
Wallet cluster allegedly drained 8.72M FET and minted 408.5M NTX in minutes
The NTX mint equaled about 42% of circulating supply and was followed by a reported 65% to >90% price collapse.
A single on-chain wallet cluster was described as hitting Fetch.ai and NuNet within minutes on Sept. 19, draining about 8.72 million FET from a conversion contract and receiving roughly 408.5 million newly minted NTX from NuNet’s deployer account. The combined value was cited near $2.01 million at the time, but the NTX leg turned the incident into a supply-shock event rather than a simple treasury loss.
Key Takeaways
- A single on-chain actor cluster was described as draining ~8.72M FET from Fetch.ai’s TokenConversionManagerV3 on Ethereum and receiving ~408.5M newly minted NTX from NuNet’s deployer account within minutes on Sept. 19, 2026.
- The two legs were valued near ~$2.01M at the time, with the FET drain estimated around ~$1.53M–$1.56M depending on the price snapshot used.
- The NTX mint was described as roughly 42% of NuNet’s circulating supply, and NTX was reported down ~65% to more than 90% in the hours that followed.
- After consolidating funds, the cluster reportedly swapped a large share into ETH, with PeckShield and Blockaid figures clustering around ~546 ETH (~$1.44M).
Two AI Tokens, One Cluster: FET Drained and NTX Minted Within Minutes
The core linkage in this incident is not the dollar value. It is the routing. On Sept. 19, 2026, a single wallet cluster was described as first pulling about 8.72 million FET from Fetch.ai’s TokenConversionManagerV3 contract on Ethereum, then receiving a freshly created batch of roughly 408.5 million NTX from NuNet’s deployer account minutes later.
That shared destination wallet is doing most of the evidentiary work. The packet does not include transaction hashes or exact timestamps, but the narrative spine is that both flows landed in the same cluster, which is why trackers treated it as one coordinated operator rather than two unrelated failures that happened to occur on the same night.
The combined haul was valued near $2.01 million at the time of the moves. The FET withdrawal was framed as the larger immediate cash component, with researchers estimating the drain at about $1.53 million to $1.56 million depending on the snapshot used. The NTX mint was described as adding “another several hundred thousand dollars” in newly issued coins, but its market impact was not bounded by that mark-to-market figure.
On-chain follow-through was fast. After consolidating the drained FET and the minted NTX, the cluster reportedly swapped a large share of proceeds into “hundreds of ether,” with figures cited by PeckShield and Blockaid clustering around 546 ETH, or about $1.44 million.
Why NTX ‘Broke’: A 42% Circulating-Supply Expansion Meets Thin Liquidity
Traders tend to bucket exploits as either a balance-sheet hit or a market-structure hit. The FET leg reads like the former. The NTX leg reads like the latter, and that is why the damage function diverged.
The reported NTX mint was roughly 408.5 million tokens, described as about 42% of NuNet’s circulating supply. That is not “sell pressure.” That is a one-transaction rewrite of scarcity. If the new supply can reach venues where NTX trades, the market has to clear a much larger float immediately, and it has to do it through whatever liquidity is actually posted, not whatever liquidity token holders assume exists.
That is the mechanical reason the reported drawdown range is so wide and so ugly. Reports put NTX’s collapse anywhere from about 65% to more than 90% in the hours after the mint, with one tracker citing a plunge from roughly $0.0013 toward “a few cents of a cent” as the new coins hit circulation. Volume jumped, but the activity was characterized as forced selling rather than stabilization buying, which is what you see when the marginal seller is not optimizing price and the marginal buyer is waiting for the book to finish repricing.
FET’s reaction was described as a slip as traders priced in a converter failure and a confidence hit around the “Artificial Superintelligence cluster.” That contrast matters. A drain from a contract is painful, but it is at least numerically bounded by what was in the contract. A mint that expands circulating supply by roughly two-fifths is not bounded the same way, because it changes the denominator every holder is implicitly long.
The other reason NTX “broke” is that dilution events are reflexive in thin markets. Once participants believe supply has become untrustworthy, they stop quoting tight spreads, they pull bids, and they demand a larger discount to hold inventory. That can turn a few hundred thousand dollars of minted notional into a multi-hour air pocket.
Privileged Access as the Common Failure Mode: Converter Authorization vs Deployer Mint Rights
Both legs, as described, hinge on permissioning rather than a public, permissionless bug. That is the uncomfortable through-line for anyone trading AI-token ecosystems that share teams, tooling, or operational assumptions.
On the Fetch.ai side, the incident “appears to have used a conversion authorization that the contract accepted without confirming that matching tokens had been locked or burned elsewhere.” TokenConversionManagerV3, in this framing, is a conversion-management contract. If it will release FET based on an authorization without verifying the corresponding lock or burn on the other side of the conversion, then the contract is effectively trusting a privileged message more than it trusts the asset accounting it is meant to enforce.
On the NuNet side, the incident “looks more like compromised minting rights on the deployer.” The deployer account is the address that deployed the token contract and may retain privileged permissions, including minting new tokens. If that key is compromised, or if mint rights were not properly constrained or revocable, the token contract can do exactly what it was built to do for an authorized caller: create supply.
This is why the shared-wallet cluster detail matters more than the exact exploit path. Two different mechanisms can still share one failure mode: privileged access that should have been either impossible to misuse or easy to revoke. In both cases, the contracts did what privileged callers asked them to do.
There is also a second-order risk embedded in the “alliance neighborhood” framing. When projects sit close to each other operationally, the market tends to assume shared upside. The catch is that shared operational surfaces can also mean shared downside, especially if key custody practices, signing infrastructure, or role management are correlated across projects.
What I’m Watching Next: Post-Mortems, Permissioning Changes, and ETH Exit Flows
The market can trade around a loss. It cannot trade around an unknown control plane. The first thing that would change the risk read here is an official post-mortem from Fetch.ai and NuNet that gets specific about key custody and role permissions, not just “an incident occurred.” The threshold that matters is whether either team can point to a concrete, on-chain verifiable remediation, like revoking mint permissions from the deployer address, pausing or patching conversion flows, or rotating privileged roles in a way that can be checked on Ethereum.
The second thing is flow. The cluster reportedly swapped a large share into about 546 ETH. If additional swaps continue beyond that figure, or if ETH begins moving to venues that imply cash-out or obfuscation, the probability of recovery via negotiation drops fast. ETH is not just liquidity. It is also a way to compress a messy set of token proceeds into a single, deep market where slippage is survivable.
The third thing is whether NTX’s circulating supply and holder distribution stabilizes after the reported 408.5 million mint. A supply shock is not over when the first candle prints. It is over when the market can see where the new supply sits, whether it is still moving, and whether liquidity providers are willing to quote again without demanding punitive spreads.
What Coordinated exploit hits Fetch.ai and NuNet Tells Me
I read this as a coordinated privileged-access event until proven otherwise, because the same destination wallet cluster is described as receiving both the drained FET and the freshly minted NTX within minutes. That is not definitive attribution, but it is the kind of linkage that usually only happens when one operator is running the playbook end-to-end, especially when the follow-through is a rapid consolidation into ETH.
The part that decides whether this becomes a contained incident or a longer-duration repricing is not the $2.01 million headline number. It is whether the control surfaces that enabled the actions are still live. If the Fetch.ai converter path can still accept authorizations without lock or burn confirmation, or if NuNet’s deployer still retains mint rights that can be exercised, then the market has to price a repeatable failure mode, not a one-off.
There are two clean scenarios. If teams publish post-mortems that identify a specific authorization-check failure on TokenConversionManagerV3 and a specific compromise path for the NuNet deployer, and then demonstrate on-chain that roles were rotated and permissions were revoked or constrained, this starts to look like a brutal but finite event-risk episode. If disclosures stay vague and remediation is not publicly verifiable, the more likely outcome is that NTX trades as a damaged asset with a permanently higher risk premium, because the float can no longer be treated as a stable input.
The real test is whether permissioning changes are visible on-chain and whether the attacker cluster’s ETH balance stops behaving like an exit ramp. If those two conditions hold, the story downgrades from “existential” to “recoverable,” and without them it stays a supply-integrity problem, not a simple exploit headline.