When AI storytelling is at its hottest, what often goes wrong isn’t the model—it’s the signing key.
On September 19, the same attacker breached Fetch.ai and NuNet one after the other:
1️⃣ Blockaid / PeckShield: TokenConversionManagerV3’s conversionIn was drained of about 8.72 million $FET (about $1.53 million–$1.56 million). Meanwhile, the same wallet cluster also carried out unauthorized minting of about 408.5 million $NTX from the NuNet deployer (about $450k–$460k). In total, approximately $2 million.
2️⃣ SlowMist: The root cause is that conversionIn authorization relies almost entirely on single EOA ECDSA signature, lacking the quota validation mechanism used by conversionOut.
3️⃣ Illicit funds side: PeckShield tracked a large amount of funds converted into about 546 $ETH (about $1.44 million); $NTX had a drop of over 90% within the day—its relative decline is smaller than that of the other case: one involves over-issuance and dilution, the other involves extracting from existing holdings.
What’s worth watching is the structure: it’s not “yet another single-contract vulnerability,” but rather a shared signing/minting trust surface across projects—once that trust is compromised, AI narrative projects can be swept up in the same minute.
Reports from secondary sources say Fetch.ai has issued an initial on-chain incident recap (claiming that the backend signing keys on the SingularityNET bridging side and the NuNet minting keys were misused), and that it has disabled related wallets/contracts with SingularityNET—follow the official final write-up.
One line to filter: as the AI agent narrative keeps echoing, key governance is still the foundation of infrastructure.
Not investment advice.