On the same address, within a few hours, around 8.7 million FET were transferred out from Fetch.ai, and then 408.5 million NTX were minted on the NuNet side.

Security agencies disclosed that a token conversion contract for Fetch.ai lost about $1.56 million. The attacker used a valid conversion authorization signature, called the conversionIn function of TokenConversionManagerV3, and withdrew the remaining FET from the converter.

After that, the same address was also involved in minting 408.5 million NTX with a NuNet deployment account, worth about $452,000 at the time. PeckShield traced that the related assets were later converted into roughly 546.36 ETH, valued at about $1.44 million.

The easiest thing to misjudge is to attribute both events directly to “the same vulnerability.” What can be confirmed now is only that the same address and two sets of on-chain activities are involved. How the authorization signature was obtained, and why NuNet was able to mint, have not yet been fully technically reconstructed.

Next, focus only on two things: whether Fetch.ai has disclosed the source of the authorization signatures, and whether NuNet has explained how this batch of NTX is handled.

$FET