Fetch.ai and NuNet Suffer $2M Loss Due to Compromised Private Key Attack
A recent attack on Fetch.ai and NuNet has resulted in a loss of approximately $2 million. The attacker compromised a private key, which was used to gain access to critical infrastructure. According to preliminary analysis, the signing key had been compromised in the case of Fetch.ai.
The same wallet that drained FET also received an unauthorized mint of NTX tokens from NuNet's deployer account. Blockaid detected an ongoing exploit on Fetch.ai on Ethereum, with a total value of around $2.01 million affected during the attack.
Both projects are part of the broader AI-crypto ecosystem, and the weak point was privileged authorization. The TokenConversionManagerV3 in Fetch.ai relied on a single externally owned account's ECDSA signature to authorize conversions without implementing proper checks or control mechanisms.