One Attacker, Multiple Tokens: Inside the Fetch.ai Breach
Key Takeaways
- •A leaked signing key enabled a single attacker to drain approximately 8.7 million FET, worth around $1.5 million, from Fetch.ai's TokenConversionManagerV3 contract on Ethereum by presenting a valid conversion-authorizer signature.
- •The same wallet was linked to the unauthorized creation of roughly 409 million NTX, equal to about 41% of the token's one billion maximum supply, as well as mints of approximately 260 million AGIX and 54 million WMTX.
- •Security firm PeckShield valued the attacker's holdings near $17 million, well above the initial estimate of a roughly $2 million incident.
- •NTX fell about 70% to an all-time low on September 20, with the mint's size relative to supply and the token's thin trading depth cited as plausible explanations for the sharper decline compared with FET.
- •Fetch.ai worked SingularityNET to deactivate the affected wallets and contracts, but the published on-chain analysis is explicitly preliminary and the investigation has not reached a final conclusion.

Fetch.ai has traced a multi-token security incident to a leaked signing key, an update that substantially widens the scope of what was first reported as a theft of roughly $2 million in FET. According to the project's preliminary on-chain analysis, a single attacker is now linked to the removal of approximately 8.7 million FET, the unauthorized creation of nearly 409 million NTX, and further unauthorized mints of AGIX and WMTX. The investigation has not reached a final conclusion.
From a Single Contract Drain to a Wider Key Compromise
Initial reports centered on approximately 8.7 million FET, worth around $1.5 million, that was removed from Fetch.ai's TokenConversionManagerV3 contract on Ethereum. Security firm Blockaid said the attacker presented a valid conversion-authorizer signature, allowing the contract to release its remaining FET balance. Fetch.ai has since published a preliminary on-chain analysis tracing the attack path to a leaked signing key.
An on-chain analysis of the exploit is now available on ASI:One. It traces the attack from the compromised signing key to the attacker's cash-out wallets. This is not the final analysis. Read the report: Together with @SingularityNET , we have deactivated… — Fetch.ai (@Fetch_ai) September 20, 2026
The project said it worked with SingularityNET to deactivate the affected wallets and contracts. It also cautioned that the analysis is preliminary and that the investigation remains open. SingularityNET's involvement underscores the cross-project reach of the incident: NTX is NuNet's token, while AGIX is the token associated with SingularityNET, so the fallout spans several token communities rather than FET holders alone.
The Same Wallet, Multiple Tokens
The wallet that received the FET was later linked to the creation of approximately 409 million NTX through a NuNet deployer account. The tokens were valued near $460,000 when issued.
The incident widened again when PeckShield reported that the same wallet was also connected to unauthorized mints of approximately 260 million AGIX and 54 million WMTX. When the security firm's findings were published, the attacker's holdings were valued near $17 million.
The shared wallet is why researchers have attributed the transactions to a single attacker. It does not yet show whether one leaked key provided access to every affected contract or whether several credentials were compromised.
The incidents identified so far:
- FET removed: approximately 8.7 million FET. Existing tokens were released from a converter contract.
- NTX created: approximately 409 million NTX. Tokens were reportedly issued without authorization.
- New findings: AGIX and WMTX mints reported. PeckShield linked further token creation to the attacker.
The Dollar Totals Hide Two Different Kinds of Damage
The FET and NTX incidents did not affect holders in the same way.
The FET transaction removed tokens that already existed. That created a known loss and gave the attacker assets that could be sold, but it did not directly increase the total number of FET tokens.
The reported NTX transaction, by contrast, reached the token's issuance process. Instead of transferring a balance from one wallet to another, the deployer account apparently created tokens outside the expected distribution schedule.
CoinGecko lists a maximum supply of one billion NTX. The reported unauthorized mint was therefore equal to roughly 41% of that amount. That does not mean every unauthorized token entered circulation. Data providers may also exclude tokens that Nu later invalidates, burns, or replaces through a contract migration. The comparison shows why traders could no longer rely on the displayed supply figure without further clarification from the project.
The later AGIX and WMTX findings make this distinction more important. The central question is no longer how much was removed from one contract, but how widely the compromised permissions could be used to create or release assets.
Why NTX Fell Much Harder Than FET
NTX fell roughly 70% after the incident became public and reached a new all-time low on September 20. FET declined by a much smaller percentage while the wider crypto market was also trading lower. The timing and scale of the unauthorized mint provide a plausible explanation for the difference, although they do not prove that the incident caused every part of the NTX decline.
The reported mint was large relative to supply. Creating an amount equal to approximately 41% of the stated maximum supply introduced immediate dilution concerns. Traders also had no clear information about how many of the tokens could reach exchanges or decentralized liquidity pools.
NTX trades in a thin market. CoinGecko showed less than $50,000 in rolling 24-hour NTX volume when checked. The unauthorized tokens had been valued near $460,000 when created, making the reported mint roughly ten times larger than the token's recent daily turnover. The comparison does not measure how much the attacker sold. It illustrates the available market depth: attempting to sell even a fraction of such a position could move the price sharply when relatively few buyers are waiting nearby.
The market could not immediately verify that minting had stopped. A stolen balance has a measurable limit. An exposed minting permission creates a more open-ended risk, because holders need evidence that the authority has been revoked before they can rule out further issuance.
Why the Distinction Matters
FET holders could see how many tokens left the converter. NTX holders also had to question whether the published supply still described the tokens that could exist.
A Valid Signature Can Still Authorize an Attack
A smart contract can verify that a signature came from an approved key, but it cannot determine whether the legitimate owner intended the transaction. Once the signing key was compromised, the attacker's instruction could appear valid to the contract.
This is why describing the incident only as a smart-contract exploit would be incomplete. The code controlling the withdrawal and the security of the key authorizing it formed one system. A failure in either part could expose the assets.
SlowMist noted that Fetch.ai's incoming conversion function relied on a single externally owned account signature and lacked some of the additional restrictions present in another conversion function. Fetch.ai's final report will need to establish how that design interacted with the leaked key. The episode also feeds a broader industry conversation about operational key management, where safeguards such as multi-signature approvals and hardware-protected key storage are common tools for limiting what any single credential can authorize.
Blockchain transparency helps researchers follow the resulting transactions, but it does not prevent an approved credential from being misused. A similar limitation appeared in Polymarket's reported $10 million fraud attempt: public records can expose what happened after an instruction was accepted, while the harder security problem is deciding who should have been permitted to issue it.
Deactivating the Contracts Contains the Risk, but Does Not Resolve It
Fetch.ai's decision to deactivate the affected wallets and contracts is an important containment step. Holders still need a final account of which permissions were exposed and how the affected tokens will be handled. For readers tracking the outcome, the markers to watch are the completed on-chain analysis — the published report is explicitly preliminary — and any clarification from NuNet on whether the unauthorized NTX will be invalidated, burned, or replaced through a contract migration.
The Permissions Now Matter More Than the First Loss Estimate
The incident was initially described as an attack involving approximately $2 million. The later findings make that figure a poor measure of its potential reach. The more important boundary is the authority the leaked credentials provided.
Fetch.ai and the connected projects will need to show that the affected permissions have been removed and that unauthorized tokens cannot continue moving through recognized contracts. Until that evidence is available, token prices will reflect more than the assets already taken. They will also carry uncertainty over which supply figures and contract permissions the market can still trust.
This article is provided for informational purposes only and does not constitute financial or investment advice. The investigation remains ongoing, and the reported figures may change as the affected projects and security researchers publish additional findings.