Fetch.ai is investigating a multi-token security breach after an attacker leveraged a leaked signing key to drain and mint digital assets across affiliated projects. The incident, first reported on September 20, 2026, initially centered on roughly 8.7 million FET—worth about $1.5 million—removed from Fetch.ai’s TokenConversionManagerV3 contract on Ethereum. Blockchain security firm Blockaid said the attacker presented a valid conversion-authorizer signature, allowing the contract to release its remaining FET balance.
Fetch.ai later published a preliminary onchain analysis tracing the attack path to a compromised signing key. The project said it worked with SingularityNET to deactivate affected wallets and contracts, but stressed that the investigation remains open. The same receiving wallet was subsequently linked to the unauthorized creation of approximately 409 million NTX through a NuNet deployer account, valued near $460,000 at issuance. Security researchers at PeckShield then connected the wallet to further unauthorized mints of roughly 260 million AGIX and 54 million WMTX, bringing the attacker’s reported holdings to around $17 million.
The impact varied by token. The FET loss involved existing tokens being moved, while the NTX mint represented about 41% of the token’s one billion maximum supply, creating immediate dilution concerns. NTX fell roughly 70% and hit an all-time low on September 20, while FET declined more moderately. Thin liquidity exacerbated the damage: CoinGecko showed less than $50,000 in rolling 24-hour NTX volume, compared with the reported mint value of about $460,000.
SlowMist noted that Fetch.ai’s incoming conversion function relied on a single externally owned account signature and lacked some restrictions present in another conversion function. Fetch.ai’s final investigation still needs to clarify access exposure, which unauthorized tokens will remain recognized, whether other contracts share the same signing arrangements, and how affected projects plan to freeze, burn, or replace unauthorized tokens. Until those questions are answered, market participants are being urged to rely only on official channels.