CoinTrust

NuNet NTX Crashes After $2M Fetch.ai Exploit Widens

nunet

NuNet’s NTX token came under heavy selling pressure after a blockchain security incident linked the same exploiter to the unauthorized transfer of millions of Fetch.ai tokens and the creation of hundreds of millions of new NTX tokens.

PeckShield reported that the attacker drained about 8.7 million FET from Fetch.ai, valued at roughly $1.53 million at the time, while also receiving approximately 408.5 million newly minted NTX worth about $462,730. The combined value of the affected assets was estimated at about $2 million. The attacker subsequently converted part of the proceeds into 546.36 ETH, valued at approximately $1.44 million when reported.

The transactions were linked through a common receiving wallet, with the 8.7 million FET transfer followed about 28 minutes later by the minting of 408.5 million NTX from a NuNet deployer account, according to on-chain records and security-monitoring reports.

NTX suffers sharp market decline

The unauthorized creation of NTX placed significant pressure on the token as newly minted supply entered the market. Reports indicated that NTX fell about 65% during the initial phase of the incident, although subsequent market trackers showed substantially larger declines as trading continued.

The incident involved a different mechanism for each asset. The Fetch.ai episode involved the movement of existing FET from an Ethereum-based token converter, while the NuNet event involved the creation of additional NTX through the project’s deployer infrastructure. This distinction is important because the reported $2 million figure combines an existing token balance that was drained with newly created token supply.


Blockchain records showed that approximately 8.72 million FET was transferred from Fetch.ai’s TokenConversionManagerV3 contract on Sept. 19, 2026. About 28 minutes later, a NuNet deployer account minted approximately 408.53 million NTX and sent the newly created tokens to the same wallet associated with the earlier transaction.

Investigation expands to SingularityNET

The incident later widened when PeckShield reported unauthorized minting involving SingularityNET‘s AGIX token and World Mobile’s WMTx token on Ethereum.


The same attacker was reported to have minted approximately 260 million AGIX and 53.838 million WMTx. At the time of the security firm’s assessment, the attacker’s holdings were estimated at about $16.77 million, including 198.3 million AGIX valued at roughly $14.42 million, 649 ETH worth about $1.67 million, and 33.538 million WMTx valued near $627,350.

The expansion to AGIX and WMTx indicates that the incident involved multiple token and bridge-related components across the broader ecosystem, rather than being limited to the initial Fetch.ai and NuNet activity.


Security concerns and response

Reports indicate that Fetch.ai’s Ethereum token converter was involved in the initial FET transfer, while the subsequent NTX issuance originated from NuNet‘s deployer account. Separate reporting on the technical investigation has pointed to authorization and key-management issues, although the full root cause has not been conclusively established in an official post-mortem.


Fetch.ai has indicated that its broader contracts remained operational while precautionary measures were taken around affected conversion and bridge functions. World Mobile also confirmed that its connection to the SingularityNET bridge had been exploited and said it was working with security partners and exchanges in response.

The incident highlights the potential market impact of compromised authorization or minting controls, because unauthorized token creation can rapidly increase circulating supply and undermine confidence even when the underlying blockchain remains operational.

Investigations into the linked transactions and affected contracts are continuing. Security researchers and blockchain monitoring firms are expected to refine estimates as more transaction data becomes available, while affected projects work to identify compromised permissions and limit further unauthorized activity.

Exit mobile version