Fetch.ai and NuNet have suffered separate attacks that exposed weaknesses in privileged access across connected crypto infrastructure.
The incidents involved unauthorized transfers and token creation worth roughly $2 million. Security firms linked both attacks to the same receiving wallet during their preliminary investigations.
The events have also raised fresh concerns about private-key management across blockchain infrastructure.
PeckShield reported that the attacker drained about 8.7 million FET worth $1.53 million from Fetch.ai-related infrastructure.
The attacker also minted approximately 408.5 million NTX tokens valued at around $462,730. Blockaid separately identified about $1.56 million in FET removed from a converter and roughly $452,000 in newly minted NTX.
The combined value of the assets linked to the attacker wallet reached approximately $2.01 million. A follow-up analysis connected the unauthorized NTX minting to the same receiving wallet.
Compromised credentials exposed critical infrastructure
Fetch.ai’s preliminary investigation indicated that compromised signing credentials likely enabled the attacker to access critical infrastructure. However, the available evidence does not establish that one private key controlled both attacks.
Blockchain analysis instead suggests that NuNet’s minting key may have faced a separate compromise. The distinction remains important because both incidents involved privileged authorization rather than direct exploitation of the underlying token contracts.
SlowMist found that Fetch.ai’s TokenConversionManagerV3 relied on an ECDSA signature from a single externally owned account. That signature authorized the conversionIn() function involved in the FET drain.
The function also lacked a checkLimits(amount) control, according to SlowMist’s analysis. It did not verify whether burn or lock proofs existed on-chain before processing the conversion.
As a result, compromising the authorizer key gave the attacker the authorization needed to drain FET from the converter. The incident therefore highlighted how privileged credentials can provide access to connected infrastructure without requiring a direct contract exploit.
Fetch.ai said it worked with SingularityNET to disable affected wallets and contracts. The project later said no Fetch.ai contracts remained at risk. It also paused AGIX-to-FET conversions as a precaution.
Unauthorized NTX supply sends NuNet token lower
The two attacks produced different effects on the affected tokens because they involved different supply mechanisms. The FET incident removed already issued tokens, while the NuNet attack created hundreds of millions of unauthorized NTX tokens.
CoinMarketCap data showed NTX trading around $0.000066 after falling almost 95% within 24 hours. The token reached an all-time low of $0.00004075 on September 20.
NuNet operates within the broader AI and crypto ecosystem and represents the second spin-off from SingularityNET, according to CoinMarketCap. The unauthorized mint therefore affected both market supply and confidence in the token’s issuance controls.
The incidents also fit a broader pattern across the crypto industry. TRM Labs recorded 207 hacks and $972 million in losses during the first half of 2026.
Infrastructure and operational compromises represented about 15% of those incidents but accounted for roughly 76% of stolen funds. CoinGecko’s 2026 security report similarly identified infrastructure and supply-chain breaches as major risks.
According to the report, those breaches caused more than $1.8 billion in losses between January 2025 and July 2026. Private-key compromise also remained a major security weakness.
Humanity Protocol previously reported exposed private keys linked to losses of up to $31 million. Its H token subsequently fell as much as 90%.
Fetch.ai said its investigation remains ongoing. Key questions include how the credentials were compromised, whether affected privileges have been fully rotated, and how NuNet will address unauthorized NTX associated with the attacker.

