause was not a smart contract vulnerability but an operational security failure: the bridge's conversion authorizer key, an offline nonce-zero key, was stolen and used to produce valid signatures.
As of September 21, the compromised conversion authorizer had not been rotated and the stolen NuNet minter role had not been revoked, according to on-chain monitoring by Bitquery. Both keys remained capable of authorizing further transactions.
The attack unfolded in two distinct phases across approximately 33 hours:
Phase 1 — September 19, 2026 (Evening UTC)
| Time (UTC) | Event |
|---|---|
| 20:21:47 | Attacker calls conversionIn on TokenConversionManagerV3 contract (0xab424A...ADF3A3), draining 8,721,530 FET (~$1.55M) at Ethereum block 26,013,913 |
| 20:50:11 | Within 29 minutes, attacker uses separately compromised NuNet minting key to produce 408.5 million NTX, inflating circulating supply by 42% |
Phase 2 — September 20, 2026
| Time (UTC) | Event | |---|---| | ~01:00–04:00 | Attacker mints 260 million AGIX on Ethereum via the same bridge signing authority | | ~04:00–05:00 | 53.838 million WMTx minted using shared cross-chain permissions | | 05:07 | World Mobile confirms exploit publicly | | 06:00 | Bitget suspends FET deposits and withdrawals | | 06:51 | Fetch.ai acknowledges converter-related reports | | 12:51 | Fetch.ai pauses its Ethereum-side bridge | | 16:19 | Fetch.ai posts "all-clear" statement for its own contracts |
The approximately 16-hour gap between the first unauthorized transaction and the first bridge pause is notable. The attacker pre-positioned NTX tokens for sale before initiating the FET drain, suggesting advance preparation.
The exploit was not a smart contract bug. Fetch.ai stated the attack used "a stolen SingularityNET bridge authorizer key used to produce a valid signature for the converter call, alongside a separately compromised NuNet mint key used within the same window."
The Affected Contract
The primary target was the TokenConversionManagerV3 contract at 0xab424A430CC09864fA1277A38193111705ADF3A3 — the Ethereum-side component of the SingularityNET bridge linking Ethereum and Cardano.
How the Signature Worked
The transaction was authorized by a valid cryptographic signature from the bridge's conversion authorizer, identified as an offline nonce-zero key. This means the signing key had never been used on-chain before — it was a cold key meant for bridge authorization. The attacker obtained this key through means not yet disclosed.
Design Flaws Identified
According to on-chain forensic analysis:
conversionIn function had no cap on individual conversion amounts, allowing the full FET liquidity to be drained in a single call.The NuNet Minter Key
The NTX minting used a reactivated deployer key that had been dormant since March 2023. The initiating address 0x1572F2af7696b39c85E3221CDE8EFb640F86c362 called the NTX contract at 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935 using the NuNet deployer address 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165.
Broader Infrastructure Penetration
Preliminary analysis by Bitquery revealed ETH and BNB sweeps from 16 wallets, including four identified as staff wallets from interconnected ASI ecosystem companies, plus $289,575 drained from what appears to be a payroll contract.
| Token | Action | Amount | Value at Time of Attack | |---|---|---|---| | FET (Fetch.ai) | Drained from converter | 8,721,530 | ~$1.55M | | NTX (NuNet) | Unauthorized mint | 408,500,000 | ~$462,730 | | AGIX (SingularityNET) | Unauthorized mint | 260,000,000 | ~$14.42M | | WMTx (World Mobile) | Unauthorized mint | 53,838,000 | ~$627,350 | | ETH | Accumulated from sales | 649 | ~$1.67M | | Total attacker holdings | | | ~$16.77M |
Of the total, approximately $2.25 million had been realized through token sales as of September 21. The majority of realized proceeds came from the sale of FET tokens, which yielded 523 ETH (~$1.2 million). Additional NTX sales through the MetaMask swap router produced 183 ETH (~$420,000).
AGIX: Fell from $0.0775 to $0.0006841 within 24 hours — a decline exceeding 99%. The crash erased approximately $93 million in market capitalization. The unauthorized minting of 260 million tokens created sudden, massive sell-side pressure against a token with limited liquidity.
NTX (NuNet): Dropped over 70% in 24 hours to an all-time low of $0.000328. The 408.5 million unauthorized tokens represented a 42% inflation of total supply, dumped primarily through DEX swap routes.
WMTx (World Mobile): Declined approximately 43% following the unauthorized minting of 53.8 million tokens.
FET (Fetch.ai): The primary ASI Alliance token experienced a comparatively modest 5% decline, falling from $0.18 to $0.172. Fetch.ai successfully distanced its own contracts from the breach, stating "Fetch.ai contracts are unaffected...attack targets SingularityNET infrastructure."
Exchange Responses: Bitget suspended FET deposits and withdrawals at 06:00 UTC on September 20. KuCoin halted FET deposits. Multiple exchanges were contacted to freeze deposits linked to the attacker's addresses.
Fetch.ai: Acknowledged the incident at 06:51 UTC on September 20, approximately 10 hours after the first exploit transaction. Paused AGIX-to-FET conversions. Emphasized its own Ethereum-side bridge contract showed no vulnerability. Published preliminary on-chain analysis.
SingularityNET: Stated treasury and exchange wallets were unimpacted. Advised token holders that no action was required. Coordinated with exchanges to freeze deposits linked to exploit addresses.
World Mobile: Confirmed exploit at 05:07 UTC on September 20. Announced immediate steps to contact exchanges and freeze attacker deposits. Began revoking minting authorities.
Critical Gap: As of September 21, according to Bitquery's on-chain monitoring, the compromised conversion authorizer key had not been rotated and the stolen NuNet minter role had not been revoked. This means both attack vectors remained technically viable more than 48 hours after initial exploitation.
The SingularityNET exploit is the latest entry in a year that has seen at least nine major bridge attacks. According to aggregate data from security firms Hacken, PeckShield, and 1inch:
| Date | Bridge | Loss | Root Cause | |---|---|---|---| | Jan 2026 | Various | ~$45M | Multiple incidents | | Apr 1 | Drift Protocol | $285M | Operational failure | | Apr 19 | Kelp DAO (LayerZero) | $292M | Bridge drain | | May 2026 | Verus-Ethereum | $11M | Contract exploit | | Jul 2026 | Two bridges (single day) | $31.5M | Key compromise | | Sep 19-20 | SingularityNET | $16.77M | Key compromise |
Cumulative bridge-related losses in 2026 have reached approximately $345 million across at least eight major incidents. Q2 2026 alone saw 67 DeFi security incidents totaling $764 million in losses, with 88% attributed to operational failures rather than smart contract bugs.
This pattern is consistent with historical data. Cross-chain bridges have been responsible for more than $2.8 billion in total losses, according to Hacken, representing nearly 40% of all value hacked in Web3. The SingularityNET exploit follows the dominant 2026 pattern: operational key management failures, not code vulnerabilities, are the primary attack surface.
The SingularityNET bridge exploit illustrates a structural problem that has persisted through six years of cross-chain infrastructure development: bridge security failures are overwhelmingly operational, not algorithmic. The signing keys were valid. The contracts functioned as designed. The failure occurred in key custody and access controls — areas where blockchain infrastructure inherits the same vulnerabilities as any centralized system.
For the ASI Alliance ecosystem specifically, the incident raises questions about infrastructure governance following the 2024 merger. Legacy bridge contracts from SingularityNET, with minting keys dormant since 2023, remained active and exploitable. The 16-hour detection gap and the continued availability of unrotated compromised keys as of September 21 suggest that incident response procedures were not commensurate with the value at risk.
The broader pattern is clear from 2026 data: bridges continue to be attacked not because the cryptography is broken but because the humans and processes managing keys and permissions do not match the security standards implied by the infrastructure they control. Until key management practices in cross-chain bridge operations match those of traditional financial custodians — multi-party computation, hardware security modules with role-based access, real-time anomaly detection — the 40% share of Web3 losses attributable to bridge exploits is unlikely to decline.