Fetch.AI, NuNet and SingularityNET targeted in $17M token attack

59 minutes ago 21

A coordinated exploit ripped through three interconnected AI-crypto projects on September 19, netting an attacker roughly $17 million in unrealized gains and sending token prices into freefall. The breach hit Fetch.ai, SingularityNET, and NuNet, all members of the Artificial Superintelligence Alliance (ASI) ecosystem, through what appears to be a single compromised set of privileged signing keys.

The attacker’s strategy was methodical: drain real tokens first, then mint fake ones at scale. Approximately 8.72 million FET tokens were siphoned from Fetch.ai’s TokenConversionManagerV3 contract using what security analysts identified as a valid signature call.

How the attack unfolded

After emptying the Fetch.ai contract, the attacker pivoted to NuNet. Using a compromised deployer account, they minted around 408.5 million unauthorized NTX tokens.

The minting spree didn’t stop there. Hundreds of millions of additional AGIX and WMTx tokens followed shortly after, bringing the total volume of newly created tokens to roughly 2.3 billion across multiple assets including AGIX, NTX, CGV, and WMTx.

Realized profits from actual token sales landed between $2 million and $2.25 million, mostly from FET tokens converted into ETH. The gap between that figure and the $17 million number matters: PeckShield estimated the attacker’s total holdings, including approximately 198 million AGIX tokens and various other assets, peaked at about $16.77 million.

NTX’s price collapsed between 65% and over 90% depending on which tracker you consulted. FET, the largest token by market cap among the three, experienced more moderate declines.

The root cause: privileged keys

Security firms Blockaid, PeckShield, and Bitquery traced the malicious activity back to a singular attacker cluster. The common thread across all three exploits was compromised privileged keys, the kind of administrative access that controls minting authority and contract upgrades.

All three projects responded by pausing related operations, deactivating vulnerable keys, and shutting down affected contracts.

A recurring pattern in DeFi security

The minting dimension of this attack adds a particularly nasty wrinkle. Draining existing tokens from a contract is bad. Creating billions of new tokens from thin air is worse, because it destroys the economic foundation of the asset itself. NTX holders didn’t just lose value from a sell-off. They lost value because the supply of their token was inflated by hundreds of millions of units in a matter of minutes.

The investigation is still active, and some wallets associated with the attacker reportedly remain unprotected, meaning additional losses could still materialize.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article