On-chain investigationASI AllianceBridgesEthereum

Someone minted 2.3 billion tokens in one night. Seven in every ten AGIX is now fake.

Someone holding SingularityNET's own signing keys printed AGIX, NTX, CGV and WMTX straight into wallets they controlled, then drained Fetch.ai's bridge of 8.7 million FET. The contracts issued every token. Nothing was behind them.

At a glance
Five tokens in the Artificial Superintelligence family were minted or drained on the night of 19 September with the projects' own deployer keys. The money came from one sale: 8.7 million FET taken out of Fetch.ai's conversion contract and sold for 523 ETH. The four token mints that followed were enormous on paper and nearly worthless in practice, because the pools they were sold into hold a few hundred dollars an hour. What the mints did do is break the supply. Across Ethereum and Cardano, seven in every ten AGIX and four in every five CGV now in the wild were made that night. NuNet's NTX, fixed at 1 billion tokens forever by its own docs, stands at 1.41 billion.
2.31B
Tokens minted or drained across five assets, 19–20 September
70.1%
Share of all AGIX in circulation on Ethereum and Cardano that was minted that night
$2.25M
Cashed out and still sitting in two wallets, unmoved
0
Transactions ever sent by the five bridge signing keys; three are still live
Key findingsEach line has its own share link
  1. 70.1%

    Seven in every ten AGIX on Ethereum and Cardano was minted by the attacker. Only 382,645,023 of the 1.28 billion outstanding is real. For Cogito's CGV it is eight in ten.

  2. 1.41B

    NuNet's NTX is capped at 1 billion by its own docs. We measured the real cross-chain total at 999,480,934, and the fake mint took it past 1.4 billion.

  3. 523 ETH

    One sale produced the money. Everything printed afterwards, across four tokens, returned 183.96 ETH, a third of that single trade.

  4. 0

    Transactions ever sent by the five keys that authorise these bridges. They sit on servers, and three of them are still live.

  5. 40.1M

    Counterfeit NTX crossed to Cardano within hours. About one in every eleven NTX on that chain is now fake.

  6. $289,575

    Taken from a SingularityNET payout contract at 13:10 UTC the next day, nine hours after the attack was reported as over.

01 · The night

One contract, everything it held, three minutes to a swap

Just after nine in the evening on 19 September, a contract on Ethereum did what it had done hundreds of times before. It sent FET to an address. The amount was 8.7 million tokens, and it was every token the contract held.

That contract is a converter, the bridge that moves these tokens between Cardano and Ethereum. When somebody bridges FET across, the Cardano side is locked and this contract pays out the Ethereum side from a float it keeps topped up. The float is small next to the token's total supply, because on any normal day only a trickle crosses. Three minutes later the FET was gone into a swap, and 523 ether came back the other way.

The wallet that took it was 18 days old. Its first money had arrived on 1 September from a ChangeNOW hot wallet, an instant swap service that needs no account. It sat quiet for 17 days after that.

What happened over the next 17 hours has a name, and it is not a bridge exploit in the usual sense. Nothing about the contracts was broken. The transactions were signed by keys that belong to SingularityNET and to NuNet, and the contracts took them because they were valid. Bitquery keeps its own index of Ethereum, BNB Chain and Cardano. So we counted what those keys produced. Five tokens, 2.3 billion units, and supply figures that no longer match what the projects publish.

What follows is what is left of the real supply, who ended up holding the difference, and the kind of key that made it possible. One correction runs through it. The hack was widely reported as over by 05:36. It was still running that afternoon.

02 · How the bridge works

Why one signature was enough

SingularityNET and Fetch.ai are two of the projects in the Artificial Superintelligence Alliance, a 2024 merger that folded several token projects into one. NuNet, Cogito and Rejuve.AI are smaller projects in the same family. World Mobile, a telecoms company, plugged its own token into the same plumbing in late 2024.

That plumbing is the part worth understanding, and SingularityNET documents it publicly. Each of these tokens lives on two chains at once, usually Cardano and Ethereum. To keep the total honest, moving a token from one chain to the other burns it on the side you left and creates it on the side you arrive at. A contract on each chain does the creating. It will only act when it is shown a message signed by one particular key, held by the project, which says the burn on the other chain really happened.

All of it rests on that signature. The contract does no checking of its own beyond it. So whoever holds that key can tell the contract a burn happened on Cardano when no burn happened anywhere, and the contract will mint.

03 · The sweep

Sixteen wallets emptied before a single token was minted

Before any of the minting, a sweep began.

Over 21 minutes, ether was pulled out of 16 separate wallets and into the one from 1 September. They were not random. Four carry entity labels in our own directory as SingularityNET or NuNet staff wallets, including the account that deployed the converters back in 2022. The same thing happened on BNB Chain in the same window, with BNB instead of ether. Together it came to about 18 ether, which is small money and the wrong way to read it. What it tells you is that whoever ran this held 16 private keys at once, across several firms, and started by emptying their petty cash.

It was not their first run. Eighteen days earlier the same wallet sent a little BNB to 33 other wallets in 37 seconds, then collected tokens back from them two minutes later. Small tokens, a few thousand dollars. The same script, against a smaller set of keys.

04 · The mint

Five tokens, 2.3 billion units, nine hours

Half an hour after the last wallet was emptied, the tokens started moving. The pattern changes from token to token, because the contracts are not all built the same way.

TokenProjectAmountHowWhen, UTC
FETFetch.ai8,721,530.40float transferred out, one call19 Sep 20:21
NTXNuNet408,532,878.13mint() on the token itself, one call19 Sep 20:50
AGIXSingularityNET895,962,344.7190 converter calls20 Sep 03:13–04:21
WMTXWorld Mobile500,479,231.22503 converter calls20 Sep 03:38–04:16
CGVCogito492,397,101.1650 converter calls20 Sep 04:34–04:38

Two rows stand out. The FET row took one transaction because that converter has no cap on a single call. The WMTX row took 503 because World Mobile's version of the same contract kept a per-call limit, so the tokens had to be taken a million at a time. Most of those calls are for exactly a million, which is what a limit looks like from the outside.

NuNet's row did not use a converter at all. The attacker called mint on the NTX contract itself, which means they held the token's own mint role, one level up from the bridge key.

05 · The keys

Five signing keys that have never sent a transaction

All of that came down to signatures, so it is worth asking where the signing keys actually live.

Each converter names one address as the authority whose signature it will accept. Five of them cover these projects.

None of the five has ever sent a transaction. Not once, on any day, across their whole lives.

An address that has never transacted is not sitting in somebody's hardware wallet. It has no gas, no history, no way to act on its own. It exists so a server can sign with it.

That is an ordinary design for a bridge. It also puts the whole thing inside one file on one machine, readable by anyone who gets into that machine. It is the same weak point we found behind on-chain malware. That night, three projects' keys all produced valid signatures for the same attacker inside four hours.

Three of the five have still not been changed.

06 · The money

One trade paid for the whole night

On paper the attacker printed 2.3 billion tokens. In practice almost none of it could be sold, because these tokens trade in pools holding a few hundred dollars.

The FET sale returned 523 ether. All of it printed after that, put together, returned a third of the same trade.

What was soldReturned
8.7M FET, in one trade522.78 ETH
AGIX, WMTX, NTX and CGV, everything after it183.96 ETH plus $52,395 in stablecoin
of which 438M NTXabout $40,000
of which 246M CGVabout $30

The CGV row is the one to sit with. Half a billion tokens were made, half of them were pushed into a pool, and the pool gave back about the price of a sandwich. The attacker kept the rest, which is the rational thing to do with a token you cannot sell.

FET barely moved. It has enough depth that a million-dollar sale dented it by a tenth and the price was back inside the hour. The other four were destroyed.

TokenPrice beforePrice afterChange
AGIX$0.0750$0.000762−99.0%
NTX$0.00140$0.0000168−98.8%
WMTX$0.0205$0.000294−98.6%
FET0.0000688 ETH0.0000656 ETH−4.7%

07 · The supply

The damage that outlives the price

The price will recover or it will not. The supply will not.

Every token that exists was minted once and every token destroyed was burned, so counting both on all three chains gives what is actually out there. Take out what was made that night and what is left is the real float.

TokenOut there nowCounterfeitGenuineFake share
AGIX1,278,607,367895,962,345382,645,02370.1%
CGV606,823,659492,397,101114,426,55881.1%
WMTX1,545,922,616500,479,2311,045,443,38532.4%
NTX1,408,013,812408,532,878999,480,93429.0%

The NTX row is the one that proves the rest. NuNet fixes its supply at 1 billion tokens, minted once at launch and split across two chains, and bridging is meant to keep that total flat forever. Our figure for the genuine total is 999,480,934. That is 0.05% under the published cap, and the gap is dust burned over four years.

A count that lands on a fixed number to four figures is a count you can trust. The 408 million sitting on top of it is fake and nothing else.

08 · The spread

It did not stay on Ethereum

Within two hours of the AGIX mint, people were moving the new tokens off the chain where the price had crashed.

WMTX left Ethereum through its own bridge at a rate no other day comes close to. The selling started four minutes after the fake mint began, came from hundreds of wallets, and ran all morning. Nearly 7 million tokens arrived on BNB Chain.

WMTX leaving EthereumTokens burned for transferTransactions
13–19 Sep, per day59,000 to 280,0003 to 7
20 Sep20,655,9951,918

Cardano took the NTX. It minted 40.1 million of them that evening, against a few hundred thousand on an ordinary day. On quiet days the two sides match to the token, so we know this is the same supply crossing over and not normal traffic. Roughly one in every eleven NTX on Cardano is now fake.

Binance took the AGIX. Its hot wallet received 17.2 million of them that morning. Five days earlier it took 7,906.

09 · The race

Someone inside was fighting back

From half past three that morning a second new wallet starts doing the opposite of all of the above.

It was funded that morning by the address that has paid gas to SingularityNET's staff wallets since 2023. It never took a single token. It grabbed the NuNet and Cogito converters and pointed their signing key at itself, then did the same to two converters on BNB Chain. It reached Rejuve.AI's converter, which the attacker never touched at all, at half past three. Later that morning it stripped the burnt NuNet account of its admin rights and froze the NTX token outright.

It has held unlimited minting rights over two tokens since that morning and has minted nothing.

What it could not reach were the AGIX and WMTX converters, because multisig wallets own those and a single stolen key cannot move a multisig. Those two kept bleeding for another hour while the handovers went through. You can read the whole night as a race between somebody with one set of keys and somebody else with the same set.

10 · After lunch

It did not stop when the reports said it had

The coverage settled on 05:36 as the end. We checked again later that day.

Just after lunch the deployer account sent a little gas to one of the 16 wallets swept the night before. Seconds later a payout contract, which had been sending salaries and invoices out in batches since December 2025, handed that wallet its entire balance of $289,575 in USDC. Twelve seconds after that the money was in the attacker's second wallet, where it still sits. The contract now holds nothing.

Over the rest of the day another 52 million WMTX were sold and four more fills came in. The total cashed out is $2.25 million, held as ether, USDC and a MetaMask stablecoin across two wallets. Nothing has gone to a mixer or a CEX.

Two numbers doing the rounds are worth correcting. A widely quoted estimate put the haul at $16.77 million. That figure covers one of the two wallets and prices the tokens in it at what they cost before the attack, which is roughly 95 times what AGIX actually trades at now. A second count put the WMTX mint at 504 calls. One of those was a real customer using a different contract, and the attacker made 503.

11 · The bill

Who is actually out of pocket

Apart from the last $289,575, the attacker's $2.25 million came out of liquidity pools. The LPs put up ether and stablecoin and got freshly minted tokens back. After them come the people who bought AGIX, NTX, WMTX or CGV on the way down and are holding a token that fell by more than nine tenths.

Then there is a quieter group. Fetch.ai's conversion float is empty. Cardano carries 870 million FET, and anyone who now burns FET there expecting to collect it on Ethereum cannot be paid until somebody refills that contract. Nobody has tried since the drain, so nothing is stuck yet. And about 40 million fake NTX now sits inside ordinary Cardano liquidity pools, where it cannot be told apart from the real thing, because on that chain it is the real thing.

12 · Still open

Three keys nobody has changed

Three of the five signing keys have not been changed. The minting stopped when the attacker chose to stop. Nothing on-chain closed the door. The payout contract that lost its cash is fed by another wallet which still holds $460,324. The AGIX and WMTX converters were never rescued, because a Gnosis Safe owns one and a 3-of-4 Safe owns the other. A stolen key beats an audit, which is the same lesson as the Tectonic drain.

WhatAddress
Attacker wallet 10x2dcc…1dfe
Attacker wallet 20x83f4…09c5
SingularityNET deployer, signed the AGIX mints0xa7a3…ee48
NuNet deployer, signed the NTX mint0x863f…2165
Fetch.ai converter, drained to zero0xab42…f3a3
SingularityNET AGIX converter0x6111…7be4
World Mobile WMTX converter0x63bb…d392
Cogito CGV converter0x6985…5a79
NuNet NTX converter0x6c0d…d1cf
The recovery wallet0x78a6…ef00
Payout contract drained of USDC0x7ffe…566b
The FET sale0x98f6…6d1c
Run it yourself

Ask these questions in plain English

Every count above came from queries anyone can run against the same index. The Bitquery MCP server puts that index behind an AI assistant, so you can ask which wallets a token contract has minted to, what a bridge contract holds today, how much of a token exists on each chain, or where a wallet's sale proceeds landed, without writing the query yourself. The Ethereum API and the docs cover the same data directly.

Total a token's mints and burns per chain to get real supplyList every address a contract minted to in a time windowFollow swap proceeds from a wallet back to the pool they came out ofCompare the same token's supply on Ethereum, Cardano and BNB Chain
Explore Bitquery MCP Figures measured 20 September 2026 against Bitquery's Ethereum, BNB Chain and Cardano indexes. Ethereum at block time 14:28 UTC, Cardano at 10:10 UTC. Written by Bitquery Research from those indexes; AI tools ran the queries and drafted the text, and every figure was re-derived from the raw data and checked before publishing.
Legal disclaimer

The on-chain record shows which keys signed these transactions and where the value moved. It cannot show how the attacker came to hold those keys, and we make no claim about that, nor about the conduct of SingularityNET, Fetch.ai, NuNet, Cogito, Rejuve.AI or World Mobile. Wallets described as belonging to those projects are labelled from our own address directory and from their own on-chain deployment history, and a label may be wrong. The wallet described as a recovery wallet is identified by behaviour, by its funding from an address that has paid gas to those projects since 2023, and by the fact that it has taken no tokens; we do not know who controls it. Supply figures are mints minus burns on the chains named and exclude any chain not listed, so the WMTX total is a floor. Prices are from Ethereum pools and are not exchange prices. Settlement fills from request-for-quote venues index late, so the proceeds figure is a floor. ChangeNOW appears only as the label on a hot wallet that sent funds, which says nothing about that company's conduct.

This article is provided for informational and educational purposes only. It reflects analysis of publicly available on-chain data as of the dates given, and does not constitute legal, financial, compliance, tax or investment advice, nor a recommendation or offer to buy, sell or hold any asset. Blockchain addresses are pseudonymous: a transaction between two addresses does not by itself establish the identity, intent or knowledge of any party, and every entity attribution here is an inference that may be incomplete or wrong. Readers should verify independently before acting on anything above, and Bitquery accepts no liability for loss arising from reliance on this material. All trademarks and company names are the property of their respective owners. Corrections and right-of-reply requests go to support@bitquery.io.