SingularityNET cross-chain bridge attacked: Who pays the price for the minting out of thin air?

CN
2 hours ago

On September 20, when security agencies and project parties captured abnormal minting transactions on the Ethereum network, they discovered that the same hacker who had previously attacked Fetch.ai and NuNet repeatedly was once again targeting the cross-chain bridge of SingularityNET along the same technical vein. The root weakness was not in the front-end contract logic but in the theft of the back-end authorization signature key after cross-chain/bridging: once in possession of this "master key," the attacker could initiate formally compliant yet unauthorized minting requests on-chain. According to a single on-chain analysis report, the hacker unauthorizedly minted approximately 260 million AGIX and about 53.83 million WMTx/WMTX on Ethereum, subsequently transferring some of these assets to their controlled wallet address. As of the current analysis node, the attacker holds approximately 16.77 million dollars in crypto assets, including around 198.3 million AGIX valued at approximately 14.42 million dollars. Fetch.ai and SingularityNET have jointly disabled the affected wallets and contracts in an attempt to "intercept" the attack path at the protocol level, but this incident of sudden token supply expansion further confirms that in cross-chain infrastructure, once the back-end signature key management fails, a single point of failure can quickly transform into systemic security risks and crises of trust.

The Same Hacker Strikes Three Times: The Expansion of the Attack Landscape

According to disclosures from security agencies like PeckShield, the address behind the SingularityNET cross-chain bridge incident is highly consistent with those used in the previous attacks on Fetch.ai and NuNet, demonstrating that the same entity launched attacks in a close time frame to accomplish a "three-attack sequence" around the same narrative ecosystem. The first two attacks have proven that this attacker not only understands the contract structures and deployment habits of the relevant projects, but also comprehends the underlying infrastructure architecture, allowing them to reuse their technical stack and criminal paths across different protocols, while public information still cannot confirm their real identity or organizational affiliation.

As the attack target extended from Fetch.ai and NuNet to the SingularityNET cross-chain/bridge contract exposed on September 20, the event became more than just an incident for a single project; it began to resemble a concentrated stress test of the entire technology stack and security management model related to AI protocols. All three attacks were anchored in similar contract designs and backend authorization mechanisms, indicating that as long as vulnerabilities exist in core key management or bridging logic, a single attack path may be reused across a broader ecosystem, shifting the risk from a single token to a wider group of related protocols.

Key Management Failure: Cross-Chain Bridge Becomes a Minting Machine

In the conventional design of cross-chain bridges, the back-end authorization signature key plays the role of the "final arbiter": when an asset on a certain chain is locked or destroyed, the back-end service generates a signed message and submits it to the bridging or token contract on the target chain to trigger minting or unlocking of the corresponding asset. The on-chain contract itself does not know what is happening in the real world; it only verifies the validity of the signature. Therefore, this key essentially serves as the single point of trust for the entire cross-chain and minting process. Once compromised, all contracts relying on it are instantly exposed to the same attack path.

In this incident, the theft of the SingularityNET cross-chain bridge's back-end authorization signature key became a critical turning point. Once the attacker gained control of the key, they could initiate ostensibly "legitimate" minting requests to the AGIX and WMTx/WMTX contracts on Ethereum, generating signatures indistinguishable from normal cross-chain processes. The on-chain contract could not distinguish whether this was a user-initiated cross-chain completion or a malicious arbitrary minting. The result was that approximately 260 million AGIX and about 53.83 million WMTx/WMTX were unauthorizedly written to the ledger, disrupting the originally designed total token supply and issuance rhythm, diluting the expected supply of all existing token holders, and shaking the entire ecosystem’s trust in the cross-chain bridge and the underlying signature management system. Under the premise that the leak route and timing of the key have not been made public, this trust gap is unlikely to be automatically repaired in the short term.

313 Million Tokens Minted: The Outline of Losses Emerges

The amount of unauthorized minting has begun to surface, transitioning from "expected dilution" to numerical reality. According to AiCoin's analysis, Fetch.ai publicly disclosed on-chain analysis on the ASI:One platform indicating that the attacker unauthorizedly minted approximately 260 million AGIX and about 53.83 million WMTx/WMTX on Ethereum using the stolen cross-chain bridge signature key. If calculated cumulatively, this incident has at least generated a potential selling pressure of over 313 million related tokens on paper, rewriting the originally embedded total and supply curve in the protocol into another version.

Even more striking is the current profile of the attacker's holdings. The same report states that the attacker’s address controls around 16.77 million dollars in crypto assets, including about 198.3 million AGIX valued at approximately 14.42 million dollars, with the remaining value dispersed among other assets. This indicates that a significant proportion of the "new coins" minted have already been transferred to the attacker’s controlled wallet, marked by on-chain analysis as a potential cash-out pathway. However, it should be emphasized that all of the above figures come from this yet-to-be-finalized single report, and Fetch.ai has noted in the text that further adjustments and modifications may occur based on new on-chain evidence. Currently, public materials do not provide the price and total market capitalization changes of AGIX and WMTx/WMTX before and after the incident, nor do they explain whether the project parties will handle this batch of unauthorized tokens through destruction, rollback, or other technical and governance means. In the absence of these key parameters, the outside world can only view this preliminary analysis as a foundational coordinate outlining the loss, without easily drawing conclusions about market-level impacts and long-term diffusion effects.

Emergency Containment and Traceability of the ASI Alliance Projects

After the incident, Fetch.ai launched the first on-chain analysis report on the ASI:One platform, focusing on the traceability work of the complete path from the theft of the authorization signature key to the assets flowing into cash-out wallets. The report marked key on-chain steps in chronological and transaction order: how the back-end key was misused to initiate seemingly compliant minting requests, how the cross-chain bridge contract unauthorizedly minted approximately 260 million AGIX and about 53.83 million WMTx/WMTX, and how these newly minted tokens were batch transferred to the wallets controlled by the attacker. At the same time, the report clearly stated "not the final version," indicating that further transaction samples and address profiles would be added later, while currently, it serves more to provide the community and related projects with a verifiable mainline of events rather than declaring the investigation complete.

While engaging in traceability and evidence collection, Fetch.ai and SingularityNET have jointly pressed the "emergency stop button," disabling confirmed affected wallets and related contracts, with the primary goal of preventing the attacker from continuing to call the cross-chain bridge or transfer tokens still within their control, to avoid the spread of the artificially minted chips to a larger range of on-chain participants. According to AiCoin data, the public can currently only see a directional description of this containment action: the complete list of wallets and contracts has not been made public, and the specific technical means employed for deactivation and actual blocking effects have not been transparently disclosed. In other words, the ASI Alliance has shifted from "individual attacks" to a coordinated response, but the overall focus remains on staunching the bleeding and clarifying the path; before more on-chain data, technical assessments, and follow-up disposal plans are revealed, the real risk profile of this arbitrary minting incident has not been fully delineated.

The Alarm of Cross-Chain Security and Subsequent Observations

From the stolen authorization signature key to unauthorized minting on Ethereum, to the same attacker continuously targeting Fetch.ai, NuNet, and SingularityNET, this incident exposed the risk of the back-end key of the cross-chain bridge as a single point of failure exceptionally directly: the compromise of one key is enough to arbitrarily generate hundreds of millions of AGIX and WMTx/WMTX on-chain, undermining the credit foundation of the entire token economy. For the high-profile AI narrative ecosystem, the more alarming alarm is that while the industry eagerly invests in models, computing power, and alliance narratives, it has yet to establish a consistent high-security standard in cross-chain architecture and key governance. Moving forward, several points warrant close observation: first, whether Fetch.ai can further restore the complete path of key theft to the attacker's holding of approximately 16.77 million dollars in assets through continuous updates to on-chain analysis; second, how projects like SingularityNET will reconstruct their cross-chain bridge architecture and key management to genuinely reduce back-end single-point control; third, whether project parties will disclose their handling plan for unauthorized tokens because how to deal with the 260 million AGIX and 53.83 million WMTx/WMTX will directly affect market evaluations of their governance capabilities and risk controls in the long term. On a broader industry level, this attack has almost forced all cross-chain infrastructure to re-examine whether institutional upgrades such as multi-signatures, hardware security modules, and permission layering are in place, and if transparent and verifiable on-chain responses can be provided in similar incidents. The trajectory of these variables will determine whether this arbitrary minting crisis is ultimately seen as a lesson or a prolonged trust deficit.

Join our community, let’s discuss, and grow stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink