Two related AI-focused crypto projects were hit by a single attacker within minutes of each other on September 19, walking away with close to $2 million combined, according to on-chain security firms Blockaid and PeckShield.
The attacker first drained roughly 8.7 million FET — about $1.5 million — from a token converter contract belonging to Fetch.ai, per Coinpedia. According to Blockaid, the same wallet that received those funds was then used to mint 408.5 million unauthorized NTX tokens, worth around $463,000 at the time, directly through NuNet's deployer account. That shared wallet is the on-chain link between the two incidents; Blockaid published the exploiter's addresses and an example transaction so exchanges and other projects can flag further movement.
Reporting by Crowdfund Insider and AMBCrypto corroborated the two-stage pattern, with AMBCrypto reporting the attack drained a converter contract after a weak security check, and that the NTX mint points to a compromised private key or misconfigured permission on the deployer account rather than a flaw in the token contract itself.
Market Impact and Laundering
The unauthorized mint created an immediate supply overhang: NTX collapsed to an all-time low, with trackers putting the drawdown between roughly 65% and 95% within hours, while FET slipped around 10%. The attacker moved quickly to convert a large share of the proceeds into 546 ETH — about $1.44 million — a common tactic to make stolen funds harder to freeze or trace.
As of the initial reports, neither Fetch.ai nor NuNet had published an official statement on the incident, and the total scope of the converter drain remained subject to on-chain reconciliation. No attribution to a known group has been made; the linkage rests on the shared receiving wallet identified by the two security firms.
The Pattern
The incident fits a recurring weak point across AI- and compute-focused crypto projects: privileged accounts — deployers, converters, minters — whose keys, once obtained, let an attacker both drain one contract and mint new supply on a connected project. The defense is unglamorous and well-known: multisig control on privileged accounts, strict separation of minting and treasury permissions, and on-chain monitoring that treats a deployer-account transaction as an alert, not a routine event.
TrustGrade tracks the security posture of protocols and firms in digital assets. Verified trust data: trustgrade.ai.