Skip to main content
AVOID.NET

Audit log

Every state-changing event for Fetch.ai / NuNet Cross-Project Exploit (September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-20 12:07:35Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 448,726,956
    sig
    mjrVHGxvdpYX…Puh4jpfNexplorer ↗
    hash
    AsocUWmZwvN7…htMLNxUDsha256 → base58
    verifying row…full verify ↗
    canonical bytes (21760 B) ▸
    {"actor":"system:backfill","investigation_id":"18c96289-1f9d-428f-a5c8-b1865010e775","kind":"publish","page_slug":"fetch-ai-nunet-cross-project-exploit-september-2026","published_at":"2026-09-20T12:07:35.555Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Fetch.ai / NuNet Cross-Project Exploit (September 2026)","sections":[{"content":"On September 20, 2026, security firms PeckShield and Blockaid reported coordinated attacks against two AI-focused crypto protocols — Fetch.ai and NuNet — traceable to a single attacker wallet (0x1572...c362). According to KuCoin's news aggregation of PeckShield findings, the attacker extracted approximately 8.72 million FET tokens (valued at roughly $1.53–1.56 million) from Fetch.ai's Ethereum-based TokenConversionManagerV3 contract, and separately minted 408.5 million NTX tokens (approximately $452,000–$462,730) through NuNet's deployer account. Fetch.ai's subsequent on-chain analysis, published via the ASI:One platform and reported by KuCoin, confirmed that both attacks occurred within the same minute and shared the same compromised signing key as their root cause. The combined on-chain proceeds were converted to approximately 546.36 ETH, worth roughly $1.44 million at the time, according to PeckShield.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Fetch.ai and NuNet suffer attack, losing approximately $2 million — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-attack-losing-around-2-million"},{"credibility":2,"name":"Fetch.ai Releases On-Chain Attack Analysis, Collaborates with SingularityNET to Deactivate Affected Wallets and Contracts — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-releases-on-chain-attack-analysis-collaborates-with-singularitynet-to-deactivate-impacted-wallets-and-contracts"},{"credibility":2,"name":"Fetch.ai and NuNet Exploited for $2 Million by Same Attacker, NTX Hits All-Time Low — BeInCrypto via Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fetch-ai-nunet-exploited-2-061332635.html"}]},{"content":"Fetch.ai's TokenConversionManagerV3 is an Ethereum smart contract designed to facilitate cross-chain token conversion. According to Blockaid's analysis — reported by Coin-Turk and Coinpedia — the attacker called the contract's conversionIn function using a valid conversion-authorizer signature. Security analysis noted that the conversionIn function relied on a single externally-owned account (EOA) ECDSA signature as its sole authorization check, and lacked the limit-verification modifier (checkLimits) that is present in the outbound conversionOut function. Once the attacker possessed the signing key, the contract's on-chain verification could not distinguish a malicious transaction from a legitimate one, allowing a single call to release the entire remaining FET balance held in the converter. Fetch.ai's on-chain report, as described by KuCoin, confirmed the root cause as a compromised backend signature key for the SingularityNET cross-chain bridge — the same key infrastructure used across multiple token contracts in the ASI ecosystem.","heading":"Attack Mechanism: Fetch.ai (TokenConversionManagerV3)","severity":"critical","sources":[{"credibility":2,"name":"Fetch.ai and NuNet attacks linked, $2 million in assets lost as NTX plunges 90% — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/fetch-ai-and-nunet-attacks-linked-2-million-in-assets-lost-as-ntx-plunges-90yuzde/"},{"credibility":2,"name":"Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/hacker-steals-2-million-from-fetch-ai-nunet-in-single-attack/amp/"},{"credibility":2,"name":"One Attacker, Multiple Tokens: Inside the Fetch.ai Breach — Coindoo","type":"news_article","url":"https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/"}]},{"content":"According to PeckShield reporting aggregated by KuCoin, the same attacker wallet used in the Fetch.ai incident separately compromised NuNet's deployer account to mint 408.5 million NTX tokens without authorization. This represented approximately 42% of NuNet's stated total token supply. Fetch.ai's on-chain analysis, as reported by KuCoin, indicated the attacker obtained the NuNet minting key as part of the same key-compromise event. Multiple sources note that reports did not clarify precisely how the NuNet minting key was obtained independently of the SingularityNET bridge key, and no NuNet post-mortem had been published at the time of writing. The thin NuNet market — reported by Coindoo to have had under $50,000 in daily trading volume — made the token particularly sensitive to the large unauthorized mint.","heading":"Attack Mechanism: NuNet (Unauthorized NTX Minting)","severity":"critical","sources":[{"credibility":2,"name":"Fetch.ai and NuNet Suffer $2 Million Loss in Cyberattack — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-2m-loss-in-cyberattack"},{"credibility":2,"name":"One Attacker, Multiple Tokens: Inside the Fetch.ai Breach — Coindoo","type":"news_article","url":"https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/"},{"credibility":2,"name":"PeckShield: Same attacker breached SingularityNET, illicitly minting 260 million AGIX and 53.838 million WMTx — PANews","type":"news_article","url":"https://panews.io/articles/01a0be2e-f8c9-738c-a585-a4d7708cc32b"}]},{"content":"Following the Fetch.ai and NuNet incidents, PeckShield reported — as aggregated by KuCoin and PANews — that the same attacker proceeded to exploit a vulnerability in SingularityNET's cross-chain bridge on Ethereum, minting 260 million AGIX and 53.838 million WMTX (World Mobile Token on Ethereum). World Mobile Chain confirmed that its cross-chain bridge was exploited, leading to the unauthorized minting of WMTX. The value of minted AGIX and WMTX was reported at approximately $16.77 million at the time of discovery, though the attacker's realized proceeds differed as only a portion had been liquidated. As of the KuCoin report, the attacker's single wallet held approximately 198.3 million AGIX (roughly $14.42 million), 649 ETH (roughly $1.67 million), and 33.538 million WMTX (roughly $627,400). The SingularityNET attack is treated here as context because it shares the same attacker and the same root-cause signing key, but it is a distinct incident affecting a distinct protocol.","heading":"Expansion to SingularityNET (AGIX and WMTX)","severity":"high","sources":[{"credibility":2,"name":"Hackers exploit SingularityNET vulnerability, mint over 313 million tokens worth $16.77 million — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/hackers-exploit-singularitynet-vulnerability-mint-over-313m-tokens-worth-16-77m"},{"credibility":2,"name":"Hackers exploit SingularityNET vulnerability, minting 260M AGIX and 53.83M WMTX — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/hackers-exploit-singularitynet-vulnerability-mint-260m-agix-and-53-83m-wmtx"},{"credibility":2,"name":"PeckShield: Same attacker breached SingularityNET, illicitly minting 260 million AGIX and 53.838 million WMTx — PANews","type":"news_article","url":"https://panews.io/articles/01a0be2e-f8c9-738c-a585-a4d7708cc32b"}]},{"content":"NuNet's NTX token suffered the most severe price impact. Multiple outlets reported different figures for the intraday decline, with Coin-Turk reporting a 90% decline, CryptoAdventure and Coinpedia reporting 65%, Coindoo and The Cryptonomist reporting approximately 70%, and Coinpedia citing an all-time low price of $0.000328. Coin-Turk separately cited an all-time low of $0.00005338. The discrepancy likely reflects measurement at different points during the trading session. Cryptoadventure reported NTX closed September 18 near $0.00133 before collapsing to approximately $0.000469 on September 19. Fetch.ai's FET token registered a more modest decline — sources cited approximately 5–10% — consistent with the smaller proportion of FET's total supply that was drained.","heading":"Token Price Impact","severity":"high","sources":[{"credibility":2,"name":"Fetch.ai and NuNet Exploit Drains $2M as NTX Plunges 65% — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/fetch-ai-and-nunet-exploit-drains-2m-as-ntx-plunges-65/"},{"credibility":2,"name":"Fetch.ai and NuNet attacks linked, $2 million in assets lost as NTX plunges 90% — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/fetch-ai-and-nunet-attacks-linked-2-million-in-assets-lost-as-ntx-plunges-90yuzde/"},{"credibility":2,"name":"Fetch.ai NuNet Exploit Drains $2M, Hits Tokens Hard — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/20/fetch-ai-nunet-exploit/"}]},{"content":"Fetch.ai acknowledged the incident via a post on X (formerly Twitter), stating it had noticed reports of an exploit affecting its token conversion contract and that the team was investigating and would release an update soon, according to PANews. Subsequently, Fetch.ai published a preliminary on-chain attack analysis on the ASI:One platform tracing the full transaction path from the initial key compromise to the attacker's cash-out wallet, according to TechFlowPost and KuCoin. Fetch.ai and SingularityNET jointly deactivated the affected wallets and contracts as a remediation measure, with both organizations committing to provide ongoing investigation updates. Fetch.ai's analysis explicitly noted it was non-final at publication. No official public post-mortem from NuNet had been reported as of the date of this investigation. Blockaid published the exploiter's wallet addresses and example transactions publicly, enabling exchanges and projects to flag and block further movement of stolen funds.","heading":"Official Response and Remediation","severity":"medium","sources":[{"credibility":2,"name":"Fetch.ai: Noticed reports of token conversion contract exploit, investigation underway — PANews","type":"news_article","url":"https://panews.io/articles/01a0bdb6-d89b-7623-a349-266106980931"},{"credibility":2,"name":"Fetch.ai Discloses: Signing Key Leaked, Partners with SingularityNET to Deactivate Affected Wallets — TechFlowPost","type":"news_article","url":"https://www.techflowpost.com/en-US/newsletter/137000"},{"credibility":2,"name":"Fetch.ai Releases On-Chain Attack Analysis, Collaborates with SingularityNET to Deactivate Affected Wallets and Contracts — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-releases-on-chain-attack-analysis-collaborates-with-singularitynet-to-deactivate-impacted-wallets-and-contracts"}]},{"content":"Security analysis reported by Coin-Turk and Coinpedia identified a structural weakness in the TokenConversionManagerV3 contract's conversionIn function: it relied on a single EOA ECDSA signature as the sole authorization check, without the limit-verification modifier present in the outbound conversionOut function. This design meant the contract had no on-chain protection against a misused but cryptographically valid signature — once the signing key was compromised, the authorization model provided no additional defense. Coindoo reported that despite the contract containing signature validation checks, transaction limits, and designated authorizer controls on paper, these protections failed in practice because the root credential (the signing key) was externally compromised. This is consistent with a broader pattern noted across AI and compute-focused crypto projects where centralized off-chain key management creates a single point of failure for on-chain authorization.","heading":"Key Design Vulnerability: Single-Signature Authorization","severity":"high","sources":[{"credibility":2,"name":"Fetch.ai and NuNet attacks linked, $2 million in assets lost as NTX plunges 90% — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/fetch-ai-and-nunet-attacks-linked-2-million-in-assets-lost-as-ntx-plunges-90yuzde/"},{"credibility":2,"name":"One Attacker, Multiple Tokens: Inside the Fetch.ai Breach — Coindoo","type":"news_article","url":"https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/"},{"credibility":2,"name":"Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/hacker-steals-2-million-from-fetch-ai-nunet-in-single-attack/amp/"}]},{"content":"Multiple sources place this incident within an unusually active period of DeFi security incidents. According to search result summaries citing DefiLlama, September 2026 DeFi losses exceeded $333 million across 18 separate incidents when the Fetch.ai and NuNet exploit is included. CryptoAdventure separately cited other concurrent September 2026 attacks including a $1.7 million loss at Notional Finance, a Blink Wallet compromise, and a $10.7 million FomoPeek iOS malware campaign (WaterPlum). The total attacker holdings linked to this single threat actor — Fetch.ai FET, NuNet NTX, SingularityNET AGIX, and World Mobile WMTX — were reported by KuCoin at approximately $16.77 million, though the relationship between this figure and realized liquidations versus paper holdings in illiquid tokens was not fully clarified in public reporting at the time of writing.","heading":"Broader September 2026 DeFi Context","severity":"medium","sources":[{"credibility":2,"name":"Fetch.ai and NuNet Exploited for $2 Million by Same Attacker, NTX Hits All-Time Low — BeInCrypto via Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fetch-ai-nunet-exploited-2-061332635.html"},{"credibility":2,"name":"Fetch.ai and NuNet Exploit Drains $2M as NTX Plunges 65% — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/fetch-ai-and-nunet-exploit-drains-2m-as-ntx-plunges-65/"},{"credibility":2,"name":"Hackers exploit SingularityNET vulnerability, mint over 313 million tokens worth $16.77 million — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/hackers-exploit-singularitynet-vulnerability-mint-over-313m-tokens-worth-16-77m"}]}],"sources_used":[{"credibility":2,"name":"Fetch.ai and NuNet suffer attack, losing approximately $2 million — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-attack-losing-around-2-million"},{"credibility":2,"name":"Fetch.ai and NuNet Suffer $2 Million Loss in Cyberattack — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-2m-loss-in-cyberattack"},{"credibility":2,"name":"Fetch.ai Releases On-Chain Attack Analysis, Collaborates with SingularityNET to Deactivate Affected Wallets and Contracts — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/fetch-ai-releases-on-chain-attack-analysis-collaborates-with-singularitynet-to-deactivate-impacted-wallets-and-contracts"},{"credibility":2,"name":"Hackers exploit SingularityNET vulnerability, minting 260M AGIX and 53.83M WMTX — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/hackers-exploit-singularitynet-vulnerability-mint-260m-agix-and-53-83m-wmtx"},{"credibility":2,"name":"Hackers exploit SingularityNET vulnerability, mint over 313 million tokens worth $16.77 million — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/hackers-exploit-singularitynet-vulnerability-mint-over-313m-tokens-worth-16-77m"},{"credibility":2,"name":"Fetch.ai and NuNet Exploited for $2 Million by Same Attacker, NTX Hits All-Time Low — BeInCrypto via Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fetch-ai-nunet-exploited-2-061332635.html"},{"credibility":2,"name":"Fetch.ai and NuNet attacks linked, $2 million in assets lost as NTX plunges 90% — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/fetch-ai-and-nunet-attacks-linked-2-million-in-assets-lost-as-ntx-plunges-90yuzde/"},{"credibility":2,"name":"Fetch.ai NuNet Exploit Drains $2M, Hits Tokens Hard — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/20/fetch-ai-nunet-exploit/"},{"credibility":2,"name":"Fetch.ai Exploit: Hacker Drains $2M Across Two AI Crypto Projects — TronWeekly","type":"news_article","url":"https://www.tronweekly.com/fetch-ai-exploit-hacker-drains-2m-across-two-ai/"},{"credibility":2,"name":"Fetch.ai and NuNet Exploit Drains $2M as NTX Plunges 65% — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/fetch-ai-and-nunet-exploit-drains-2m-as-ntx-plunges-65/"},{"credibility":2,"name":"One Attacker, Multiple Tokens: Inside the Fetch.ai Breach — Coindoo","type":"news_article","url":"https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/"},{"credibility":2,"name":"Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/hacker-steals-2-million-from-fetch-ai-nunet-in-single-attack/amp/"},{"credibility":2,"name":"Fetch.ai: Noticed reports of token conversion contract exploit, investigation underway — PANews","type":"news_article","url":"https://panews.io/articles/01a0bdb6-d89b-7623-a349-266106980931"},{"credibility":2,"name":"PeckShield: Same attacker breached SingularityNET, illicitly minting 260 million AGIX and 53.838 million WMTx — PANews","type":"news_article","url":"https://panews.io/articles/01a0be2e-f8c9-738c-a585-a4d7708cc32b"},{"credibility":2,"name":"Fetch.ai Discloses: Signing Key Leaked, Partners with SingularityNET to Deactivate Affected Wallets — TechFlowPost","type":"news_article","url":"https://www.techflowpost.com/en-US/newsletter/137000"},{"credibility":2,"name":"SingularityNET attacked: hackers illegally mint AGIX and WMTx — TechFlowPost","type":"news_article","url":"https://www.techflowpost.com/en-US/newsletter/137002"}],"summary":"On September 20, 2026, a single attacker exploited a compromised signing key to drain approximately $1.55 million in FET tokens from Fetch.ai's TokenConversionManagerV3 contract on Ethereum, then pivoted within the same minute to mint 408.5 million unauthorized NTX tokens from NuNet, for a combined loss of roughly $2 million. PeckShield and Blockaid both confirmed the two incidents were linked to a single wallet (0x1572...c362), which converted all proceeds to 546.36 ETH. The same attacker subsequently exploited SingularityNET's cross-chain bridge, minting 260 million AGIX and 53.84 million WMTX, bringing estimated total attacker holdings to approximately $16.77 million across all three incidents.","timeline":[{"date":"2026-09-20","event":"Attacker wallet (0x1572...c362) calls conversionIn on Fetch.ai's TokenConversionManagerV3 contract using a compromised but cryptographically valid signing key, draining approximately 8.72 million FET (~$1.55 million) in a single transaction.","source":"KuCoin / PeckShield","source_url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-attack-losing-around-2-million"},{"date":"2026-09-20","event":"Within the same minute as the FET drain, the same wallet mints 408.5 million NTX tokens (approximately $452,000–$462,730, representing ~42% of NuNet's total supply) through NuNet's deployer account without authorization.","source":"KuCoin / Fetch.ai on-chain analysis","source_url":"https://www.kucoin.com/news/flash/fetch-ai-releases-on-chain-attack-analysis-collaborates-with-singularitynet-to-deactivate-impacted-wallets-and-contracts"},{"date":"2026-09-20","event":"All stolen FET and NTX proceeds are converted to approximately 546.36 ETH (~$1.44 million), as reported by PeckShield.","source":"KuCoin / PeckShield","source_url":"https://www.kucoin.com/news/flash/fetch-ai-and-nunet-suffer-2m-loss-in-cyberattack"},{"date":"2026-09-20","event":"NTX token hits an all-time low, declining between 65% and 90% intraday depending on the measurement point. FET declines approximately 5–10%.","source":"CryptoAdventure / Coin-Turk","source_url":"https://cryptoadventure.com/fetch-ai-and-nunet-exploit-drains-2m-as-ntx-plunges-65/"},{"date":"2026-09-20","event":"Blockaid publicly confirms both incidents are linked to a single attacker and publishes the exploiter's wallet address (0x1572...c362) and example transactions to enable exchanges to flag and block funds.","source":"BeInCrypto via Yahoo Finance","source_url":"https://finance.yahoo.com/markets/crypto/articles/fetch-ai-nunet-exploited-2-061332635.html"},{"date":"2026-09-20","event":"Fetch.ai posts on X acknowledging reports of an exploit targeting its token conversion contract and states the team is investigating.","source":"PANews","source_url":"https://panews.io/articles/01a0bdb6-d89b-7623-a349-266106980931"},{"date":"2026-09-20","event":"PeckShield reports the same attacker subsequently exploited SingularityNET's cross-chain bridge on Ethereum, minting 260 million AGIX and 53.838 million WMTX, with attacker holdings growing to approximately $16.77 million across all incidents.","source":"PANews / KuCoin","source_url":"https://panews.io/articles/01a0be2e-f8c9-738c-a585-a4d7708cc32b"},{"date":"2026-09-20","event":"Fetch.ai publishes a preliminary on-chain attack analysis on ASI:One platform, attributing the root cause to a compromised backend signature key for the SingularityNET cross-chain bridge. Fetch.ai and SingularityNET jointly deactivate affected wallets and contracts.","source":"TechFlowPost / KuCoin","source_url":"https://www.techflowpost.com/en-US/newsletter/137000"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 793f0efe-c28a-49ed-a487-b605797e8c34
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.