An attacker compromised privileged signing credentials on September 19, 2026, to execute a coordinated $2 million exploit against AI-focused crypto projects Fetch.ai and NuNet. The hacker drained 8.7 million FET tokens from a Fetch.ai converter contract and minted 408.5 million unauthorized NTX tokens via NuNet's deployer account. While FET fell only 5% to 10%, NTX crashed up to 95% to an all-time low. Fetch.ai and SingularityNET deactivated affected contracts and paused token conversions.
FET token drain method
- ▪An attacker using wallet 0x1572…c362 drained 8.7 million FET tokens, valued at approximately $1.53 million to $1.56 million, from a Fetch.ai token converter contract on Ethereum
- ▪SlowMist reported that Fetch.ai's TokenConversionManagerV3 relied solely on an ECDSA signature from a single externally owned account to authorize the conversionIn() function, which lacked a checkLimits control mechanism
Token price crash aftermath
- ▪Fetch.ai's FET token experienced a much milder decline of 5% to 10% following the September 19, 2026 exploit of Fetch.ai and NuNet, as the hack that drained the Fetch.ai converter removed existing tokens rather than minting new supply
- ▪NuNet's NTX token crashed between 65% and 95% following the September 19, 2026 exploit of Fetch.ai and NuNet, reaching an all-time low on September 20, 2026
Debatable claims
- ▪Crypto protocols should abandon single-signature authorization for critical smart contract functions
- ▪Decentralized protocols should maintain emergency pause mechanisms for token conversions
Story comments
Loading comments…