The decentralized artificial intelligence ecosystem took a major hit on September 19 and 20, 2026, with a coordinated triple attack that drained roughly $2 million in tokens and exposed deep infrastructure weaknesses across one of crypto’s fastest-growing sectors.
🔑 Key takeaways
- About $2M was stolen via a compromised ECDSA signature key, according to Blockaid and PeckShield.
- Fetch.ai, NuNet, and SingularityNET, all members of the Artificial Superintelligence Alliance, were hit in under 28 minutes.
- NTX collapsed between 65 % and 95 %, while AGIX lost more than 99 % of its value within 24 hours.
- Bitget suspended FET deposits and withdrawals on September 20 as a precaution.
- September 2026 DeFi losses already exceed $333M according to DefiLlama, including $320M tied to the Liquid network.
Attack timeline: a three-stage coordinated strike
The exploit unfolded in a carefully orchestrated sequence. On September 19, 2026 at 20:21 UTC, in Ethereum block 26013913, the attacker exploited Fetch.ai’s TokenConversionManagerV3 contract by using a compromised authorization signature to call the conversionIn function. The operation drained 8.7 million FET tokens, valued at roughly $1.53 million at the time.
Twenty-eight minutes later, at 20:50 UTC, NuNet’s deployer account executed an unauthorized mint of 408.53 million NTX tokens, worth approximately $462,730. The recipient address was identical for both operations: 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE. That reuse of the same wallet allowed on-chain analysts to attribute both attacks to a single threat actor.
A few hours later, SingularityNET’s bridge was compromised. The attacker minted 900 million AGIX, 500 million WMTx from World Mobile Chain, and 500 million CGV from Cogito. According to Protos, the FET sale generated 523 ETH (roughly $1.2 million), while the subsequent sales across the other four tokens brought in 183 ETH, or about $420,000. The 500 million CGV yielded just $30 due to extremely thin liquidity. PeckShield reported the loot was eventually swapped into 546.36 ETH, worth about $1.44 million. Blockaid’s preliminary assessment put combined exposure at roughly $2.01 million while the attack was still live.

Technical root cause: a single-signature bottleneck
SlowMist’s preliminary analysis pointed to a structural flaw in the TokenConversionManagerV3 contract. It relied on a single ECDSA signature (an elliptic-curve digital signature algorithm) from one externally owned account (EOA) to authorize the conversionIn function, with no cap on mintable amounts and no on-chain verification of lock or burn proofs.
« Preliminary analysis points to a compromised signature key rather than a defect in the smart contract code itself. »
Fetch.ai, X post
The incident also revealed lateral compromise across interconnected systems. Bitquery detected preliminary sweeps of ETH and BNB from sixteen wallets, four of which had previously been flagged as belonging to SingularityNET or NuNet employees. Subsequently, $289,575 in USDC was drained from a payroll contract, underscoring how deep the intrusion ran inside the alliance’s operational infrastructure. PeckShield also estimated the attacker’s unrealized profit at nearly $17 million based on the nominal value of minted tokens.
Market reaction: from a dip to total wipeout
The two most-traded affected tokens diverged sharply. FET contained the damage to roughly a 5 % drop in 24 hours, while NTX and AGIX suffered double-digit collapses as massive new supply overwhelmed thin liquidity.
| Token | Pre-attack price | 24h post-attack | Change |
|---|---|---|---|
| FET | ~$0.18 | ~$0.172 | -5 % |
| NTX | ~$0.00133 | $0.00004075 | -65 % to -95 % |
| AGIX | pre-attack level | total collapse | -99 % |
For NTX, the sudden injection of 408.53 million new tokens obliterated liquidity. CoinMarketCap data showed the token printing an all-time low of $0.00004075 on September 20. Cryptonomist reported a drop of more than 70 %, while Cryptopolitan put the decline close to 95 %. AGIX fared no better: the mint of an additional 260 million tokens wiped out roughly $93 million in market capitalization, a loss exceeding 99 % in 24 hours according to Ground.news.
Response measures and the open investigation
Fetch.ai and SingularityNET announced they had disabled compromised wallets and contracts. In an X post on September 20, Fetch.ai said it had worked with SingularityNET to disable the affected access and suspended AGIX-to-FET conversions as a precaution. An on-chain analysis report was published on ASI:One, tracing the attack from the compromised key through to the fund-conversion wallets.
Exchange Bitget announced the suspension of FET deposits and withdrawals from 06:00 UTC+8 on September 20, citing wallet maintenance, while keeping spot trading open. As of 04:36 UTC on September 20, neither Fetch.ai nor NuNet had issued a full public statement on X. BeInCrypto said it had reached out to both projects for comment and received no reply by publication time. Fetch.ai confirmed the investigation remained open, with outstanding questions about the exact circumstances of the credential compromise and how NuNet will handle the unauthorized NTX tokens still tied to the attacker.
Sector context: a brutal September for DeFi security
The incident lands in a particularly painful month for on-chain security. DefiLlama data cited by Cryptonomist puts decentralized finance losses in September 2026 above $333 million across eighteen separate incidents. Before the Fetch.ai and NuNet attacks, seventeen incidents had already caused roughly $331 million in losses, the bulk of which came from a single $320 million exploit tied to the Liquid network.
CoinGecko’s 2026 security report found that infrastructure flaws and supply-chain compromises caused more than $1.8 billion in losses between January 2025 and July 2026. TRM Labs recorded 207 hacks and $972 million in losses in the first half of 2026, noting that infrastructure compromises accounted for roughly 15 % of incidents but nearly 76 % of stolen funds.
Conclusion: a wake-up call for decentralized AI
The triple attack highlights the structural fragility of inter-project crypto alliances, where a single compromised signature key can cascade through an entire ecosystem. PeckShield estimates the attacker’s unrealized gains at close to $17 million at the nominal value of the minted tokens, well above the roughly $2 million actually extracted in ETH.
In the short term, Fetch.ai, NuNet, and SingularityNET will need to restore holder confidence, rotate every compromised privilege, and deploy robust multisignature controls. For DeFi as a whole, September 2026 reinforces TRM Labs’ central finding: infrastructure compromises make up only 15 % of incidents yet concentrate 76 % of stolen funds. The coming days will show whether the ASI alliance can turn this shock into a catalyst for better practices, or whether market distrust sets in for good.
Sources
- Protos — $2M stolen in triple attack on Fetch.ai, NuNet, and SingularityNET
- CryptoTimes — Fetch.ai and NuNet hit by $2M exploit, NTX crashes over 65 %
- Cryptopolitan — Fetch.ai and NuNet hit in attacks linked to a compromised private key
- Ground.news — Fetch.ai suffers $2M loss following security flaw discovery
- Cryptonomist — Fetch.ai NuNet exploit
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

