Advertisement

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Hack Database

SingularityNET: The $16.77M Bridge Hack That Paid the Thief $2.29M

A cloud breach let an attacker print 2.3 billion unbacked tokens across five crypto projects. Headlines said $16.77M. About $2.29M was cashed out.

Ben Goertzel, SingularityNET's chief executive.

Key numbers

  • $2.29M

    Stolen

  • $16.77M

    Paper value

  • 2.3B

    Tokens minted

  • Unidentified

    Attacker

At 20:21 UTC on Saturday 19 September 2026, a single transaction emptied a vault on the Ethereum blockchain of 8.72 million FET tokens, worth about $1.56 million. Two minutes and 24 seconds later the thief had swapped every one of them for 522.78 ETH, Ethereum's own currency. Nobody broke the vault open. It opened because someone showed it a valid signature.

The vault belonged to a bridge run by SingularityNET, the AI and blockchain company led by Ben Goertzel. Over the next nine hours the same attacker used that bridge, and a second permission kept in the same company's systems, to print roughly 2.3 billion new tokens out of nothing across four more coins: SingularityNET's own legacy token AGIX, NuNet's NTX, World Mobile's WMTX and Cogito's CGV. Then, at 13:10 UTC on 20 September, a SingularityNET payout contract sent its entire balance of 289,575 USDC, a digital dollar, to a wallet the attacker controlled.

On the morning of 20 September the blockchain security firm PeckShield valued what the attacker held at $16.77 million. Most headlines used that number. It was mostly paper. A transaction-by-transaction reconstruction published by Rekt News on 25 September found that the attacker turned about $2.29 million into money that could actually be spent. Bitquery, a blockchain data company that traced the attack for the Artificial Superintelligence Alliance (ASI Alliance), put the cashed-out figure at $2.25 million. The rest was freshly printed tokens that no market was deep enough to buy.

Advertisement

AI agents and automation

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.

AI agents and automation

What a bridge is

Every blockchain keeps its own ledger, rather like two stock exchanges with separate share registers that cannot read each other. Ethereum cannot see Cardano. A bridge is the currency exchange booth between them. A holder hands tokens in on one side, the booth destroys (or "burns") them there, and it issues (or "mints") the same number on the other side. The new tokens are only worth something because the old ones are gone, in the same way a booth should only hand out pounds after it has taken in the dollars.

SingularityNET's bridge linked Cardano and Ethereum for a family of related tokens, including FET, the shared token SingularityNET and Fetch.ai adopted when they merged their coins into the ASI Alliance in 2024. Its Ethereum side could not look at Cardano for itself. It trusted a messenger instead: a signing key, a secret code that works like a bank manager's signature, held on the company's own computers rather than on the blockchain. When that key signed a message saying "these tokens were burned on Cardano, release them here", the smart contract, code that moves money by itself, paid out. Bitquery counted five of these authoriser accounts across the affected bridges. None had ever sent a transaction of its own. They existed only to sign.

How one key printed money

Whoever holds that signature does not need to fake a deposit. They only need to tell the booth that a deposit happened. The security firm SlowMist identified the flaw at 02:47 UTC on 20 September. The converter's incoming payment function accepted one signature as its only check, never confirmed any burn on Cardano, and skipped the amount limit that applied in the other direction. That limit was 100 to 1,000,000 FET per conversion. The drain released 8.72 million in one go.

The other tokens followed the same logic. At 20:50 UTC on 19 September, 29 minutes after the FET drain, the attacker used NuNet's own minting permission to create 408.53 million NTX directly on the token. From 03:13 UTC on 20 September AGIX was printed in batches of 10 million. WMTX followed at 03:38. World Mobile's converter did cap each call, which only meant the attacker split the job into 503 calls. CGV was printed in 50 calls between 04:34 and 04:38. Bitquery's tally: 895.96 million AGIX, 408.53 million NTX, 500.48 million WMTX and 492.4 million CGV. By its count, unauthorised tokens made up 70.1% of all the AGIX it could measure and 81.1% of the CGV.

Before printing anything, the attacker had emptied 16 ordinary wallets in 21 minutes. Bitquery said four of them carried SingularityNET or NuNet staff labels, including the account that deployed the converters in 2022.

How the key leaked has only been described by the company. SingularityNET said on 22 September that "an unauthorized party gained access to part of our cloud infrastructure". Goertzel went further in a blog post on 30 September. He described old Amazon Web Services infrastructure "set up by some of SNET team members around 2018", and said it looked as if AI agents, chatbot-style programs set loose to work on their own, had found several small weaknesses and chained them together to reach the keys. He stressed that the forensic work was not finished.

Why $16.77M became $2.29M

PeckShield's $16.77 million was made of three things: 198.3 million AGIX valued at $14.42 million, 649 ETH at $1.67 million, and 33.54 million WMTX at $627,350. The ETH was real. The AGIX was priced at what the token traded for before hundreds of millions of new ones existed, which is like valuing counterfeit shares at the last price of the real ones. CoinMarketCap data showed AGIX falling from about 7.75 cents to under a tenth of a cent within roughly an hour. At that price the same 198.3 million AGIX was worth about $136,000.

Bar chart: $16.77M paper value against $2.29M actually takenCMZ chart. Data: PeckShield, Rekt News, Bitquery
What the attacker held on paper, and what could be spent.

Every sale proved the point. A swap of 246.2 million CGV into Cogito's trading pool returned 0.0123 ETH, around $30. Ten million NTX fetched 940 USDT, another digital dollar. A batch of 100,000 WMTX brought 0.83 ETH.

Rekt's tally up to 22 September came to about 742.7 ETH and $362,075 in digital dollars, roughly $2.29 million. The biggest piece by far was the 522.78 ETH from the stolen FET, which was real and had real buyers. The payout contract supplied $289,575. Bitquery counted only about 184 ETH and $52,395 in digital dollars from selling the counterfeit tokens. On 25 September the attacker's two main wallets still held about 824 million AGIX, 200 million WMTX and 246 million CGV.

The paper number still hurt someone. About 40 million fake NTX crossed to Cardano and landed in ordinary trading pools, which cannot tell a counterfeit token from a real one. Traders and automated market makers who paid real money for printed AGIX, WMTX and NTX now hold tokens their issuers are disowning. NTX fell by between 65% and 90% depending on the tracker. WMTX lost about 43%.

Where the money went

The cash moved quickly. The blockchain tracing firm AMLBot reported on 22 September that one 100 ETH batch had been swapped for about 266,000 USDC, moved through Circle's transfer system to Arbitrum and into the trading platform Hyperliquid, and converted into something called "FXMR", likely a stand-in for Monero, a coin built to be hard to trace. A second 100 ETH batch was turned away by a Chainflip broker, so the attacker went to THORChain instead and came out with about 3.28 BTC. Three other wallets sent 75,000 USDC to Chainflip, 75,000 USDC to Baltex, a swap service that advertises no identity checks, and 118,015 USDC to Chainflip again. About 433 ETH was still sitting in the attacker's main wallet on 25 September. No firm has publicly attributed the attack to a named group.

The aftermath

SingularityNET's first full statement came on 22 September. It said treasury and exchange wallets were not affected, that it had revoked the compromised access, switched off the affected bridges and conversion contracts, and paused AGIX and NTX transfers on Ethereum. The bridges, it said, will stay off until an independent security review finds them safe. It said it was working with law enforcement "in the relevant jurisdictions" and added: "Our systems are audited regularly and we follow industry security standards." Audits check smart contract code. They say little about who can reach the keys on a company's servers.

The clean-up was uneven. A recovery account changed the signing settings on the NuNet, Cogito and Rejuve converters and froze NTX. According to Bitquery, the AGIX and WMTX converters were controlled by multisig wallets, joint accounts that need several people to sign, so handing them over took time and minting carried on for roughly another hour. Bitquery found three of the five authoriser keys still unchanged on 20 September.

On 24 September SingularityNET said AGIX "is being retired following the security incident" and that "a replacement token will be issued for affected holders, with details to follow". It has not said who will qualify, which is the hard part when roughly seven in ten AGIX in existence were printed by the attacker and some passed through ordinary markets afterwards.

The ASI Alliance confirmed on 20 September that "an unauthorized party withdrew approximately $1.56M in FET from the converter" and promised a full report once the investigation ends. Fetch.ai said its own contracts "are not affected" and paused AGIX to FET conversions and its Ethereum bridge contract. The exchanges Bitget and KuCoin halted FET deposits for a time; SingularityNET later asked exchanges to resume them. The drained FET was the bridge's own float, not holders' coins, but the Ethereum converter is now empty while roughly 870 million FET sits on Cardano. No compensation plan has been announced for that gap, or for buyers who paid real money for counterfeit tokens.

World Mobile, a mobile network operator whose token used the same bridge, moved fastest. It asked exchanges to freeze deposits within hours, took a snapshot of balances from before the attack, and on 25 September declared Ethereum WMTX permanently deprecated, reissuing eligible balances on the Base network instead. Kraken and Coinbase reopened WMTX deposits on Base. In a live audio session on 21 September, founder Micky Watkins said Swiss and British Virgin Islands police had been notified and that around 95% of the printed WMTX could be recovered, since most of it never left the attacker's wallets.

Goertzel's 30 September post said treasury tokens and ordinary holders' tokens "were not affected", that the infrastructure had been rebuilt, and that he felt "quite bad" the team had not done more to shore up the old AWS setup. No arrests have been announced and the ETH, bitcoin and Monero the attacker cashed into are beyond any issuer's freeze button.

What this teaches

  • A bridge that trusts a single signature is only as safe as the computer holding that key. SingularityNET's Ethereum contract never checked Cardano; it believed whoever signed.
  • Limits must apply in both directions. The converter capped outgoing conversions at 1,000,000 FET but had no cap on incoming releases, so one call paid out 8.72 million.
  • Old cloud accounts are live attack surface. Goertzel traced the entry point to AWS infrastructure set up around 2018.
  • Headline losses built on freshly minted tokens are paper. $16.77M on screen became about $2.29M in spendable money, because no market could absorb billions of printed tokens.
  • Projects that plug their token into someone else's bridge inherit that bridge's security. World Mobile's supply on Ethereum was effectively controlled by a partner's cloud account.
Advertisement

Live DeFi agents

Watch four AI agents manage money in public.

Stablecoins across Base, Arbitrum, Optimism, Polygon and Avalanche. Every decision is on-chain.

Subscription opening soon. Not financial advice.

  • BASE
  • ARB
  • OP
  • POL
  • AVAX