SingularityNET Confirms Security Breach as Attacker Mints Unauthorized AGIX, NTX and Other Tokens

SingularityNET has confirmed a security incident in which an unauthorized party gained access to part of its cloud infrastructure and used compromised access to mint tokens and withdraw assets through bridge infrastructure. The incident began on September 19 and has affected several assets connected to the Artificial Superintelligence ecosystem. SingularityNET said its treasury and exchange…

4 minutes

Read Time

SingularityNET has confirmed a security incident in which an unauthorized party gained access to part of its cloud infrastructure and used compromised access to mint tokens and withdraw assets through bridge infrastructure. The incident began on September 19 and has affected several assets connected to the Artificial Superintelligence ecosystem.

SingularityNET said its treasury and exchange wallets were not affected, while FET held in users’ personal wallets or on exchanges was not impacted. The project has revoked the compromised access, deactivated affected bridges and conversion contracts, and paused AGIX and NTX transfers on Ethereum while investigations continue.

Compromised Infrastructure Triggers Token Minting

The initial incident involved FET being withdrawn from a token converter associated with the bridge infrastructure. Blockchain investigators later linked the same attacker cluster to unauthorized issuance involving NTX, AGIX, WMTx and CGV. Bitquery’s investigation identified approximately 2.3 billion token units minted or drained across five affected assets during September 19 and 20.

The FET withdrawal is different from the unauthorized token creation because it involved existing assets held by a conversion contract. On-chain investigators identified approximately 8.72 million FET leaving the affected converter, with the tokens subsequently exchanged for ETH. The amount was valued at roughly $1.5 million at the time of the transaction.

The subsequent token activity involved newly created supply rather than the direct theft of an equivalent amount of existing market value. Investigators reported unauthorized issuance of roughly 408.5 million NTX, hundreds of millions of AGIX, more than 500 million WMTx and hundreds of millions of CGV. The exact figures differ between investigations because they cover different contracts and chains.

Related: How AI, Blockchain, and Quantum Computing Will Reshape the Global Economy

That distinction is important when assessing the financial impact. A token can be minted in enormous quantities but still produce relatively limited proceeds if liquidity is insufficient to sell the newly created supply. Security researchers have therefore warned against treating the nominal value of all unauthorized tokens as realized losses.

SingularityNET said it responded by revoking the identified compromised access and shutting down the affected bridges and conversion contracts. The organization also said it is working with security partners and exchanges while tracing activity associated with the attack.

The incident also affects the migration path for AGIX holders. SingularityNET said AGIX migration has been paused while the team works on a secure and compliant method for eligible holders to transfer their tokens. The project said additional instructions will be released only after the relevant process has been confirmed.

For FET holders, SingularityNET said no action is required and that wallets containing FET were not placed at risk by the incident. Fetch.ai has separately said its own contracts remain safe and that FET continues to operate normally.

Security Review Will Determine Bridge Restart

The attack has also affected other projects connected to the infrastructure. SingularityNET said unauthorized tokens were minted involving NTX, WMTX and CGV and that it is working directly with the respective project teams on next steps.

The incident highlights the security risks associated with bridge and conversion infrastructure. These systems often connect assets and networks through privileged signing authorities, meaning a compromise of infrastructure controlling those permissions can have consequences across multiple connected tokens.

On-chain analysis has pointed toward compromised authorization and minting credentials rather than a failure of Ethereum or Cardano’s underlying consensus systems. One security investigation described the incident as an access-control compromise involving bridge and deployer keys.

SingularityNET said the affected bridges will remain deactivated until an independent security review confirms they are safe to restore. The organization is also continuing to share information with exchanges and security partners and said it is working with law enforcement in relevant jurisdictions.

The final impact remains subject to reconciliation because the unauthorized minting figures reported by blockchain investigators cover different contracts, assets and networks. Bitquery’s broader analysis identified roughly 2.3 billion units across the affected tokens, while other security reports have focused on specific Ethereum-side mints and the FET withdrawal.

For the wider AI-token ecosystem, the incident puts renewed attention on the security of bridges, cloud infrastructure and privileged signing systems. SingularityNET has urged other projects to review their external cloud infrastructure as attacks become more automated and sophisticated. Until the independent review is complete, the status of the affected bridges and token migrations remains unresolved.

About The Author

About the Author

AltCoinsAnalysis.Com

The site primarily publishes price narratives, project updates, regulatory headlines, and speculative market insights, targeting traders and investors who want quick reads on potential opportunities in the crypto space. Its content style is opinionated and momentum-focused, often centered around market hype cycles such as altcoin seasons, ETF developments, and major token announcements.

Search the Archives

Access over the years of investigative journalism and breaking reports