$2.25M stolen in coordinated attack on Fetch.ai, NuNet, and SingularityNET

$2.25M stolen in coordinated attack on Fetch.ai, NuNet, and SingularityNET

Attack hits three AI crypto projects over a weekend

A hacker exploited bridges — tools that let tokens move between blockchain networks — connecting three AI-focused cryptocurrency projects: Fetch.ai, NuNet, and SingularityNET. The theft netted around $2.25 million in realized profits. The three projects are all part of the "Artificial Superintelligence Alliance" ecosystem, and two of them were hit almost simultaneously.

The attacker first drained 8.7 million FET tokens from Fetch.ai's bridge and minted 400 million of NuNet's NTX token. Hours later, the SingularityNET bridge was exploited, with 900 million AGIX tokens and 500 million each of World Mobile Chain's WMTx and Cogito's CGV minted out of thin air.

Financial impact of the hack

  • The sale of Fetch.ai's FET tokens generated 523 ETH, roughly $1.2 million — the largest share of the attacker's gains
  • Additional token sales returned 183 ETH, about $420,000, across the remaining four tokens
  • Half a billion CGV tokens returned just $30 due to extremely thin liquidity
  • Security firm Peckshield estimated the attacker's unrealized profits at nearly $17 million at the time of the theft

What security firms found

According to a report from blockchain analytics firm Bitquery, the nominal value of the tokens minted was several times higher than the realized profits at the time of the theft. Blockchain security auditor Peckshield flagged the third incident.

Bitquery also noted a preliminary sweep of ETH and BNB from 16 wallets, four of which it had previously labeled as "SingularityNET or NuNet staff wallets," suggesting widespread penetration of the interconnected companies' infrastructure. Additionally, $289,575 in USDC was later drained from a payroll contract.

What the evidence confirms

The confirmed facts include the amounts stolen and minted, the $2.25 million in realized profits, and the $289,575 USDC drain from a payroll contract. The sale of the genuine FET tokens resulted in a 5% price drop, while the counterfeit tokens caused the prices of minted assets to collapse.

The Bitquery report warned that the majority of signing keys — credentials used to authorize transactions on a blockchain — have not been changed, which could indicate ongoing vulnerability if the attacker still holds access.

Questions still unanswered

The identity of the attacker has not been confirmed. It is also unclear whether the signing keys have been changed since the report was published, or whether the full extent of the penetration into the companies' infrastructure has been assessed.

Why this matters

The attack affected multiple interconnected AI cryptocurrency projects at once, showing how vulnerabilities in one project can spread across an ecosystem. The collapse in token prices after the counterfeit minting affected legitimate holders. The warning about unchanged signing keys suggests the risk may not be fully resolved.

Where this information comes from

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!