Fetch.ai, NuNet, and SingularityNET have been targeted in a series of interconnected cyber attacks. The hacker managed to withdraw FET and issue hundreds of millions of tokens from various projects, according to experts at PeckShield.

— PeckShieldAlert (@PeckShieldAlert) September 20, 2026

Initial Withdrawal of FET and Issuance of NTX

The attacks commenced on the evening of September 19. Initially, the hacker withdrew 8.7 million FET from Fetch.ai's conversion contract, valued at approximately $1.53 million.

About thirty minutes later, the same cluster of addresses received 408.5 million newly minted NTX, created through a NuNet account.

Preliminary analysis suggests that the hacker used a valid signature from an authorized address to withdraw the FET. The conversionIn() function accepted this as confirmation of the operation without verifying whether the corresponding assets were locked or destroyed on another network, allowing the entire available balance of the converter to be accessed in a single transaction.

In the case of NTX, the hacker exploited the rights to issue the asset and created around 408 million coins. According to Bitquery, prior to the incident, the total supply of NTX was approximately 591 million, but the unauthorized issuance pushed it to the maximum limit of 1 billion tokens.

Some of the FET and NTX were exchanged for ETH. Early in the attack, the hacker converted assets worth about 546.36 ETH (around $1.44 million), as reported by PeckShield.

Subsequent Attack on SingularityNET Bridge

On September 20, PeckShield reported that the attack continued, with 260 million AGIX and 53.838 million WMTx being issued without authorization through the SingularityNET infrastructure on Ethereum.

At that time, analysts estimated the assets on the related addresses to be around $16.77 million, comprising 198.3 million AGIX, 649 ETH, and 33.538 million WMTx. This figure represented the market value of the balances on the addresses, rather than the actual profit for the hacker.

World Mobile confirmed the unauthorized issuance of WMTx via the SingularityNET bridge and began contacting exchanges to halt deposits while revoking rights to create new tokens.

Importantly, the Cardano network and World Mobile infrastructure remained unaffected.

Security Notice ⚠️

We have identified an exploit of the @SingularityNET bridge that has resulted in the unauthorised minting of $WMTx on Ethereum. This had led to recent price action across all exchanges that $WMTx is listed on.

Our team is actively responding:
• We are in…

— World Mobile Chain (@wmchain) September 20, 2026

Later, Bitquery reported significantly more operations than initially recorded by PeckShield. Experts indicated that overnight, the hacker issued approximately 896 million AGIX, 500.5 million WMTx, 492.4 million CGV from Cogito Finance, and 408.5 million NTX.

Including the withdrawn 8.72 million FET, the total number of affected tokens reached around 2.3 billion.

While the nominal value of the issued tokens was high, this does not equate to a similar level of damage. Bitquery estimated the actual realized assets and funds remaining on the hacker's two main addresses to be about $2.25 million.

There was insufficient liquidity to sell hundreds of millions of additionally issued tokens at market prices.

Analysts also discovered that ETH was withdrawn from 16 wallets before the issuance began, with four of these linked to employees of SingularityNET or NuNet.

This suggests a compromise of several private keys, although the method of acquisition remains undetermined.

Developers' Responses

The teams at Fetch.ai and SingularityNET took immediate action by disabling the affected wallets and contracts.

Following reports of an exploit on 19 September, here is where things stand.
> https://t.co/CwbPmOj7TU contracts are not affected. No https://t.co/CwbPmOj7TU contract is under threat at this time, and FET continues to operate normally.
> The attack is targeting SingularityNET…

— Fetch.ai (@Fetch_ai) September 20, 2026

The conversion of AGIX to FET has been halted, and the Ethereum bridge for Fetch.ai was also suspended as a precaution. The team assured that the core contracts of Fetch.ai are not compromised and that the network continues to operate. The investigation is ongoing.

World Mobile has also requested users to temporarily refrain from interacting with WMTx and is preparing a snapshot of the network's state prior to the incident.

It is worth noting that in 2024, SingularityNET, Fetch.ai, and Ocean Protocol agreed to combine their tokens as part of the Artificial Superintelligence Alliance.