Key Takeaways
- Fetch.ai lost 8.72 million FET after a compromised signing key opened its converter.
- NTX got hammered after 408.5 million new tokens, roughly 42% of supply, were minted.
- Fetch.ai traced both attacks to the same window, but how the keys escaped is still unknown.
One Attacker, Two Crypto Projects and $2 Million Gone
Late Saturday into Sunday, somebody holding the right cryptographic keys managed to hit two crypto projects almost simultaneously, turning what could have looked like unrelated exploits into one very strange $2 million heist. On the Fetch.ai side, 8,721,530 FET, worth roughly $1.55 million, disappeared from a token converter. On the other side, the attacker didn’t merely steal coins already sitting somewhere.
They created about 408.5 million new NTX, worth roughly $452,000 to $463,000 at the time. That mint represented about 42% of NTX’s supply. Peckshield, Blockaid and Fetch.ai ultimately connected the activity to the same wallet cluster.
One Signature Opened the FET Vault
The latest FET theft wasn’t a case of somebody discovering a clever mathematical flaw and hammering a smart contract. Fetch.ai’s TokenConversionManagerV3 contract accepted a valid conversion-authorizer signature through its conversionIn()function. The problem was that this signature was essentially the gatekeeper. Unlike conversionOut(), the function didn’t run the checkLimits(amount) modifier, nor did it verify onchain that corresponding tokens had been locked or burned elsewhere.
Once the signing key was compromised, the attacker could create a fresh valid message pointing to their own address. One transaction later, the converter’s remaining FET inventory was gone. Fetch.ai’s preliminary review traced the compromised credential to a backend signing key used by SingularityNET’s cross-chain bridge. A separate NTX minting key was compromised as well, with Fetch.ai saying both attack paths began in the same minute.

That timing is where the story gets stranger. These weren’t simply two projects having bad weekends at once. The same operator appears to have obtained credentials capable of authorizing transactions across connected infrastructure, then used them almost simultaneously.
408.5 Million Tokens Appeared From Thin Air
The NTX side was considerably more destructive to the token itself. Instead of draining a finite wallet, the attacker gained the ability to create new coins. Roughly 408.5 million NTX suddenly entered the equation, equivalent to about 42% of supply.
Put another way, for every 10 NTX already represented in the supply, the attacker had suddenly created the equivalent of roughly four more.

That’s a brutal problem for a thinly traded token. The NTX exchange rate had been sitting near $0.0013 before the incident. Market data showed it falling more than 70% and touching a $0.000328 low, while later feeds printed even lower prices as liquidity deteriorated. Some trackers recorded declines of 96% to 99%, though exact prices varied sharply between venues because the market was so thin.
FET took a very different punch. Its circulating supply didn’t suddenly balloon because the attacker stole existing inventory from a converter. FET fell roughly 5% to 8% across several feeds, painful but nowhere near NTX’s collapse.
The Loot Quickly Became ETH
The attacker didn’t simply leave the stolen assets sitting around. PeckShield tracked the wallet cluster swapping proceeds into 546.36 ETH, worth roughly $1.44 million at the time. Fetch.ai’s later snapshot showed about 547.89 ETH alongside approximately 230 million NTX still sitting in one wallet.

That remaining NTX matters because a large chunk of the newly minted supply apparently hadn’t been sold when Fetch.ai published its initial analysis. The market, therefore, had to contend not only with coins already dumped but with hundreds of millions more potentially hanging over thin order books.
Fetch.ai said treasury funds, exchange wallets, and user coins held in self-custody or on exchanges weren’t affected. The team began working with SingularityNET to disable the affected wallets and contracts while warning users to ignore unsolicited messages and rely on official channels.
The Missing Answer Is How the Keys Escaped
Investigators have explained the machinery of the attack far better than its origin. SlowMist detailed how the FET converter accepted the compromised signature, while Fetch.ai identified the SingularityNET bridge signer and NTX minting key involved. What nobody has publicly established is how those credentials were compromised in the first place.
There’s no confirmed public answer yet showing whether phishing, a server intrusion, a leaked backup or something else put the keys in the attacker’s hands. There are also hundreds of millions of newly minted NTX still to account for, along with the question of whether exchanges can freeze labeled funds or the extra supply can somehow be neutralized.
The blockchain did exactly what the valid signatures told it to do. That may be the strangest part of the whole episode. FET bent. NTX broke.


