Fetch.ai and NuNet Exploits Drain Nearly $2 Million as NTX Plunges 65%
Key Takeaways
- •A single attacker address was linked to both the withdrawal of 8.7 million FET from Fetch.ai's TokenConversionManagerV3 contract and the minting of 408. million NTX from NuNet's infrastructure, together moving nearly $2 million.
- •Blockaid's analysis found an externally owned account used valid conversion authorization data to drain the Fetch.ai converter, but the method used to obtain or generate that authorization has not been publicly established.
- •The unauthorized NTX mint was followed by an approximately 65% price collapse, with the token falling from about $0.00133 on September 18 to roughly $0.000469 on September 19, according to CoinGecko data.
- •PeckShield traced the attacker's conversion of much of the extracted value into approximately 546.36 ETH, worth about $1.44 million at the time of the tracing.
- •Neither Fetch.ai nor NuNet had published a technical post-mortem confirming the failure mechanism, and the affected Fetch.ai contract remained active on Ethereum holding approximately 13.7 million FET.

Fetch.ai and NuNet were hit by linked security incidents that moved nearly $2 million in crypto assets, with the same attacker address tied to the withdrawal of 8.7 million FET and the creation of 408.5 million NTX.
The FET, worth roughly $1.53 million at the time of the incident, was taken from Fetch.ai's Ethereum-based TokenConversionManagerV3 contract. The verified contract manages conversions involving the ERC-20 version of FET and relies on signed authorization data for conversion transactions. Security monitoring later connected the address that received the FET to the NuNet activity, bringing the combined value involved to approximately $2 million. That common address ties the two events to a single actor working across separate codebases, rather than two independent breaches.
Fetch.ai Converter Loses 8.7 Million FET
Transactions on September 19 removed approximately 8.7 million FET from Fetch.ai's conversion infrastructure. According to Blockaid's analysis, an externally owned account used valid conversion authorization data to interact with the converter, although the exact method used to obtain or generate that authorization has not been established publicly.
The contract includes checks against invalid or previously used signatures, transaction limits, and a designated conversion authorizer. No confirmed technical explanation has yet determined whether the incident resulted from compromised authorization credentials, an implementation issue, or another failure outside the contract itself. In signed-authorization designs, the decisive safeguards sit off-chain: once a valid, previously unused signature reaches the contract, its built-in checks treat the resulting conversion as legitimate, so the safety of the pooled FET rests on how tightly the credentialing side is controlled.
The attack follows several recent incidents involving narrowly scoped smart-contract components. A Notional Finance escrow contract lost about $1.7 million earlier in September, and investigators had not established the precise authorization path behind that withdrawal at the time of publication.
NuNet Hit by 408.5 Million NTX Mint
The same attacker was subsequently linked to approximately 408.5 million newly minted NTX originating NuNet's deployment infrastructure. The tokens were valued at roughly $462,700 at the time of the activity, based on the sharply reduced market price following the mint.
The supply expansion was followed by an approximately 65% collapse in NTX. CoinGecko () recorded NTX closing September 18 near $0.00133 before falling to about $0.000469 on September 19. Because the newly created tokens sit alongside previously existing balances, a mint of this scale immediately reduces every other holder's proportional share of total supply — the mechanical effect that separates unauthorized minting from a straightforward theft of pooled funds.
Unauthorized supply creation has produced similar disruptions elsewhere this year. The Base deployment of The Sandbox was hit by a suspected SAND mint in August after an address obtained minting authority and created billions of tokens beyond the normal supply. More recently, Blink Wallet temporarily shut down its platform after an attacker gained unauthorized access to a limited number of custodial accounts and withdrew funds, while FomoPeek, an iPhone app marketed for tracking whale wallets, was found to contain malicious code capable of escaping iOS security restrictions and extracting cryptocurrency wallet credentials from affected devices.
Attacker Converts Proceeds Into 546 ETH
The address linked to both incidents subsequently converted much of the extracted value into approximately 546.36 ETH worth about $1.44 million when PeckShield traced the transactions (https://x.com/PeckShieldAlert/status/2101457227379044822).
Neither Fetch.ai nor NuNet had published a technical post-mortem or confirmed the underlying failure mechanism at the latest check. The available on-chain evidence establishes the FET withdrawal, the NTX issuance, and the subsequent asset conversions, but does not yet establish a common vulnerability across the two projects. The questions still open are the unexplained authorization path behind the FET withdrawal and the minting mechanism behind the NTX issuance; a technical post-mortem from either team would be the first public account of how its failure occurred.
Fetch.ai's affected TokenConversionManagerV3 contract remained active on Ethereum and held approximately 13.7 million FET at the latest Etherscan () check.