Fetch.ai's token converter drained and NuNet's deployer emptied by one wallet: what the Bithumb notice of 20 September states, what the on-chain trackers report, and what the two projects have not yet said
On 20 September 2026 the Korean exchange Bithumb issued a caution notice on FET, the Fetch.ai token, stating that it had identified a security incident and had suspended deposits and withdrawals. On-chain security trackers, as reported by BeInCrypto the same day, attribute about 1.56 million dollars in FET drained from a Fetch.ai converter contract and about 452,000 dollars in NTX from NuNet's deployer to the same attacker wallet. This article documents the exchange notice, the tracker reports, and the absence, at the time of writing, of any statement from either project.
When a token is drained, the first documents to appear are rarely from the project. They come from exchanges, which have to decide whether to keep accepting deposits, and from security firms, which publish what they see on the chain. The project's own account comes later, sometimes days later. This article is written in that gap. It documents an exchange notice issued on the morning of 20 September 2026 about FET, the token of Fetch.ai, and the figures that on-chain trackers had published by the same morning about two related drains, and it records that at the time of writing neither Fetch.ai nor NuNet had published a statement we could find.
🎧 Audio edition — the full article read aloud, 8 minutes, MP3: fetch-ai-nunet-exploit-bithumb-notice-2026-09-audio-EN.mp3
The exchange notice
Bithumb, a Korean exchange, published a notice on FET dated 20 September 2026 at 15:10:32 Korea Standard Time, which is 08:10 Central European Summer Time. The notice is short and its three operative sentences translate as follows. "We have identified the occurrence of a security incident related to FET." "Due to this, there is concern about increased price volatility for FET." "Currently, FET deposit and withdrawal services are suspended." The notice cites, as its reference for the incident, a post by the security firm Blockaid on X.
An exchange caution notice is a document with a narrow scope. It states that the exchange has seen something, that it has acted on its own platform, and that it warns its own users. It does not describe the incident, attribute it, or quantify it; the reference to Blockaid is the notice's way of pointing to where that description lives.
What the trackers report, as carried by BeInCrypto
BeInCrypto published an account on 20 September 2026 that draws on posts by Blockaid, SlowMist and PeckShield and on aggregate data from DefiLlama. We did not read the original posts on X and we attribute every figure below to BeInCrypto's report of them.
The report states that a single attacker drained approximately 1.56 million dollars in FET from Fetch.ai's converter contract on Ethereum, named as TokenConversionManagerV3, and that the same wallet received approximately 452,000 dollars in NTX tokens from NuNet's deployer address. The combined figure given is approximately 2.01 million dollars. The wallet is identified by its first and last characters as 0x1572 and c362. The stolen funds, according to the report, were converted into 546.36 ETH, valued at approximately 1.44 million dollars at the time.
On the mechanism, the report gives one technical sentence: Fetch.ai's token converter used a single ECDSA signature for authorisation and lacked the amount verification checks that its other functions had. We record this as SlowMist's analysis as relayed by BeInCrypto; we have not read the contract and we do not verify the description. On NuNet, the report describes the NTX movement as a mint from the deployer; it does not explain the link between the two protocols beyond the shared wallet, and the report's own headline poses that link as a question rather than a finding.
The market consequence the report records is that NTX fell by more than seventy percent within twenty-four hours to an all-time low of 0.000328 dollars. The report also notes that Bithumb suspended FET deposits and withdrawals, which is the notice documented above.
What has not been published
At the time of writing, 20 September 2026 in the morning, we searched the Fetch.ai blog and found its most recent post dated 15 January 2026, with nothing on a security incident, a converter contract or a pause. We did not find a NuNet statement. We did not read the posts by Blockaid, SlowMist or PeckShield on X, which are the primary sources for every figure above, because they were not accessible to us in this session. The article is therefore bounded by two documents we read directly, the Bithumb notice and the BeInCrypto report, and everything else is attributed to those two.
This matters for a reader trying to judge the event. An exchange notice proves that an exchange acted. A tracker's figure proves that a tracker saw a transfer of that size. Neither proves the cause, and neither is the project's own account of what failed and what it will do. A converter contract drained by a valid signature, if the description holds, is a different kind of failure from a compromised key or a logic error in a bridge, and the difference is the kind of thing only the project can settle.
Where this fits in our own work
This is the second document this week in which we have read a security incident from the outside. On 18 September a joint alert from seven agencies described credential theft from thousands of cryptocurrency wallets by a state-linked group, which we documented on 19 September; that was a government document with attribution. The present case is the opposite shape: no government, no attribution, and no statement from the victims, only an exchange and three trackers. We record both kinds and do not treat one as the other.
The price and volume data we display under Market Observation are sourced from exchanges and would show an event of this kind only as a move in a series; the series does not explain itself, which is why we write these readings. Readers who want the vocabulary of contracts, signatures and converters explained from the beginning will find it in the Kripto Akadémia, and the way our research desk reads documents of this kind is described on the About page. Our earlier readings in this area are collected under Research.
Sources
Bithumb, notice 1654956, feed.bithumb.com/notice/1654956, 20 September 2026 15:10:32 KST; the three sentences quoted in translation; the notice references x.com/blockaid_/status/2101426221825348095, which we did not read. BeInCrypto, "Fetch.ai and NuNet Exploited for 2 Million Dollars by Same Attacker, NTX Hits All-Time Low", beincrypto.com/fetch-ai-nunet-2-million-exploit, 20 September 2026; the figures, the wallet fragment, the contract name, the mechanism as attributed to SlowMist, and the DefiLlama aggregate. Fetch.ai blog, fetch.ai/blog, read 20 September 2026: most recent post 15 January 2026, no statement on the incident. No NuNet statement was found at the time of writing.
Educational content. Not investment advice. This article describes an exchange notice and third-party security reporting; it contains no instruction to buy, sell or hold any asset.
Continue on DAI
Explore Topics
Written by
DAI Research Desk
Content creator and writer sharing insights and stories.
