Market Cap: $2.8003T 2.04%
Volume(24h): $76.1875B 3.63%
  • Market Cap: $2.8003T 2.04%
  • Volume(24h): $76.1875B 3.63%
  • Fear & Greed Index:
  • Market Cap: $2.8003T 2.04%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$81483.540274 USD

1.45%

ethereum
ethereum

$2656.445935 USD

3.16%

tether
tether

$0.999729 USD

0.01%

bnb
bnb

$771.482703 USD

2.73%

xrp
xrp

$1.434506 USD

3.76%

usd-coin
usd-coin

$0.999848 USD

-0.01%

solana
solana

$111.949960 USD

2.99%

tron
tron

$0.342844 USD

0.77%

zcash
zcash

$1496.192048 USD

3.04%

hyperliquid
hyperliquid

$93.842057 USD

2.86%

dogecoin
dogecoin

$0.088966 USD

4.37%

monero
monero

$618.824864 USD

18.41%

chainlink
chainlink

$12.540039 USD

4.61%

cardano
cardano

$0.232168 USD

5.42%

unus-sed-leo
unus-sed-leo

$8.922830 USD

0.41%

Cryptocurrency News Articles

One Attacker, Multiple Tokens: Inside the Fetch.ai Breach - A New York Minute

Sep 20, 2026 at 08:05 pm

The Fetch.ai breach, initially thought to be a $1.5M FET token theft, has ballooned into a multi-token saga involving NTX, AGIX, and WMTX, with total attacker holdings now topping $17M. This incident highlights the critical difference between stolen and newly minted tokens, revealing deeper security implications beyond initial financial losses.

One Attacker, Multiple Tokens: Inside the Fetch.ai Breach - A New York Minute

Folks, gather 'round, because we've got a real head-scratcher brewing in the digital realm. What started as a seemingly contained incident, a mere blip on the blockchain radar for Fetch.ai, has escalated into a sprawling drama of 'One Attacker, Multiple Tokens.' It’s the kind of story that reminds you that in the wild west of crypto, things are rarely as simple as they first appear.

The Plot Thickens: Beyond the Initial FET Fiasco

Initially, the buzz was all about a cool 8.7 million FET tokens, roughly $1.5 million worth, that vanished from Fetch.ai's TokenConversionManagerV3 contract. A bummer, for sure, but seemingly a straightforward theft. However, as the digital detectives at Fetch.ai and their partners at SingularityNET dug deeper, the plot thickened faster than a New York cheesecake.

It turns out the attacker wasn't just content with a single haul. The same digital wallet, a veritable digital briefcase for ill-gotten gains, was later linked to a staggering 409 million NTX tokens, conjured out of thin air via a NuNet deployer account. And just when you thought it couldn't get any wilder, PeckShield chimed in, connecting the same wallet to unauthorized mints of 260 million AGIX and 54 million WMTX. Suddenly, that initial $1.5 million loss felt like pocket change, with the attacker's total haul soaring to nearly $17 million. Talk about an ambitious thief!

The Two Faces of Digital Damage: Stolen vs. Minted

This whole kerfuffle brings to light a crucial distinction that’s often overlooked: the difference between stolen tokens and newly minted tokens. When FET was swiped, existing tokens changed hands, creating a loss but not inflating the overall supply. It's like someone lifting a few bills from your wallet – painful, but the total amount of money in circulation remains the same.

But with NTX, AGIX, and WMTX, we're talking about a different beast entirely. These tokens were reportedly *minted* without authorization, essentially creating new supply out of nowhere. Imagine a counterfeiter suddenly printing a significant chunk of the world's currency – that's the kind of market-shaking impact we're talking about. The reported NTX mint alone was roughly 41% of its stated maximum supply, a move that sent its price plummeting by 70%. It's a stark reminder that in the crypto game, not all losses are created equal.

The Phantom Key: A Valid Signature, a Rogue Act

So, how did this digital heist go down? Fetch.ai's preliminary analysis points to a leaked signing key. This isn't your garden-variety hacking where someone brute-forces their way in. Instead, the attacker presented a *valid* conversion-authorizer signature, making their instructions appear legitimate to the smart contract. It's like a thief having a genuine key to your apartment – the lock works perfectly, but the person using it is a crook.

This highlights a critical vulnerability: even with robust smart contract code, a compromised signing key can undermine the entire system. As SlowMist observed, Fetch.ai's conversion function relied on a single externally owned account signature, potentially lacking the multi-layered security some might expect. It's a sobering thought for anyone relying on digital security: the system is only as strong as its weakest link, and sometimes that link isn't the code itself, but the credentials that authorize its use.

What Now? Deactivation and Lingering Questions

Fetch.ai and SingularityNET have been quick to deactivate affected wallets and contracts, a crucial step to contain the bleeding. But the investigation is far from over. The real question isn't just how much was taken, but how widely these compromised permissions could be used. Until Fetch.ai can definitively show that all affected permissions have been revoked and no more unauthorized tokens can float through the system, the market will remain uneasy.

Because let's be honest, in the unpredictable world of crypto, trust is everything. And when supply figures become questionable and contract permissions are up in the air, that trust can evaporate faster than a free sample on a hot summer day. So, while we sip our coffees and watch the digital drama unfold, remember: this Fetch.ai breach isn't just about a few missing tokens; it's a wake-up call for the entire ecosystem about the intricate dance between code, keys, and market confidence. Stay vigilant, folks, and keep those digital eyes peeled!

Original source:coinmarketcap

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 22, 2026