NewsCryptoNuNet's NTX Crashes After $2 Million Fetch.ai Exploit Widens to SingularityNET

NuNet's NTX Crashes After $2 Million Fetch.ai Exploit Widens to SingularityNET

Author: CoinTrust·

Key Takeaways

  • PeckShield connected approximately 8.7 million FET, worth about $1.53 million, drained from Fetch.ai's TokenConversionManagerV3 contract to the same wallet that received roughly 408.5 million newly minted NTX from a NuNet deployer account about 28 minutes later.
  • NuNet's NTX token declined about 65% during the initial phase of the incident, and market trackers subsequently recorded substantially larger drops as trading continued.
  • The same attacker was reported to have minted around 260 million AGIX and 53.838 million WMTx on Ethereum, with holdings estimated at approximately $16.77 million, including 198.3 million AGIX, 649 ETH, and 33.538 million WMTx.
  • Fetch.ai paused its Ethereum bridge contract as a precaution while stating its broader contracts remained operational, and World Mobile confirmed its connection to the SingularityNET bridge had been exploited and said it was working with security partners and exchanges.
  • The full root cause has not been conclusively established in an official post-mortem, though separate reporting has pointed to authorization and key-management issues, and investigations into the affected contracts remain ongoing.
NuNet's NTX Crashes After $2 Million Fetch.ai Exploit Widens to SingularityNET

NuNet's NTX token came under heavy selling pressure after on-chain security analysts linked a single exploiter to both the unauthorized transfer of millions of Fetch.ai tokens and the creation of hundreds of millions of new NTX tokens.

Blockchain security firm PeckShield reported that the attacker drained approximately 8.7 million FET from Fetch.ai, valued at roughly $1.53 million at the time, while also receiving about 408.5 million newly minted NTX worth approximately $462,730. The combined value of the affected assets was estimated at about $2 million. The attacker subsequently converted part of the proceeds into 546.36 ETH, valued at approximately $1.44 million when reported.

According to on-chain records and security-monitoring reports, the transactions were linked through a common receiving wallet, with the 8.7 million FET transfer followed roughly 28 minutes later by the minting of 408.5 million NTX from a NuNet deployer account. The projects involved are established names in decentralized infrastructure: Fetch.ai and SingularityNET operate decentralized AI networks, NuNet builds decentralized computing infrastructure, and World Mobile runs a decentralized connectivity network.

#PeckShieldAlert The same exploiter has exploited both @Fetch_ai & @nunet_global , totaling ~$2M in crypto losses: 8.7M ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 ($1.53M) drained &408.5M NTX ($462.73K) minted NuNet's $NTX has dropped ~65%. The exploiter has swapped the… pic.twitter.com/YRJnB9XjDF

— PeckShieldAlert (@PeckShieldAlert) September 19, 2026

NTX suffers sharp market decline

The unauthorized creation of NTX placed significant pressure on the token as newly minted supply entered the market. Reports indicated that NTX fell about 65% during the initial phase of the incident, although subsequent market trackers showed substantially larger declines as trading continued.

The incident involved a different mechanism for each asset. The Fetch.ai episode involved the movement of existing FET from an Ethereum-based token converter, while the NuNet event involved the creation of additional NTX through the project's deployer infrastructure. The distinction is significant because the reported $2 million figure combines an existing token balance that was drained with newly created token supply. During incidents of this kind, trading venues and market data providers typically flag affected tokens while they assess compromised supply, which is one reason loss estimates and price readings continue to shift as the situation develops.

Blockchain records showed that approximately 8.72 million FET was transferred from Fetch.ai's TokenConversionManagerV3 contract on Sept. 19, 2026. About 28 minutes later, a NuNet deployer account minted approximately 408.53 million NTX and sent the newly created tokens to the same wallet associated with the earlier transaction.

Investigation expands to SingularityNET

The incident later widened when PeckShield reported unauthorized minting involving SingularityNET's AGIX token and World Mobile's WMTx token on Ethereum.

We're aware of reports of an exploit involving a token conversion contract. Our team is investigating and will share an update soon. Please rely only on official httpst.co/CwbPmOj7TU channels. We will never DM you or ask you to move your tokens.

— Fetch.ai (@Fetch_ai) September 20, 2026

The same attacker was reported to have minted approximately 260 million AGIX and 53.838 million WMTx. At the time of the security firm's assessment, the attacker's holdings were estimated at about $16.77 million, including 198.3 million AGIX valued at roughly $14.42 million, 649 ETH worth about $1.67 million, and 33.538 million WMTx valued near $627,350.

The expansion to AGIX and WMTx indicates that the incident involved multiple token and bridge-related components across the broader ecosystem, rather than being limited to the initial Fetch.ai and NuNet activity. Conversion contracts and bridges are a recurring focal point in crypto security because they concentrate the permissions needed to move and, in some designs, issue tokens, which leaves little room for error in how those controls are administered.

As a precaution, we have paused our bridge contract on Ethereum. There is no indication of any vulnerability. This is purely precautionary, and we will restore it in due course.

— Fetch.ai (@Fetch_ai) September 20, 2026

Security concerns and response

Reports indicate that Fetch.ai's Ethereum token converter was involved in the initial FET transfer, while the subsequent NTX issuance originated from NuNet's deployer account. Separate reporting on the technical investigation has pointed to authorization and key-management issues, although the full root cause has not been conclusively established in an official post-mortem. Authorization settings and key management determine who can trigger minting or conversion functions, and transactions executed with valid credentials are treated as legitimate by the chain itself, which limits the automatic safeguards available once those controls are compromised.

#PeckShieldAlert The same exploiter has exploited @SingularityNET , resulting in the unauthorised minting of 260M $AGIX & 53.838M $WMTx on Ethereum. The exploiter currently holds ~$16.77M worth of crypto, including 198.3M AGIX (worth $14.42M), 649 $ETH (worth ~$1.67M), and… pic.twitter.com/oHBpbWXQMj

— PeckShieldAlert (@PeckShieldAlert) September 20, 2026

Fetch.ai has indicated that its broader contracts remained operational while precautionary measures were taken around the affected conversion and bridge functions. World Mobile also confirmed that its connection to the SingularityNET bridge had been exploited and said it was working with security partners and exchanges in response.

The incident highlights the potential market impact of compromised authorization or minting controls, because unauthorized token creation can rapidly increase circulating supply and undermine confidence even when the underlying blockchain remains operational.

Investigations into the linked transactions and affected contracts are continuing. Security researchers and blockchain monitoring firms are expected to refine estimates as more transaction data becomes available, while affected projects work to identify compromised permissions and limit further unauthorized activity. Developments worth tracking include updates on the paused bridge and conversion functions, how exchanges and market data providers handle the minted AGIX, WMTx, and NTX supply, and whether the affected teams publish root-cause findings that explain how the permissions were compromised.