Fetch.ai and NuNet hit in attacks linked to a compromised private key

- An attacker used a compromised signing key to drain roughly $2 million from Fetch.ai and NuNet.
- NuNet’s NTX fell to an all-time low after the attacker minted 408.5 million NTX.
- Fetch.ai has now paused its Ethereum bridge and, with SingularityNET, disabled the affected wallets and contract.
An attacker has taken around $2 million from the infrastructure connected with Fetch.ai and NuNet.
Both attacks were linked by security firms to the same attacker wallet. Preliminary analysis of Fetch.ai revealed that the attacker used signing credentials that were compromised to gain access to the infrastructure.
While a theft of $2 million may be deemed insignificant in the context of an estimated $2.85 trillion crypto market, what is remarkable about this particular event is that compromised privileged credentials gave the hacker access to critical infrastructure and highlighted how weaknesses in key management can spill across connected systems even if those underlying token contracts are not compromised themselves.
The same wallet drained FET and received the NTX mint
According to PeckShield, the hacker siphoned off a total of 8.7 million FET, valued at an equivalent of $1.53 million, and unauthorizedly minted 408.5 million NTX worth around $462,730.
Blockaid has separately observed about $1.56 million in FET removed from a converter, along with approximately $452,000 in newly minted NTX. This brought the total value of this wallet cluster to about $2.01 million while the attack was ongoing. A follow-up post connected the NTX mint to the same receiving wallet.
🚨Blockaid detected an ongoing exploit on @Fetch_ai on Ethereum.
— Blockaid (@blockaid_) September 19, 2026
The same exploiter wallet then received a large NTX mint from the @nunet_global deployer account.
~$2.01M so far (~$1.56M FET drained from the converter + ~$452k NTX minted) across the cluster. Attack still…
NuNet is also part of the same broader AI-crypto ecosystem. CoinMarketCap describes it as the second spin-off from SingularityNET.
The weak point was privileged authorization
According to the presented evidence, it cannot be concluded that a single key was responsible for both projects. Based on Fetch.ai’s preliminary analysis, it is likely that the signing key had been compromised. On the other hand, the analysis thereof that was done on the blockchain implies that the minting key from NuNet may also be compromised.
In its analysis, SlowMist reported that the TokenConversionManagerV3 relied on only the ECDSA signature from a single externally owned account to authorize the conversionIn() function at the draining of the FET.
The said function did not implement a checkLimits(amount) control mechanism against the transaction, and did not check if burn or lock proofs were available on-chain. The drain of the FET happened as soon as the authorizer key was compromised, since a legitimate signature was all that was required for the draining of the converter’s FET balance.
Fetch.ai said it worked with SingularityNET to deactivate affected wallets and contracts. A later update said no Fetch.ai contracts were then at risk and AGIX-to-FET conversions had been paused as a precaution.
An on-chain analysis of the exploit is now available on ASI:One. It traces the attack from the compromised signing key to the attacker’s cash-out wallets. This is not the final analysis.
— Fetch.ai (@Fetch_ai) September 20, 2026
Read the report: https://t.co/W95r50VMaY
Together with @SingularityNET, we have deactivated…
Why NTX cratered while FET did not
These two tokens responded in distinct ways due to the different effects the attacks had on supply. The FET hack removed previously issued tokens, while the NTX hack generated hundreds of millions of unauthorized tokens, compromising supply integrity and adding extra selling pressure.
According to CoinMarketCap, NTX is currently trading around $0.000066, down almost 95% within the last 24 hours after reaching its all-time low of $0.00004075 on September 20. At the same time, FET’s situation was not complicated by such a catastrophe.

The direct loss is modest, but the attack method fits a much larger industry pattern. TRM Labs recorded 207 hacks and $972 million in losses in the first half of 2026. Infrastructure and operational compromises accounted for only about 15% of incidents but roughly 76% of stolen funds.
CoinGecko’s 2026 security report tells a similar story. Infrastructure and supply-chain breaches caused more than $1.8 billion in losses between January 2025 and July 2026, while private-key compromise remained a major failure point.
Cryptopolitan also reported a similar pattern in June, when Humanity Protocol said exposed private keys contributed to losses of up to $31 million, and its H token fell as much as 90%.
Fetch.ai says the investigation remains open. The next questions are how the credentials were compromised, whether Fetch.ai has rotated or replaced all affected privileges, and how NuNet handles the unauthorized NTX still linked to the attacker.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How did the attacker steal from Fetch.ai and NuNet?
Fetch.ai's preliminary analysis points to a compromised signing key rather than a smart-contract flaw. SlowMist and Blockaid found that the conversionIn() function on TokenConversionManagerV3 accepted a single account's signature as its only authorization and lacked a spending-limit check present elsewhere in the contract.
How much was lost in the Fetch.ai and NuNet exploit?
PeckShield and Blockaid put the combined loss at roughly $2 million: about 8.7 million FET worth around $1.53 million drained, plus roughly 408.5 million NTX (about $452,000 to $463,000) minted without authorization.
Why did NuNet's NTX token crash so hard?
The attacker minted new NTX rather than only draining existing tokens, which undermines supply integrity and adds sell pressure. CoinMarketCap shows NTX down about 95% over 24 hours to an all-time low of $0.00004075 on September 20, 2026.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ibiam Wayas
Ibiam Wayas has covered the crypto news beat since 2019. He studied Computer Science at National Open University of Nigeria. His work has appeared on various crypto news platforms, including Coinfomania, Crypto News Australia, and AltcoinBuzz. Drawing on his background in Computer Science, he now focuses on crypto, robotics, and longevity news.
















