Fetch.ai NuNet exploit drains $2M, sends NTX crashing 70% to record low

2 hours ago 33
Fetch.ai NuNet exploit

A single wallet drained roughly $2 million from two different crypto projects within hours of each other, and the fallout has been brutal for one of them. The Fetch.ai NuNet exploit hit both protocols through what appears to be the same attacker, according to security firm Blockaid, sending NuNet’s NTX token crashing to a record low while Fetch.ai’s FET absorbed a smaller but still notable hit.

Key takeaways

  • The same attacker is linked to exploits on both Fetch.ai and NuNet, involving roughly $2 million in combined value.
  • Blockaid says the attacker used a valid authorization signature to drain about $1.56 million in FET from Fetch.ai’s TokenConversionManagerV3.
  • The attacker also minted around $452,000 worth of NuNet’s NTX token using the same wallet.
  • NTX crashed more than 70% in 24 hours to an all-time low of $0.000328, while FET fell about 5%.
  • September 2026 DeFi losses now exceed $333 million across 18 incidents, per DefiLlama data.

Dual Exploit Targets Fetch.ai and NuNet Protocols

One wallet, two protocols, roughly $2 million gone. That’s the short version of what Blockaid reported on September 20, tying a single exploiter to attacks that hit both Fetch.ai and NuNet almost simultaneously. The security firm identified the attacker’s wallet address as 0x1572…c362 and connected it to activity across both projects’ smart contracts.

What makes this case stand out isn’t just the dual-protocol reach — it’s how clean the exploit method was. No obvious brute-force attack, no complicated multi-step manipulation on the Fetch.ai side. Just one call that unlocked a large pool of tokens.

Technical Method Using Authorization Signature

According to Blockaid, the attacker used a valid conversion-authorizer signature to call the conversionIn function on Fetch.ai’s TokenConversionManagerV3 contract on Ethereum. That single call released the converter’s remaining FET inventory, draining approximately $1.56 million worth of the token.

This is worth pausing on. A valid signature means the attacker didn’t have to break encryption or exploit a bug in the traditional sense — they had authorization credentials that should have controlled access, and used them to empty the contract in one move. The mechanics behind how that signature was obtained weren’t detailed by Blockaid, but the outcome was straightforward: the converter’s FET reserves were gone in a single transaction.

Attacker’s Wallet Activities

The same wallet that received the stolen FET also picked up a large NTX mint originating from the NuNet deployer account. Blockaid estimated that mint at roughly $452,000 worth of tokens. Combined, the Fetch.ai drain and the NuNet mint pushed the total value tied to this wallet cluster to approximately $2.01 million.

PeckShieldAlert, another blockchain security tracker, reported that the attacker didn’t sit on the stolen assets. Instead, the funds were swapped for 546.36 ETH, worth roughly $1.44 million at the time of reporting — a move that converts the loot into a more liquid, widely traded asset and makes tracing or freezing the proceeds considerably harder.

Post-Exploit Asset Conversion and Token Market Impact

The market reaction split sharply between the two tokens, and the gap tells its own story about exposure and liquidity. NuNet’s NTX collapsed. Fetch.ai’s FET wobbled but held up far better.

NTX hit an all-time low of $0.000328 following the exploit, with the token trading near $0.0004 at press time — a drop of more than 70% within 24 hours. That kind of move essentially wipes out most of the token’s trading value in a single day, a scale of loss that goes well beyond what a typical market sell-off produces.

FET, by comparison, fell about 5% over the same window. That decline lined up with a broader crypto market slide, where most major digital assets traded lower and total crypto market capitalization dropped around 4%. In other words, FET’s dip looks more like it rode the market down than collapsed under the weight of the exploit itself — a meaningful distinction for anyone trying to gauge how much of the damage was project-specific versus market-wide.

That contrast matters for how the two projects get judged going forward. A token that falls in line with the broader market can recover once sentiment turns. A token that loses 70% of its value on a direct exploit carries a different kind of scar — one tied to trust in the protocol’s security rather than macro conditions.

Wider DeFi Sector Losses in September 2026

This exploit didn’t happen in isolation — it landed in what’s already been a rough month for decentralized finance. Before the Fetch.ai and NuNet incidents, DefiLlama had tracked roughly $331 million in losses across 17 separate incidents in September 2026 alone, with the bulk of that figure coming from a single $320 million hit tied to the Liquid Network.

Add the Fetch.ai and NuNet losses, and the month’s total DeFi damage now exceeds $333 million across 18 incidents. That’s a striking figure for a single month, and it places this latest exploit alongside other recent security failures rather than as an outlier.

Just three days before the Fetch.ai and NuNet incidents, the Starknet-based lending protocol Nostra lost $3.5 million to an oracle manipulation attack. Taken together, the pattern suggests September has been an especially costly month for DeFi security across multiple chains and protocol types — from lending platforms to token converters to cross-chain infrastructure.

For crypto investors and builders watching this unfold, the recurring theme is authorization and validation failures rather than purely code-level bugs. Whether it’s a manipulated oracle feed or a valid-but-misused signature, the common thread across several of September’s biggest losses is that the systems trusted to verify legitimacy were the point of failure — not necessarily the smart contract logic itself.

BeInCrypto reached out to both Fetch.ai and NuNet for comment on the exploit; neither had issued a public statement at the time of reporting.

FAQ

How was the attacker able to exploit Fetch.ai’s protocol?

The attacker used a valid conversion-authorizer signature to call the conversionIn function on TokenConversionManagerV3, releasing the remaining FET inventory in a single transaction.

What happened to NuNet’s NTX token after the exploit?

The NTX token dropped more than 70% in 24 hours, hitting an all-time low of $0.000328.

Did the attacker convert the stolen tokens into another asset?

Yes. According to PeckShieldAlert, the attacker swapped the stolen funds for 546.36 ETH, worth about $1.44 million.

What is the broader impact of this exploit on the DeFi sector in September 2026?

Including the Fetch.ai and NuNet exploit, DeFi losses in September 2026 have exceeded $333 million across 18 separate incidents, according to DefiLlama.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article