Same Wallet, Two Exploits: Fetch.ai and NuNet Lose $2 Million
Fetch.ai and NuNet were both hit by an attacker linked to a single wallet, per Blockaid, with roughly $2 million in assets involved. NuNet's NTX token dropped over 70% and hit an all-time low on September 20, raising harder questions about security in the AI-crypto corner of the market.
I noticed something on September 20 that most people scrolled right past. Fetch.ai and NuNet both got exploited. Roughly $2 million in assets walked out the door. And according to Blockaid, the same wallet was behind both.
That last part is the story.
One Wallet, Two Protocols
Here's what we know. Security researchers tied the Fetch.ai (FET) incident and the NuNet (NTX) incident to a single wallet. That's an attribution, not a confession, so treat it with a grain of salt. Admittedly, chain analysis works by following funding trails, gas payments, bridge hops, and the occasional lazy mistake. It's forensics, not a courtroom.
But it's usually right about the lazy ones.
The damage on NuNet is what jumps out. NTX lost more than 70% of its value and printed an all-time low on September 20. An all-time low matters for a specific reason. There's no support underneath it. Every holder is underwater, and every chart-based trader is staring at blank space where the price floor used to be.
Pair that with thin liquidity on a small-cap token, and the math gets ugly fast. Two million dollars spread across two protocols doesn't sound enormous in a market that moves billions a day. On order books this shallow, it's.
So why two protocols, same attacker, same week? The question worth asking: was this a targeted sweep of one project family, or opportunistic scanning that just happened to land twice?
The Bigger Problem
Both projects sell a story about decentralized compute and machine learning. NuNet sits in the same AI-crypto orbit as SingularityNET. Fetch.ai is part of the Artificial Superintelligence Alliance alongside Ocean Protocol and SingularityNET. The pitch is genuinely compelling. Pool idle hardware, run AI workloads, cut out the cloud middlemen.
None of that protects a private key.
And that's the uncomfortable lesson. Security isn't a narrative problem. It's an engineering problem. The attack surface on these protocols looks a lot like the attack surface on any DeFi app: keys, contracts, bridges, permissions. A great whitepaper doesn't change that, and neither does a strong AI thesis.
For regular holders, the takeaway is blunt. If you're sitting in small-cap AI tokens, you're exposed to liquidity risk that has nothing to do with the technology. A 70% single-day drawdown isn't a market cycle. It's a structural feature of thin order books, and it shows up whenever someone with size decides to leave.
What I'd Watch
I'm not entirely convinced the full picture is public yet. Post-mortems in this space take weeks, and they often arrive polished. Watch for both teams to publish the actual transaction paths, not just a summary. Watch whether other protocols in that same cluster show the same funding trail. And watch NTX, because a token at an all-time low needs either a credible recovery plan or an honest conversation about why anyone should stay.
History suggests the second option is rarer.
To be fair, one attacker hitting two related, thinly traded tokens isn't proof of a coordinated campaign against AI-crypto. It could be a straightforward case of someone finding one weak door, then checking the neighbors. Either way, the pattern is worth tracking, because the market clearly isn't pricing it in.
Time will tell, though.
Related Articles
Explore More
Key Terms Explained
An approval term meaning authentic, bold, or worthy of respect.
A protocol that lets you move tokens between different blockchains.
Not controlled by any single entity, authority, or server.
A network of distributed GPU and CPU providers that offer computing power for AI training, inference, and rendering without relying on centralized cloud providers like AWS or Google Cloud.