Security firms have identified a connection between recent exploits targeting Fetch.ai and NuNet, with the incidents resulting in combined losses of approximately $2 million. Both cryptocurrency projects, known for their AI and blockchain-powered solutions, were affected by the same attacker, firms reported.
Coordinated Attacks Affect Fetch.ai and NuNet
PeckShield, a blockchain security company, revealed that about 8.7 million FET tokens were drained from a Fetch.ai token converter, assigning a value of $1.53 million to the stolen assets. This sum represented the majority of the overall losses reported in these incidents.
The NuNet project experienced an unauthorized minting event, with its deployer account creating 408.5 million NTX tokens. PeckShield estimated the value of these newly issued tokens at roughly $462,730. As a result, the value of NTX dropped sharply, plummeting by over 90% in subsequent trading, while Fetch.ai’s FET token registered a more modest decline.
Alternative figures provided by security firm Blockaid placed the value of stolen FET tokens at $1.56 million and the NTX mint at $452,000, bringing the total losses to $2.01 million. These assessments indicate that both events contributed significantly to the overall depletion of assets.
Blockaid attributed the exploits to a single wallet address, linking activity across Fetch.ai and NuNet. The use of the same receiving address suggested a coordinated attack, with $1.56 million in FET drained from Fetch.ai and $452,000 in NTX minted without authorization, resulting in nearly $2.01 million in total losses.
PeckShield further reported that the proceeds from these actions were quickly exchanged for 546.36 ETH, which was worth approximately $1.44 million at the time of the transactions.
Mechanics Behind the Exploit
Blockaid traced the exploits to a specific wallet, identified as 0x1572…c362, as the common destination for both the stolen FET and newly minted NTX tokens. This finding allowed exchanges and associated projects to monitor and attempt to freeze the movements of the misappropriated funds.
Fetch.ai specializes in autonomous AI agent solutions via its Agentverse platform, while NuNet develops decentralized sharing of GPU and CPU resources. Both initiatives integrate blockchain technology and artificial intelligence in their frameworks.
According to Blockaid, the vulnerability in Fetch.ai was associated with the TokenConversionManagerV3 contract on the Ethereum blockchain. The attacker was able to invoke the conversionIn function using a valid authorization signature, which enabled the release of the remaining FET tokens within the converter contract.
Security firm SlowMist analyzed the flaw further, noting that the conversionIn function required a single external account’s signature as authorization. Unlike the outbound function, this inbound transaction logic did not include a limit verification feature, allowing the exploiter to drain large amounts without triggering additional checks.
Mini dictionary: TokenConversionManagerV3 contract, the smart contract managing conversions between tokens in Fetch.ai, vulnerable due to a missing limit verification in one conversion direction.
Reports did not clarify how the attacker secured a valid signature to authorize the Fetch.ai function, nor how access to NuNet’s deployer account was achieved, leaving key questions open regarding the attack vector.
Market Impact and Wider Industry Context
The exploit led to a sharp decline in the price of NTX, with the token falling by about 65% and eventually hitting an all-time low of $0.00005338 as trading continued. FET’s drop appeared less severe and coincided with a larger cryptocurrency market downturn, as industry-wide market capitalization slipped 4.1%.
These security incidents contributed to a wave of losses throughout September, with DeFi analytics platform DefiLlama recording 17 security breaches in the month up to September 17, totalling $331 million in losses. The Liquid Network incident on September 6 accounted for $320 million, comprising almost all of the monthly figure and resulting from a major bridge exploit involving unbacked token minting.
| Date | Project | Type | Loss |
|---|---|---|---|
| September 19 | Fetch.ai | Token drain | $1.53 million (FET) |
| September 19 | NuNet | Unauthorized mint | $462,730 (NTX) |
| September 17 | Nostra Money Market | Oracle manipulation | $3.5 million |
| September 12 | Chainflip | Bridge logic flaw | $736,442 |
| September 9 | Nomic | Cross-chain mint | $3.15 million |
| September 6 | Liquid Network | Bridge exploit | $320 million |
Other notable incidents included losses of $3.5 million at Nostra Money Market due to oracle price manipulation, $3.15 million at Nomic from an unbacked cross-chain mint, and $736,442 at Chainflip caused by a bridge logic error. With the addition of new attacks, total September exploits recorded by DefiLlama and security specialists reached approximately $333 million.




