Two AI-flavored crypto projects got hit by what security firms say is the same attacker on September 19, walking away with close to $2 million combined. According to Coinpedia’s Sep 20 report citing Blockaid and PeckShield, the shared trail is a single wallet that received stolen Fetch.ai tokens and then minted unauthorized NuNet supply—an ugly weekend reminder that “AI crypto” still dies the old-fashioned way: bad permissions and fast exits into ETH.
How the double hit unfolded
Coinpedia’s reconstruction, based on the two firms’ on-chain notes:

- The attacker drained about 8.7 million FET, worth roughly $1.53 million, from a Fetch.ai token converter contract.
- The same wallet that caught those funds was then used to mint about 408.5 million unauthorized NTX, worth around $463,000, through NuNet’s deployer account.
- That shared destination wallet is what lets researchers attribute both events to one actor rather than two coincidental weekend exploits.
Blockaid published the exploiter addresses and an example transaction so exchanges, bridges, and other projects can flag further movement. In practice, that is the industry’s first line of defense after a drain: name the wallets loudly before the next hop finishes.
Token prices got wrecked
Market reaction was ugly and uneven. Trackers cited by Coinpedia show NuNet’s NTX crashing as much as 65–70% after the mint flood—exactly what you expect when fresh unauthorized supply hits a thin market—while FET dropped around 10%. The attacker moved quickly to convert a large portion of the haul into roughly 546 ETH (~$1.44 million).

That ETH conversion is not a flourish. It is a playbook step: leave the ecosystem tokens, reduce the chance a team or exchange freezes the exact stolen asset, and scramble tracing across a more liquid base. Holders watching NTX’s chart saw the inflation shock first; researchers watching the wallet graph saw the exit path second.
Silence from the teams (so far)
As of Coinpedia’s Sep 20 write-up, neither Fetch.ai nor NuNet had issued an official statement. Security researchers tracking the incident are telling holders to stay cautious until the teams confirm what broke, which contracts are paused, and whether related deployer or converter surfaces are safe to touch again.
That silence matters operationally. Without a postmortem, retail users cannot tell whether the issue was a one-off compromised key, a logic bug in a converter, a deployer misconfiguration, or something still live. Default posture until then: assume related contracts are hostile and wait for primary-source confirmation.
Why AI-crypto stacks keep showing this bruise
Coinpedia’s broader read matches a pattern Geeknewz watches across “AI + compute” tokens: permissioned converter and deployer surfaces. Misconfigured or compromised controls that let an attacker drain one contract and then mint on an unrelated project via the same stolen access path turn a single breach into a multi-ecosystem event.
Fetch.ai (agent/AI narrative) and NuNet (decentralized compute narrative) sit in the same marketing neighborhood even when their contracts are separate. Shared operational keys, loose deployer privileges, and converter contracts with broad allowances remain the boring failure mode that still pays out millions. The branding says future-of-AI; the exploit path says 2018 DeFi hygiene.
What to watch next
- Official incident posts from Fetch.ai and NuNet—root cause, paused contracts, remediation.
- Exchange and bridge flags on the Blockaid-published wallets and any fresh hop addresses.
- NTX circulating supply accounting after the unauthorized mint—whether a burn, pause, or redeploy is proposed.
- FET converter status — whether the drained contract is frozen or replaced.
Geeknewz take
This is not a novel zero-day narrative—it is another reminder that “AI crypto” does not get a free pass on basic contract hygiene. A converter drain plus a deployer mint linked by one wallet is about as textbook as weekend exploits get. Until Fetch.ai and NuNet publish postmortems, treat FET/NTX ecosystem contracts as hostile, watch the Blockaid-flagged wallets, and assume the ETH exit was the attacker’s way of saying the weekend’s work is done.
Source: Coinpedia — Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack (Anjali Belgaumkar, Sep 20, 2026).
