Attack on Fetch.ai and NuNet Highlights Vulnerabilities in AI‑Crypto Infrastructure
On 20 September 2026, security researchers uncovered a coordinated exploit that siphoned approximately $2 million from the Fetch.ai ecosystem while simultaneously minting more than 408 million NTX tokens on NuNet. The incident underscores how a single compromised private key can propagate damage across interconnected blockchain projects, even when the core smart contracts remain untouched.
How the Attack Unfolded
- Compromised Credentials: PeckShield’s forensic analysis traced the breach to a single attacker wallet that had obtained signing credentials for both Fetch.ai and NuNet. The same credentials allowed the attacker to move funds and mint tokens without triggering on‑chain alarms.
- Fetch.ai Drain: The attacker transferred 8.7 million FET (Fetch.ai’s native token) to a destination wallet, valuing the theft at roughly $1.53 million at the time of the transfer.
- NuNet Mint: Less than half an hour later, the same wallet received a 408.5 million NTX mint from the NuNet deployer contract. This illicit issuance was worth about $462,730.
- Conversion to Ether: Subsequent analysis by Blockchain.News revealed that the attacker converted the combined proceeds—approximately $1.44 million—into 546.36 ETH, a move that further obfuscated the trail of funds.
The same chain of transactions was corroborated by Blockaid, which reported similar figures: $1.56 million in FET drained from a converter and $452 000 in newly minted NTX, bringing the cluster’s total to $2.01 million.
Impact on NuNet’s Token Supply
NuNet’s native token, NTX, had a market cap of $212,400 as of 19 September 2026, with a close price of $0.00042136. The sudden influx of 408.5 million NTX—nearly 40 % of the token’s circulating supply—led to a sharp price decline, as reported by AMBCrypto. Despite the mint, Fetch.ai’s core contracts remained untouched, suggesting that the vulnerability lay within the bridge or deployment mechanisms rather than the token itself.
Broader Implications for AI‑Crypto Projects
Both Fetch.ai and NuNet are part of a rapidly expanding AI‑crypto ecosystem, with NuNet positioned as a spin‑off that integrates AI and blockchain functionalities. This incident demonstrates that:
- Privileged Key Management Is Critical: A single compromised private key can grant access to multiple projects, especially when they share infrastructure or bridge mechanisms.
- Supply Chain Risks Persist: Even if a smart contract is secure, ancillary components—such as deployment scripts or bridge routers—can become attack vectors.
- Market Sensitivity: Large, unauthorized token issuances can trigger immediate market corrections, as seen with NTX’s price plunge.
Current Status and Next Steps
Fetch.ai has confirmed that its main contracts remain secure, and the company is conducting a comprehensive audit of its bridge routes. NuNet’s development team is investigating the deployer contract that facilitated the mint and is evaluating additional safeguards to prevent repeat incidents. Security firms have urged both projects to implement multi‑factor authentication for signing keys, regular key rotation, and rigorous monitoring of token‑minting events.
As the broader AI‑crypto community absorbs this breach, the incident serves as a stark reminder: in interconnected ecosystems, the security of one component can directly influence the stability of the entire network.




