Attacker Drains $1.56M in FET From Fetch.ai Token Converter

An exploiter drained $1.56M in FET from Fetch.ai's token converter via a single signature call, part of a $2.01M wallet cluster attack that also hit NuNet.

(08:45 AM UTC)
4 min read
AI SummaryAI
  • Attacker drained $1.56 million in FET from Fetch.ai's TokenConversionManagerV3 on September 20.
  • The exploiter wallet 0x1572…c362 received a roughly $452,000 NTX mint from the NuNet deployer.
  • Combined activity across the wallet cluster reached approximately $2.01 million.
  • The exploiter swapped stolen funds into 546.36 ETH, worth about $1.44 million.
k7rq2fdm

One Signature Drains Fetch.ai Converter

An attacker drained approximately $1.56 million in FET from the Fetch.ai token converter on Ethereum on September 20, and on-chain forensics now tie the same wallet to a coordinated raid on the NuNet (NTX) protocol. Blockaid, the security research firm whose alert went out within hours of the breach, reported that the exploiter deployed a valid conversion-authorizer signature in order to invoke the conversionIn function on TokenConversionManagerV3, the contract module that processes FET conversions. A single authorized call was enough to release the converter's entire remaining FET inventory into attacker-controlled wallets, which the firm attributed to the address 0x1572...c362.

The mechanism matters as much as the headline figure. A converter of this kind sits between a protocol and its token supply, shuttling value between deployments much the way cross-chain bridges move assets between networks — and when the authorization around one privileged function rests on a thin check, the module's whole balance is exposed to a single transaction. That is what unfolded here: instead of chaining several capped withdrawals, the attacker submitted one signature-verified call and swept the module clean. The speed of the response — detection, public alerting and wallet attribution all landing on the same day — reflects how closely on-chain security desks now monitor conversion infrastructure. What remains undisclosed is any statement from the Fetch.ai team on remediation or compensation; no such announcement had been published at the time of writing, so readers should treat fund recovery as unconfirmed. Earlier in the session FET had slipped about 5%; live spot data now shows a 6.7% decline over the past 24 hours, a move our desk reads as broad-market pressure layered on top of the security headline rather than systemic damage to the Artificial Superintelligence Alliance ecosystem.

NuNet Token Collapses to Record Low

The same wallet cluster moved well beyond FET. On-chain data shows the Fetch.ai loot wallet received a large mint of NuNet's NTX token directly from the NuNet deployer account, a supply injection valued at roughly $452,000, which lifted combined activity across the cluster to approximately $2.01 million. PeckShield's tracing adds that the exploiter has since swapped the stolen proceeds into 546.36 ETH, worth about $1.44 million at the time of that analysis — a standard laundering step aimed at escaping a token whose exit liquidity is thin. NTX bore the brunt of the fallout: it collapsed to an all-time low of $0.000328 on September 20 and traded near $0.0004 at the time of reporting, down more than 70% within 24 hours as holders rushed for the door across every exchange venue that lists the asset. For a low-capitalization token, a single wallet controlling new supply proved catastrophic. The incident also lands in a brutal month for the sector. Nostra, a Starknet lending protocol, lost $3.5 million to a manipulated oracle three days earlier, and aggregate hack-tracking data had already logged roughly $331 million in losses across 17 incidents this September before the Fetch.ai drain — most of it from the $320 million Liquid Network breach. With the FET and NTX episodes included, the month's exploit tally now exceeds $333 million. The broader tape offered no cushion, with total crypto market capitalization down about 4% on the day and a risk-off backdrop that analysts describe as classic bear market conditions keeping buyers away from distressed tokens.

Signature-Only Authorization Under Scrutiny

The arc across both incidents is hard to miss: one attacker, two protocols, and a shared weakness in authorization logic that trusts a single off-chain signature. SlowMist's post-incident analysis pins the root cause precisely: conversionIn() relied on a single-EOA ECDSA signature as its sole check, omitting the checkLimits(amount) modifier that conversionOut() carries and verifying nothing on-chain. The remediation, read straight from the primary evidence, is unambiguous — every privileged call needs on-chain validation and amount limits. Until converter and bridge-style modules adopt that standard, COINOTAG expects September's $333 million loss ledger to keep growing. The episode also lands as AI-linked tokens face renewed scrutiny; our related coverage, AI tokens like FET in focus, shows how headline risk is compounding for the sector.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.