T
iTokenly

SingularityNET bridge (compromised signing keys) hack — September 2026

Verified — 4 sourcesLast checked September 25, 2026

Incident facts

Date of incident
Target typeCross-chain bridge
Loss$1,550,000Published estimates range $1,530,000 to $2,010,000Price at time of incident
MethodPrivate key compromiseA compromised backend authorisation key signed a conversionIn call that released the entire FET balance of the Ethereum-side conversion contract, whose per-transaction cap did not apply in that direction and whose signed message did not bind the recipient; a separate NuNet minter key dormant since March 2023 was used to mint NTX
ChainsEthereum
OutcomeUnresolved

What happened

An attacker holding compromised keys across the SingularityNET bridge stack emptied the Ethereum-side FET conversion contract on 19 September 2026. At 20:21:47 UTC, in Ethereum block 26,013,913, a single call to the contract's conversionIn function released 8,721,530.40 FET to an attacker-controlled wallet, about $1.55m at the time; this registry read the transfer from the chain. The contract, TokenConversionManagerV3, is the lock-and-release component of SingularityNET's Ethereum-Cardano bridge and is tied to the Artificial Superintelligence Alliance's FET token.

The transaction carried a valid signature from the address the contract was configured to trust, so a forensic report prepared by Athena traced the loss to a compromised backend authorisation key rather than to a way around the contract. The design made it worse: the contract's 1 million FET per-transaction cap applied to tokens leaving Ethereum but was not enforced on conversionIn, and the signed message did not bind the recipient, so a valid authorisation could send the tokens wherever the caller chose.

The same operation used other credentials. Twenty-nine minutes after the FET drain, a NuNet minter key dormant since March 2023 created 408,532,878 NTX, about 42% of NuNet's documented supply, and sent it to the same wallet; the attacker sold more than 217 million of it until the pools ran dry, and NTX fell by as much as 95%. On 20 September the same cluster minted 260 million AGIX and 53.8 million World Mobile Token (WMTx) on Ethereum, and Bitquery counted about 2.3 billion unauthorised units across AGIX, NTX, CGV and WMTx. PeckShield valued the cluster's holdings at about $16.77m that day, $14.42m of it in 198.3 million AGIX, but that is a screen-price value of newly minted tokens that could not be sold at anything like that rate, so it is not recorded as a loss. The headline is the $1.55m of FET that actually left the contract; the upper end of the range, about $2.01m, is the combined figure reported for the FET drain and the NTX mint at the time of the moves.

Fetch.ai said its own contracts were not under threat and that the attack targeted SingularityNET's contracts, primarily the bridge between Ethereum and Cardano; it paused AGIX-to-FET conversions and its Ethereum-side bridge as a precaution. World Mobile Chain confirmed the unauthorised WMTx mint and said it was asking exchanges to freeze deposits and revoking minting authority, and Bitvavo suspended WMTX deposits, withdrawals and trading. By about 01:10 UTC on 20 September the attacker's main wallet held 547.89 ETH, roughly $1.44m. Nothing has been reported as frozen or recovered, and SingularityNET had not published an incident statement of its own when The Crypto Times reported on 21 September.

Sources

  1. CryptoSlateSecondary · retrieved 2026-09-25
  2. The Crypto TimesSecondary · retrieved 2026-09-25
  3. Crowdfund InsiderSecondary · retrieved 2026-09-25
  4. Ethereum transaction logs, read by this registryOn-chain · retrieved 2026-09-25

Changes to this entry

  • Recorded six days after the incident. The headline is the 8,721,530.40 FET drained from the conversion contract, confirmed by this registry from the transaction logs. The NTX, AGIX and WMTx mints are described but not added at screen price, because newly minted tokens in thin markets cannot be sold at that rate.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SingularityNET bridge (compromised signing keys) hack — September 2026", iTokenly, accessed 2026-09-25, https://itokenly.com/hacks/singularitynet-bridge-signing-keys
https://itokenly.com/hacks/singularitynet-bridge-signing-keys

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.