One Wallet Linked $1.55M FetchAI Theft to 408.5M NTX Mint
Athena's forensic report traced a dormant NuNet minter key to the same wallet that drained Fetch.ai's bridge, exposing a credential gap that persisted for five hours.
Yuna · Sep 22, 2026 · 1 min
On-chain forensics from Athena link a $1.55 million FetchAI theft to a 408.5 million NTX mint, showing both attacks flowed from a single compromised credential set. The link rests on timing and wallet identity: a NuNet minter key, dormant since March 2023, executed a mint 29 minutes after the FET drain and sent the tokens to the identical receiving address [source:fact:F2] [source:article].
The decisive detail is the wallet’s pre-emptive movement. At 19:36 UTC, 45 minutes before the main FET withdrawal, the NuNet minter sent 0.3667 ETH to the eventual receiving wallet, while another linked account moved 24.3 million NTX into the same place [source:fact:F4] [source:article]. This sequence suggests the operation was already underway before the bridge was emptied, contradicting any narrative of a single, isolated exploit of the conversion contract.
The mechanism allowed the attack to bypass safety limits. The contract’s 1 million FET cap applied only to tokens moving out of Ethereum, not to the conversionIn function, allowing the attacker to release the entire balance in one transaction [source:article]. Fetch.ai suspended the AGIX-to-FET service and halted its Ethereum-side bridge operations as a preventive measure, noting that the damaged infrastructure originated from SingularityNET [source:article].
The exposure remained critical in the hours following the breach. The NTX mint equaled roughly 42% of NuNet’s documented supply, while the FET loss totaled $1.55 million [source:fact:F3] [source:fact:F1]. Investigators noted the compromised bridge authorizer and NuNet minter credentials "had not yet been rotated" during the initial tracking window, roughly five hours post-attack [source:article]. Until those keys are revoked, refilling the contract risks further signed withdrawals, and NuNet remains vulnerable to additional minting by the affected wallet [source:article].
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.