
SingularityNET has publicly confirmed that an unauthorized party accessed part of its cloud infrastructure on September 19 to mint tokens and withdraw assets through its bridge systems. In an official statement issued September 22, the company said treasury and exchange wallets were not affected, and that FET held in personal wallets or on exchanges remains untouched.
The confirmation comes three days after security researchers first flagged unusual on-chain activity tied to the SingularityNET bridge, and it marks the project’s most detailed public account of the incident to date. AGIX transfers remain paused while the team works on what it describes as a “secure and compliant way” for eligible holders to move their tokens, with further details still to come.
How The SingularityNET Bridge Exploit Minted AGIX, NTX And WMTx
The attacker targeted the TokenConversionManagerV3 contract, the Ethereum-side component of the bridge that links Ethereum and Cardano, draining 8.7 million FET, worth about $1.55 million, and minting at least 260 million AGIX, 408.5 million NTX and 53.8 million WMTx, according to PeckShield’s initial count, along with Cogito’s CGV. Later reports put the totals far higher, between September 19 and 20, 2026.
According to Fetch.ai’s later technical analysis, the attacker used a stolen SingularityNET bridge authorizer key to produce a valid signature for the converter call, alongside a separately compromised NuNet mint key used within the same window.
On-chain data shows the FET drain occurred first, followed roughly half an hour later by the unauthorized NTX mint, with the AGIX and WMTx mints following the next day. Security firm PeckShield valued the attacker’s holdings at about $16.77 million at the time of its alert, before AGIX’s price collapsed, including 198.3 million AGIX worth roughly $14.42 million and 649 ETH worth about $1.67 million.
Dear SingularityNET Community,
On September 19, an unauthorized party gained access to part of our cloud infrastructure and used it to mint tokens and withdraw assets through our bridge infrastructure. Treasury and exchange wallets were not affected, and FET held in your own… pic.twitter.com/OFaTWfnrdV
— SingularityNET (@SingularityNET) September 22, 2026
In its statement, Fetch.ai confirmed its contracts were unaffected, and FET token operations continued normally, while pausing AGIX-to-FET conversions and its Ethereum-side bridge contract as a precaution, even though no vulnerability was found in that contract. Exchanges responded independently as well: Bitget suspended FET deposits and withdrawals starting September 20, citing wallet maintenance, while KuCoin separately halted FET deposits over the same window.
Why Bitquery Says SingularityNET Signing Keys Stayed Live
On-chain investigators at Bitquery later identified signs of a broader compromise beyond the bridge itself. The firm reported a preliminary sweep of ETH and BNB from 16 wallets, four of which had previously been labeled as SingularityNET or NuNet staff wallets, suggesting the attacker had reached well beyond the bridge itself, along with $289,575 in USDC drained from a payroll contract. Bitquery’s report also warned that the majority of the signing keys involved in the breach had not been changed. Bitquery’s monitoring found that as of September 21 neither the conversion authorizer key nor the NuNet minter role had been changed, meaning both could still have been used two days after the first attack.
The market reaction was swift and severe. AGIX’s price collapsed by roughly 99%, wiping out about $93 million in market capitalization within 24 hours; of the attacker’s total holdings, around $2.25 million had already been realized through token sales as of September 21.
What SingularityNET’s Statement Leaves Open For AGIX Holders
SingularityNET’s September 22 statement addresses several of these threads directly. The company said it had revoked the compromised access it identified, deactivated the affected bridges and conversion contracts, and paused AGIX and NTX transfers on Ethereum. It confirmed that FET’s minting controls were not affected and that FET holders need to take no action. For the four tokens (AGIX, NTX, WMTX, and CGV) caught up in the unauthorized minting, the company said it is coordinating separately with each affected project team, with those teams expected to communicate updates through their own official channels.
Looking ahead, SingularityNET said the deactivated bridges will remain offline until an independent security review confirms they are safe to restore, with no timeline given for when that review will conclude. The company also confirmed it is working with law enforcement in relevant jurisdictions and sharing tracing data with exchanges and security partners. Notably, the statement did not directly address whether the specific signing keys implicated in the Bitquery and Fetch.ai forensic reports have since been rotated. This one detail remains as an extremely consequential open question in the entire case.
SingularityNET closed its statement by urging its community to rely only on official channels for updates, a standard precaution after major exploits, when phishing attempts and fake “recovery” offers tend to proliferate. The incident adds to a difficult year for cross-chain infrastructure: 2026 has already seen at least nine major bridge attacks, with cumulative bridge-related losses reaching about $345 million, a pattern researchers largely attribute to operational key-management failures rather than smart contract vulnerabilities.
