The September 19 attack that drained a Fetch.ai token converter and minted 408.5 million unauthorized NuNet (NTX) tokens has widened into a broader key-compromise event across the SingularityNET bridge stack, according to on-chain security firms tracking the incident.
On September 20, the same attacker cluster exploited the SingularityNET bridge contract to mint 260 million AGIX and 53.838 million WMTx on Ethereum, per PeckShield. At the time of the alert, the firm valued the cluster's holdings at approximately $16.77 million — 198.3 million AGIX worth about $14.42 million, 649 ETH worth roughly $1.67 million, and 33.5 million WMTx worth about $627,000. The Crypto Times reported the full timeline, and Protos corroborated the linkage to the earlier Fetch.ai and NuNet strikes.
The scope may be larger still. Blockchain data provider Bitquery separately reported that roughly 2.3 billion newly created units across AGIX, NTX, CGV and WMTx were traced to the same actor, in addition to the 8.7 million FET drained from the Fetch.ai converter. Bitquery cautioned that a large share of the remaining AGIX supply on Ethereum, Cardano and BNB Chain now appears to be unauthorized inventory — a count spanning additional chains that should be read alongside, not in place of, PeckShield's Ethereum-only snapshot.
What the projects have confirmed
Fetch.ai stated on September 20 that its own contracts were not under threat and FET continues to operate normally, describing the attack as targeting SingularityNET contracts — "primarily the SingularityNET Bridge between Ethereum and Cardano." The team paused AGIX-to-FET conversions and, as a precaution, the Ethereum-side Fetch.ai bridge, and said it had deactivated affected wallets and a contract together with SingularityNET. A preliminary on-chain analysis hosted on ASI:One, which Fetch.ai flagged as not final, traces the incident path from a compromised signing key to cash-out wallets.
World Mobile Chain confirmed the same day that the SingularityNET bridge had been exploited and WMTx minted on Ethereum without authorization. The team said it is contacting exchanges to freeze affected deposits, working with security partners to revoke minting authorities, and preparing a pre-exploit snapshot — while warning holders against recovery direct messages, fake support accounts and unofficial migration links.
Attribution remains on-chain only: no group has been named, and the linkage across the four projects rests on the shared wallet cluster identified by PeckShield, Blockaid and Bitquery. As of The Crypto Times' report, SingularityNET had not published a standalone incident statement comparable to those issued by Fetch.ai and World Mobile.
Same pattern, fourth token
The incident is now effectively a four-token key-compromise: FET drained from a converter, NTX minted through NuNet's deployer account, and AGIX and WMTx minted through the SingularityNET bridge. Every stage ran through privileged infrastructure rather than token contracts — which is why Fetch.ai could accurately say its contracts are safe while the ecosystem around them bled.
The unauthorized mints created immediate supply overhangs: NTX collapsed to an all-time low within hours of the September 19 mint, and WMTx price action on listed venues prompted World Mobile's warning to holders. For exchanges, the actionable defense is the one World Mobile is pursuing — freezing flagged deposit addresses and pressuring the projects to revoke the minting authorities the attacker abused.
TrustGrade tracks the security posture of bridge operators and token issuers. Verified trust data: trustgrade.ai.