One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint
By Oluwapelumi Adejumo
Read original article on CryptoSlateA coordinated attack drained 8.7 million FET and used a compromised NuNet minter key to create 408.5 million NTX.
The Sept. 19 attack emptied the Ethereum-side conversion contract used by SingularityNET’s bridge, removing 8,721,530 FET worth about $1.55 million at the time. Twenty-nine minutes later, a stolen NuNet minter created 408.5 million NTX and sent the tokens to the same receiving wallet, according to an on-chain forensic report prepared by Athena.
Fetch.ai subsequently paused AGIX-to-FET conversions and its Ethereum-side bridge contract as a precaution. The company said the affected infrastructure belonged to SingularityNET, primarily its Ethereum-Cardano bridge, while Fetch.ai’s own contracts and normal FET transfers remained operational.
The forensic report identified the affected contract as TokenConversionManagerV3, the legitimate Ethereum-side lock-and-release component of SingularityNET’s bridge. Its verified source matches SingularityNET’s public repository, and the contract is tied to the current Artificial Superintelligence Alliance FET token.
Investigators traced the loss to a compromised backend authorization key, not a flaw that let an attacker bypass the bridge contract. The transaction carried a valid signature from the address the contract was configured to trust, allowing its conversionIn function to release the entire FET balance to an attacker-controlled wallet.
The contract’s design magnified the damage. Its 1 million FET transaction cap applied to tokens moving out of Ethereum but was not enforced onconversionIn, allowing the attacker to withdraw 8.72 million FET in one transaction. The signed message also failed to bind the eventual recipient, meaning a valid authorization could direct the tokens to an address selected by the caller.
Same wallet connects separate compromised keys
The NuNet activity provides the strongest evidence that the FET drain formed part of a broader coordinated operation.
At 20:50 UTC, 29 minutes after the FET withdrawal, a NuNet minter key dormant since March 2023 created 408,532,878 NTX and sent the entire amount to the same wallet that received the stolen FET. The mint was equivalent to roughly 42% of NuNet’s documented token supply, according to the report.
A later forensic pass tightened that connection. At 19:36 UTC, 45 minutes before the FET drain, the NuNet minter sent 0.3667 ETH directly to the eventual receiving wallet, while another attacker-linked account moved 24.3 million NTX into it.
NTX sales through MetaMask’s swap infrastructure had also begun before the FET bridge was emptied, indicating that the operation involving the two compromised credentials was already underway ahead of the main withdrawal.
The attacker then began converting the assets. The stolen FET was routed through MetaMask’s swap infrastructure and exchanged largely for Ethereum, while more than 217 million of the newly minted NTX was sold through decentralized liquidity venues.
By about 1:10 UTC on Sept. 20, the central wallet held 547.89 ETH worth roughly $1.44 million and another 230 million NTX, according to the report.
Liquidity quickly became a constraint on the NTX side. Four later sales involving 38.55 million NTX increased the attacker’s ETH balance by only about 0.30 ETH as available pools were depleted. A separate 10 million NTX transaction routed through Mayan Protocol ultimately produced about 940 USDT for cross-chain dispatch.

The disruption later widened beyond the two assets examined in the forensic report. Bitvavo suspended WMTX deposits and withdrawals on Sept. 20 after citing an active security incident affecting the token, then temporarily halted trading. The exchange said customer balances remained safe.
Historical SingularityNET material shows WMTX, FET and NTX all used infrastructure connected to its Ethereum-Cardano bridge ecosystem. The available forensic evidence, however, examined the FET and NTX activity in detail and does not establish that WMTX was compromised through the same mechanism.
Fetch.ai said it was working with SingularityNET and paused conversions while it investigated the incident.
The report’s first tracking window found that the compromised FET bridge authorizer and NuNet minter credentials had not yet been rotated or revoked roughly five hours after the attack. By then, the FET bridge was empty and inactive.
That makes credential remediation central to restoring the affected services. Refilling the FET conversion contract while the same authorizer remains trusted could expose fresh liquidity to another signed withdrawal, while NuNet faces a separate risk as long as the affected wallet retains authority to create additional NTX.
Fetch.ai’s AGIX-to-FET conversion service and Ethereum-side bridge are therefore among the clearest operational markers to watch.
For WMTX, Bitvavo has said trading and transfers will remain restricted while it assesses the incident, leaving exchange reopenings and credential rotations as the next visible tests of whether the affected infrastructure is secure.
The post One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint appeared first on CryptoSlate.
This story was originally published on CryptoSlate. DennTech aggregates headlines from top crypto publications to keep traders informed.
Read full article on CryptoSlate