The AI-crypto sector, one of the hottest narratives of the cycle, just took a serious hit. An attacker exploited a cross-chain bridge tied to SingularityNET, minting hundreds of millions of unauthorized tokens across a cluster of connected AI projects including Fetch.ai and NuNet, and holding an estimated $16.8 million in stolen value. Some of the affected tokens crashed by as much as 90%. It's a textbook example of crypto's most dangerous attack surface, and a wake-up call for a booming sector.
What happened
The attack unfolded over the weekend, beginning September 19. According to security firm PeckShield and analysis from Fetch.ai, the attacker used a stolen SingularityNET bridge "authorizer key" to produce a valid signature for the bridge's token-conversion function, alongside a separately compromised NuNet mint key. Because the attacker held legitimate signing keys, the system treated the fraudulent transactions as authorized.
The scale grew as it unfolded. The exploit first drained Fetch.ai's Ethereum-based token converter and produced 408.5 million unauthorized NuNet Tokens (NTX), then widened into a broader key-compromise event as the same attacker minted 260 million SingularityNET tokens (AGIX) and 53.8 million World Mobile Tokens (WMTx) on Ethereum. PeckShield valued the attacker's Ethereum holdings at roughly $16.77 million at the time of its alert, including about 198 million AGIX (~$14.4M) and 649 ETH (~$1.67M). Blockchain analytics firm Bitquery noted the attacker's realized profit so far was smaller, around $2.25 million, but the nominal value of the minted tokens was far higher.
The damage
The consequences rippled fast. As the newly minted supply hit the market, prices of the affected tokens fell sharply: NTX dropped between 65% and more than 90% depending on the tracker, and WMTx fell around 43%. Exchanges reacted defensively, Bitget suspended FET deposits and withdrawals citing wallet maintenance, and KuCoin was reported to have halted FET deposits over the same window. The attacker also reportedly swept ETH and BNB from 16 wallets (some previously labeled as staff wallets) and drained roughly $289,000 in USDC from a payroll contract, indicating deep penetration of the interconnected companies' infrastructure.
Importantly, the projects moved to contain and clarify the damage. Fetch.ai stated its own smart contracts remain secure and that FET operates normally, pausing AGIX-to-FET conversions and its Ethereum-side bridge as a precaution even though no vulnerability was found in Fetch.ai's own contracts. The breach was specific to the SingularityNET bridge route connecting Ethereum and Cardano.
Why this matters for the AI-crypto sector
The victims here aren't random tokens, they're founding members of the Artificial Superintelligence (ASI) Alliance, the flagship coalition of the AI-crypto narrative that includes SingularityNET, Fetch.ai, NuNet, and others. AI-plus-crypto has been one of the market's most-hyped themes, so a multi-million-dollar exploit tearing through its core infrastructure is a significant blow to confidence in the sector, even though the underlying AI technology wasn't what failed.
What failed was, once again, a bridge. Cross-chain bridges are among the most-attacked targets in all of crypto because they hold or control token supply across two separate chains, making them concentrated honeypots, and because a single compromised key can unlock catastrophic, "valid-looking" minting. This incident joins a relentless 2026 run of bridge and cross-chain failures (from the $320M Liquid Network exploit to a string of others), reinforcing that the connective tissue between blockchains remains crypto's weakest structural link. A particularly concerning detail: reporting indicated the majority of the compromised signing keys had not yet been changed, leaving open questions about whether the threat is fully contained.
Why it matters
For users, the SingularityNET hack carries the same hard lessons that keep recurring: bridges are high-risk infrastructure, "the project's main contracts are safe" doesn't mean your tokens on a connected route are safe, and a compromise of signing keys can be as devastating as a code bug. For the AI-crypto sector specifically, it's a reputational and financial setback at a moment when the narrative was riding high. The projects are coordinating a response and the exploit appears contained, but with tokens down heavily and key questions about signing-key security unresolved, the ASI ecosystem has real trust-rebuilding ahead. As always in these moments, users should be extra alert to phishing and impersonation, and verify every instruction through official project channels only.
This is educational information, not financial or security advice. Verify all updates through official project channels. Always do your own research.




