SingularityNET Bridge Key Compromise Triggers Unauthorized Token Mints

Cross-chain bridge with a broken lock, AGIX and WMTx tokens, Ethereum and Cardano symbols, and a security analyst observing.

A security incident involving SingularityNET’s cross-chain infrastructure resulted in large unauthorized token mints on Ethereum, extending an attack cluster already linked to Fetch.ai and NuNet. PeckShield reported that the attacker had minted 260 million AGIX and 53.838 million WMTx, while valuing the wallet cluster’s holdings at approximately $16.77 million at the time of its September 20 snapshot.

At that point, the attacker held approximately 198.3 million AGIX worth $14.42 million, 649 ETH worth $1.67 million and 33.538 million WMTx worth roughly $627,000. The $16.77 million figure represents a mark-to-market snapshot of attacker holdings, not confirmed realized proceeds or an independently reconciled financial loss. Much of the inventory consisted of irregularly minted tokens whose realizable value depends on available liquidity.

Compromised Signing Authority Exposed Bridge Contracts

Subsequent forensic work indicates the incident was caused by compromised authorization keys rather than a signature-verification bypass inside the bridge contracts. SingularityNET’s converters rely on designated signing authorities to attest that tokens were burned or locked on another chain before corresponding assets are released or created. Whoever controlled the compromised keys could generate signatures the contracts considered valid even when no legitimate cross-chain event had occurred.

The incident was broader than PeckShield’s early snapshot. Bitquery later reconstructed 895.96 million unauthorized AGIX, 500.48 million WMTx and 492.40 million CGV generated through converter calls, while a separate compromised NuNet mint authority produced 408.53 million NTX. These quantities should not be added together and presented as dollar losses, because unauthorized supply, tokens still held, tokens sold and cash actually extracted are different accounting categories.

The same attacker cluster had previously removed 8.72 million FET from a Fetch.ai converter. Fetch.ai subsequently said its own contracts were not under threat, paused AGIX-to-FET conversions and suspended its Ethereum-side bridge contract as a precaution. Fetch.ai characterized SingularityNET’s Ethereum-Cardano bridge infrastructure as the principal affected area while saying FET itself continued operating normally.

Projects Move to Contain Unauthorized Supply

World Mobile separately confirmed that the SingularityNET bridge had been exploited to create WMTx on Ethereum without authorization. The project contacted exchanges to freeze affected deposits and worked with security partners to revoke minting authorities. World Mobile’s response focused on containing the irregular supply rather than indicating a compromise of World Mobile Chain itself.

NuNet represents a different attack path within the same cluster. Rather than using a converter, the attacker directly invoked the NTX token’s mint function through a compromised authority, creating approximately 408.53 million NTX. The NTX incident was unauthorized minting, not a drain of 408.5 million pre-existing tokens, an important distinction when calculating the financial impact of the broader compromise.

The final scale remains under reconciliation because security trackers captured different stages of the attack. PeckShield’s $16.77 million figure describes holdings at a particular moment, while later forensic analysis identified substantially more unauthorized token creation than its initial AGIX and WMTx counts. The next milestone will be a definitive root-cause report, reconciled cross-chain supply figures and confirmation that compromised signing authorities have been fully revoked before affected bridge and conversion services resume.

Related post

Best crypto platforms