Someone minted 2.3 billion tokens in one night. Seven in every ten AGIX is now fake.
Someone holding SingularityNET's own signing keys printed AGIX, NTX, CGV and WMTX straight into wallets they controlled, then drained Fetch.ai's bridge of 8.7 million FET. The contracts issued every token. Nothing was behind them.
- 70.1%
- 1.41B
- 523 ETH
- 0
- 40.1M
- $289,575
01 · The night
One contract, everything it held, three minutes to a swap
Just after nine in the evening on 19 September, a contract on Ethereum did what it had done hundreds of times before. It sent FET to an address. The amount was 8.7 million tokens, and it was every token the contract held.
That contract is a converter, the bridge that moves these tokens between Cardano and Ethereum. When somebody bridges FET across, the Cardano side is locked and this contract pays out the Ethereum side from a float it keeps topped up. The float is small next to the token's total supply, because on any normal day only a trickle crosses. Three minutes later the FET was gone into a swap, and 523 ether came back the other way.
The wallet that took it was 18 days old. Its first money had arrived on 1 September from a ChangeNOW hot wallet, an instant swap service that needs no account. It sat quiet for 17 days after that.
What happened over the next 17 hours has a name, and it is not a bridge exploit in the usual sense. Nothing about the contracts was broken. The transactions were signed by keys that belong to SingularityNET and to NuNet, and the contracts took them because they were valid. Bitquery keeps its own index of Ethereum, BNB Chain and Cardano. So we counted what those keys produced. Five tokens, 2.3 billion units, and supply figures that no longer match what the projects publish.
What follows is what is left of the real supply, who ended up holding the difference, and the kind of key that made it possible. One correction runs through it. The hack was widely reported as over by 05:36. It was still running that afternoon.
02 · How the bridge works
Why one signature was enough
SingularityNET and Fetch.ai are two of the projects in the Artificial Superintelligence Alliance, a 2024 merger that folded several token projects into one. NuNet, Cogito and Rejuve.AI are smaller projects in the same family. World Mobile, a telecoms company, plugged its own token into the same plumbing in late 2024.
That plumbing is the part worth understanding, and SingularityNET documents it publicly. Each of these tokens lives on two chains at once, usually Cardano and Ethereum. To keep the total honest, moving a token from one chain to the other burns it on the side you left and creates it on the side you arrive at. A contract on each chain does the creating. It will only act when it is shown a message signed by one particular key, held by the project, which says the burn on the other chain really happened.
All of it rests on that signature. The contract does no checking of its own beyond it. So whoever holds that key can tell the contract a burn happened on Cardano when no burn happened anywhere, and the contract will mint.
03 · The sweep
Sixteen wallets emptied before a single token was minted
Before any of the minting, a sweep began.
Over 21 minutes, ether was pulled out of 16 separate wallets and into the one from 1 September. They were not random. Four carry entity labels in our own directory as SingularityNET or NuNet staff wallets, including the account that deployed the converters back in 2022. The same thing happened on BNB Chain in the same window, with BNB instead of ether. Together it came to about 18 ether, which is small money and the wrong way to read it. What it tells you is that whoever ran this held 16 private keys at once, across several firms, and started by emptying their petty cash.
It was not their first run. Eighteen days earlier the same wallet sent a little BNB to 33 other wallets in 37 seconds, then collected tokens back from them two minutes later. Small tokens, a few thousand dollars. The same script, against a smaller set of keys.
04 · The mint
Five tokens, 2.3 billion units, nine hours
Half an hour after the last wallet was emptied, the tokens started moving. The pattern changes from token to token, because the contracts are not all built the same way.
| Token | Project | Amount | How | When, UTC |
|---|---|---|---|---|
| FET | Fetch.ai | 8,721,530.40 | float transferred out, one call | 19 Sep 20:21 |
| NTX | NuNet | 408,532,878.13 | mint() on the token itself, one call | 19 Sep 20:50 |
| AGIX | SingularityNET | 895,962,344.71 | 90 converter calls | 20 Sep 03:13–04:21 |
| WMTX | World Mobile | 500,479,231.22 | 503 converter calls | 20 Sep 03:38–04:16 |
| CGV | Cogito | 492,397,101.16 | 50 converter calls | 20 Sep 04:34–04:38 |
Two rows stand out. The FET row took one transaction because that converter has no cap on a single call. The WMTX row took 503 because World Mobile's version of the same contract kept a per-call limit, so the tokens had to be taken a million at a time. Most of those calls are for exactly a million, which is what a limit looks like from the outside.
NuNet's row did not use a converter at all. The attacker called mint on the
NTX contract itself, which means they held the token's own mint role, one level
up from the bridge key.
05 · The keys
Five signing keys that have never sent a transaction
All of that came down to signatures, so it is worth asking where the signing keys actually live.
Each converter names one address as the authority whose signature it will accept. Five of them cover these projects.
None of the five has ever sent a transaction. Not once, on any day, across their whole lives.
An address that has never transacted is not sitting in somebody's hardware wallet. It has no gas, no history, no way to act on its own. It exists so a server can sign with it.
That is an ordinary design for a bridge. It also puts the whole thing inside one file on one machine, readable by anyone who gets into that machine. It is the same weak point we found behind on-chain malware. That night, three projects' keys all produced valid signatures for the same attacker inside four hours.
Three of the five have still not been changed.
06 · The money
One trade paid for the whole night
On paper the attacker printed 2.3 billion tokens. In practice almost none of it could be sold, because these tokens trade in pools holding a few hundred dollars.
The FET sale returned 523 ether. All of it printed after that, put together, returned a third of the same trade.
| What was sold | Returned |
|---|---|
| 8.7M FET, in one trade | 522.78 ETH |
| AGIX, WMTX, NTX and CGV, everything after it | 183.96 ETH plus $52,395 in stablecoin |
| of which 438M NTX | about $40,000 |
| of which 246M CGV | about $30 |
The CGV row is the one to sit with. Half a billion tokens were made, half of them were pushed into a pool, and the pool gave back about the price of a sandwich. The attacker kept the rest, which is the rational thing to do with a token you cannot sell.
FET barely moved. It has enough depth that a million-dollar sale dented it by a tenth and the price was back inside the hour. The other four were destroyed.
| Token | Price before | Price after | Change |
|---|---|---|---|
| AGIX | $0.0750 | $0.000762 | −99.0% |
| NTX | $0.00140 | $0.0000168 | −98.8% |
| WMTX | $0.0205 | $0.000294 | −98.6% |
| FET | 0.0000688 ETH | 0.0000656 ETH | −4.7% |
07 · The supply
The damage that outlives the price
The price will recover or it will not. The supply will not.
Every token that exists was minted once and every token destroyed was burned, so counting both on all three chains gives what is actually out there. Take out what was made that night and what is left is the real float.
| Token | Out there now | Counterfeit | Genuine | Fake share |
|---|---|---|---|---|
| AGIX | 1,278,607,367 | 895,962,345 | 382,645,023 | 70.1% |
| CGV | 606,823,659 | 492,397,101 | 114,426,558 | 81.1% |
| WMTX | 1,545,922,616 | 500,479,231 | 1,045,443,385 | 32.4% |
| NTX | 1,408,013,812 | 408,532,878 | 999,480,934 | 29.0% |
The NTX row is the one that proves the rest. NuNet fixes its supply at 1 billion tokens, minted once at launch and split across two chains, and bridging is meant to keep that total flat forever. Our figure for the genuine total is 999,480,934. That is 0.05% under the published cap, and the gap is dust burned over four years.
A count that lands on a fixed number to four figures is a count you can trust. The 408 million sitting on top of it is fake and nothing else.
08 · The spread
It did not stay on Ethereum
Within two hours of the AGIX mint, people were moving the new tokens off the chain where the price had crashed.
WMTX left Ethereum through its own bridge at a rate no other day comes close to. The selling started four minutes after the fake mint began, came from hundreds of wallets, and ran all morning. Nearly 7 million tokens arrived on BNB Chain.
| WMTX leaving Ethereum | Tokens burned for transfer | Transactions |
|---|---|---|
| 13–19 Sep, per day | 59,000 to 280,000 | 3 to 7 |
| 20 Sep | 20,655,995 | 1,918 |
Cardano took the NTX. It minted 40.1 million of them that evening, against a few hundred thousand on an ordinary day. On quiet days the two sides match to the token, so we know this is the same supply crossing over and not normal traffic. Roughly one in every eleven NTX on Cardano is now fake.
Binance took the AGIX. Its hot wallet received 17.2 million of them that morning. Five days earlier it took 7,906.
09 · The race
Someone inside was fighting back
From half past three that morning a second new wallet starts doing the opposite of all of the above.
It was funded that morning by the address that has paid gas to SingularityNET's staff wallets since 2023. It never took a single token. It grabbed the NuNet and Cogito converters and pointed their signing key at itself, then did the same to two converters on BNB Chain. It reached Rejuve.AI's converter, which the attacker never touched at all, at half past three. Later that morning it stripped the burnt NuNet account of its admin rights and froze the NTX token outright.
It has held unlimited minting rights over two tokens since that morning and has minted nothing.
What it could not reach were the AGIX and WMTX converters, because multisig wallets own those and a single stolen key cannot move a multisig. Those two kept bleeding for another hour while the handovers went through. You can read the whole night as a race between somebody with one set of keys and somebody else with the same set.
10 · After lunch
It did not stop when the reports said it had
The coverage settled on 05:36 as the end. We checked again later that day.
Just after lunch the deployer account sent a little gas to one of the 16 wallets swept the night before. Seconds later a payout contract, which had been sending salaries and invoices out in batches since December 2025, handed that wallet its entire balance of $289,575 in USDC. Twelve seconds after that the money was in the attacker's second wallet, where it still sits. The contract now holds nothing.
Over the rest of the day another 52 million WMTX were sold and four more fills came in. The total cashed out is $2.25 million, held as ether, USDC and a MetaMask stablecoin across two wallets. Nothing has gone to a mixer or a CEX.
Two numbers doing the rounds are worth correcting. A widely quoted estimate put the haul at $16.77 million. That figure covers one of the two wallets and prices the tokens in it at what they cost before the attack, which is roughly 95 times what AGIX actually trades at now. A second count put the WMTX mint at 504 calls. One of those was a real customer using a different contract, and the attacker made 503.
11 · The bill
Who is actually out of pocket
Apart from the last $289,575, the attacker's $2.25 million came out of liquidity pools. The LPs put up ether and stablecoin and got freshly minted tokens back. After them come the people who bought AGIX, NTX, WMTX or CGV on the way down and are holding a token that fell by more than nine tenths.
Then there is a quieter group. Fetch.ai's conversion float is empty. Cardano carries 870 million FET, and anyone who now burns FET there expecting to collect it on Ethereum cannot be paid until somebody refills that contract. Nobody has tried since the drain, so nothing is stuck yet. And about 40 million fake NTX now sits inside ordinary Cardano liquidity pools, where it cannot be told apart from the real thing, because on that chain it is the real thing.
12 · Still open
Three keys nobody has changed
Three of the five signing keys have not been changed. The minting stopped when the attacker chose to stop. Nothing on-chain closed the door. The payout contract that lost its cash is fed by another wallet which still holds $460,324. The AGIX and WMTX converters were never rescued, because a Gnosis Safe owns one and a 3-of-4 Safe owns the other. A stolen key beats an audit, which is the same lesson as the Tectonic drain.
| What | Address |
|---|---|
| Attacker wallet 1 | 0x2dcc…1dfe |
| Attacker wallet 2 | 0x83f4…09c5 |
| SingularityNET deployer, signed the AGIX mints | 0xa7a3…ee48 |
| NuNet deployer, signed the NTX mint | 0x863f…2165 |
| Fetch.ai converter, drained to zero | 0xab42…f3a3 |
| SingularityNET AGIX converter | 0x6111…7be4 |
| World Mobile WMTX converter | 0x63bb…d392 |
| Cogito CGV converter | 0x6985…5a79 |
| NuNet NTX converter | 0x6c0d…d1cf |
| The recovery wallet | 0x78a6…ef00 |
| Payout contract drained of USDC | 0x7ffe…566b |
| The FET sale | 0x98f6…6d1c |
Ask these questions in plain English
Every count above came from queries anyone can run against the same index. The Bitquery MCP server puts that index behind an AI assistant, so you can ask which wallets a token contract has minted to, what a bridge contract holds today, how much of a token exists on each chain, or where a wallet's sale proceeds landed, without writing the query yourself. The Ethereum API and the docs cover the same data directly.
The on-chain record shows which keys signed these transactions and where the value moved. It cannot show how the attacker came to hold those keys, and we make no claim about that, nor about the conduct of SingularityNET, Fetch.ai, NuNet, Cogito, Rejuve.AI or World Mobile. Wallets described as belonging to those projects are labelled from our own address directory and from their own on-chain deployment history, and a label may be wrong. The wallet described as a recovery wallet is identified by behaviour, by its funding from an address that has paid gas to those projects since 2023, and by the fact that it has taken no tokens; we do not know who controls it. Supply figures are mints minus burns on the chains named and exclude any chain not listed, so the WMTX total is a floor. Prices are from Ethereum pools and are not exchange prices. Settlement fills from request-for-quote venues index late, so the proceeds figure is a floor. ChangeNOW appears only as the label on a hot wallet that sent funds, which says nothing about that company's conduct.
This article is provided for informational and educational purposes only. It reflects analysis of publicly available on-chain data as of the dates given, and does not constitute legal, financial, compliance, tax or investment advice, nor a recommendation or offer to buy, sell or hold any asset. Blockchain addresses are pseudonymous: a transaction between two addresses does not by itself establish the identity, intent or knowledge of any party, and every entity attribution here is an inference that may be incomplete or wrong. Readers should verify independently before acting on anything above, and Bitquery accepts no liability for loss arising from reliance on this material. All trademarks and company names are the property of their respective owners. Corrections and right-of-reply requests go to support@bitquery.io.