A single wallet stole 8.7 million FET and minted 408.5 million NTX, exposing major risks in bridge security and token supply for users and exchanges.
One wallet pulled off a coordinated attack that stole $1.55 million in FetchAI tokens and minted 408.5 million new NuNet tokens. The breach exposed serious gaps in bridge security and token mint controls. The attacker drained all FET from SingularityNET's Ethereum bridge. Then, using a dormant NuNet minter key, they created a flood of new NTX-about 42% of the token's reported supply.
Bridge and minter compromised
The attack happened in two quick steps. First, the Ethereum contract running SingularityNET's bridge lost 8,721,530 FET, worth about $1.55 million. Investigators found the cause: a backend authorization key had been compromised, not a smart contract bug. The attacker used a valid signature from a trusted address to call the contract's 'conversionIn' function. This let them bypass the 1 million FET transaction cap and empty the whole balance at once. The contract failed to enforce its own limit, which made the loss worse.
PeckShield estimated the total loss at approximately $2 million, with the attacker minting 408.5 million NTX-about 42% of the token's supply-in a single exploit.
Within 30 minutes, the same wallet got 408,532,878 freshly minted NTX. The attacker used a previously inactive NuNet minter key to create the tokens. This mint instantly diluted existing holders and put pressure on liquidity and prices across exchanges.
On-chain evidence and attack sequence
Forensic analysis showed the NuNet minter sent a small amount of ETH to the receiving wallet before the FET theft. Another attacker-linked account moved 24.3 million NTX into the same address. NTX sales through MetaMask's swap started even before the FET bridge was drained, showing the operation was planned and used both compromised credentials. After the theft, the attacker quickly swapped stolen FET for ETH and sold over 217 million NTX on decentralized platforms. By early September 20, the wallet held 547.89 ETH (about $1.44 million) and 230 million NTX. But further NTX sales hit liquidity limits as pools ran dry.
Bitvavo, a European exchange, stopped WMTX deposits and withdrawals after a related security incident. The exchange said customer balances were safe. WMTX, FET, and NTX all use infrastructure tied to SingularityNET's Ethereum-Cardano bridge. But the evidence focused on FET and NTX, and did not confirm WMTX was hit the same way.
Fetch.ai clarified that the incident impacted SingularityNET infrastructure, not its own contracts, and that regular FET transfers and treasury wallets were unaffected. Both Fetch.ai and SingularityNET deactivated affected wallets and contracts, temporarily suspending AGIX-to-FET conversions during the investigation.
Operational fallout and security response
Fetch.ai paused AGIX-to-FET conversions and disabled its Ethereum-side bridge contract. The company stressed that the affected infrastructure belonged to SingularityNET. Fetch.ai's own contracts and normal FET transfers kept working. The forensic report noted that, five hours after the attack, the compromised bridge authorizer and NuNet minter credentials still had not been rotated or revoked. This left the system open to more attacks if services restarted too soon.
Fixing credentials is now the main step to restore services. Refilling the FET conversion contract without replacing the authorizer could let attackers strike again. NuNet faces ongoing risk as long as the compromised wallet can still mint tokens. Bitvavo has kept WMTX trading and transfers restricted while it investigates. The next key steps for users and exchanges will be rotating credentials and reopening affected services. These moves will show if the infrastructure is secure again.
Events like this echo lessons from a previous investigation into bridge and key management failures. Even strong private key controls can fail if operational mistakes or design flaws are present.
Token supply and market impact
The NTX mint-over 400 million tokens-instantly diluted the supply. The attacker could only sell part of it before liquidity dried up. Four later NTX sales, totaling 38.55 million tokens, brought in just 0.30 ETH, showing how quickly decentralized pools can run out under stress. Another 10 million NTX went through Mayan Protocol, netting about 940 USDT for cross-chain transfer. On the FET side, most stolen tokens were swapped for ETH using MetaMask's swap feature.
During the attack, the FET bridge contract was left empty and inactive. The attacker's wallet held a mix of ETH and unsold NTX. The fast draining of liquidity pools and the huge NTX mint show how one compromised key can disrupt tokenomics and markets, especially for tokens with thin liquidity or centralized minting.
On September 19, the attacker drained 8,721,530 FET from SingularityNET's Ethereum bridge, worth about $1.55 million. Twenty-nine minutes later, 408,532,878 NTX were minted and sent to the same wallet, about 42% of NuNet's reported supply. By 1:10 UTC on September 20, the wallet held 547.89 ETH (about $1.44 million) and 230 million NTX, according to the forensic report. Later NTX sales quickly hit liquidity limits, with four sales totaling 38.55 million NTX bringing in only 0.30 ETH as pools emptied.
Bridge infrastructure is still one of the weakest spots in crypto. Unlike decentralized protocols, bridges and minters often depend on a few privileged keys or backend authorizers. If these credentials are not rotated quickly after a breach-or if contract logic fails to enforce transaction limits and recipient checks-attackers can drain funds or mint tokens at will. This incident shows why strong operational security, regular credential rotation, and safer contract designs are needed to limit the damage from a single compromised key. For users and exchanges, it's a warning: token supply and liquidity can change overnight, and even big-name projects face real infrastructure risks.