The same black hand's serial attack on Fetch.ai and NuNet.

CN
13 hours ago

Recently, an unidentified attacker launched two attacks on the same "prey" on-chain. First, according to PeckShield/PeckShieldAlert monitoring, the attack targeted the decentralized AI/computing project Fetch.ai, resulting in approximately 8.7 million FET being transferred out, with estimated losses from a single source around 1.53 million USD; immediately following, the same attacker was found to shift focus to the same sector project NuNet, illegally minting about 408.5 million NTX in its contract, valued at around 462,700 USD, with the overall loss scale roughly estimated at about 2 million USD by monitoring organizations. Analysts view the NuNet incident as a typical example of "illegal minting/unlimited minting" vulnerability exploitation, which directly impacts token prices, leading NTX to drop by about 65%. When the same hand repeatedly breached the defenses of Fetch.ai and NuNet in a short time, the market began to confront a sharp question: are the security shortfalls in contract architecture and permission management of the decentralized AI/computing sector being concentratedly exposed.

Same Hand Strikes Twice: FET Transferred Away, NTX Minted Excessively

According to PeckShield/PeckShieldAlert monitoring, the same unidentified attacker first extended its reach toward Fetch.ai: in addresses related to the project, approximately 8.7 million FET were abnormally transferred out, with a valuation at the time of disclosure roughly around 1.53 million USD, directly stripped from the existing control system. Following that, the attacker appeared on the NuNet side, this time not "moving" existing chips, but launching an attack directly on the contract itself—illegally minting about 408.5 million new NTX tokens in the NTX contract, with an estimated value of around 462,700 USD, forcibly tearing a hole in the originally closed token supply. The two incidents were clearly linked by monitoring entities as consecutive actions of the same hacker, forming a clear attack trajectory of "first transferring away FET, then minting excessively NTX."

On the surface, the total amount of the two incidents sums to about 2 million USD, which may not be considered top-tier compared to many people's impressions of "massive hacker cases," but they share a common point: both precisely target the token contract, the underlying control hub, with one manifestation being large abnormal transfers and the other being near "groundless" minting. This combination means that the risk no longer remains at the level of price fluctuation or individual address theft, but directly questions the reliability of contract permissions and issuance rules. After the decentralized AI/computing sector experiences such attacks, even if the loss figures are not the most glaring, once contracts are proven to be continuously breached by the same hand, the market's doubts about the foundational security assumptions of similar projects have been undeniably pushed into the open.

408.5 Million Instantly Appears: How Minting Attacks Tear Apart Consensus

In the case of NuNet, the same attacker employed a more lethal method. Public information shows that instead of transferring existing chips, he directly launched "illegal minting" on the NTX contract, with a single operation minting approximately 408.5 million NTX, valued at about 462,700 USD. This is not cutting a piece from the existing cake, but rather creating a large plate of new cake from thin air, instantly diluting the shares of existing token holders and making the NTX in hand logically "less scarce" on-chain.

The report categorizes such attacks encountered by NuNet as typical "illegal minting/unlimited minting" exploitations, usually related to improper management of minting permissions or key control issues—although the specific technical reasons were not disclosed in this case, the principle is clear: once the "master key" of minting permissions is abused or breached, the token's supply limit becomes untrustworthy, and the scarcity assumptions on which market pricing relies will be rapidly destroyed. The approximate 65% price drop of NTX following the incident is a direct feedback on this consensus rupture—the market is not pricing based on a few hundred thousand dollars' worth of paper losses, but is repricing for the core risk of "whether this token is still worth trusting."

The Shadow of AI Narrative: How Security Incidents Damage Trust

When the same unidentified attacker first transferred about 8.7 million FET from Fetch.ai and then illegally minted about 408.5 million NTX in the NuNet contract, this is no longer an isolated incident, but a precise blow to the narrative of "decentralized AI/computing." The report itself has classified both under this sector, and the characteristics of "same hand, similar timing, targeting the same type of goal" of the serial attack turned the previously abstract security concerns into quantifiable losses and comparable token price curves.

NTX of NuNet fell by about 65% after the incident, reflecting not just the fortune of a single project but the weak side of the entire "AI + crypto" story at the security level. Compared to larger assets, such segmented sector projects inherently have limited liquidity and participant bases, making a single contract exploitation or illegal minting enough to trigger violent price and emotional resonance. Even more troubling, the report indicates that both incidents may reflect common risks in contract architecture or permission management, yet it has yet to confirm whether there is a direct technical connection between the two projects; this uncertainty of "not knowing how the landmine was planted, and not knowing who else it might still be planted on" will hang over the entire decentralized AI/computing sector for a longer time, continuously eroding an already unstable foundation of trust.

Concentration of Permission Risks: Common Lessons Extracted from Two Incidents

NuNet's illegal minting of about 408.5 million NTX laid bare the weight of the "minting key": in token economics, scarcity does not automatically come into effect just because it is written in a white paper, but rather is tied to that string of genuine permissions that can "mint a few more decimals." Once this barrier cannot be held, even a one-time mint will fundamentally tear apart price anchoring and market expectations; this time, the approximate 65% drop in NTX is a direct echo of dwindling expectations being instantly pierced. The report classifies this as a typical "illegal minting/unlimited minting" attack, while public materials have yet to disclose the specific technical causes, further highlighting that minting permissions themselves are the most fragile and sensitive weak points in the system.

Correspondingly, the Fetch.ai incident also occurred at the token contract level, with approximately 8.7 million FET being transferred out. Both attacks precisely revolved around a few high-permission operations: one end was minting, and the other end was asset transfer. Industry experience has repeatedly proven that most minting and abuse-related attacks either stem from contract parameter design or are trapped in key and permission management, but this attack method has not been publicly confirmed, leaving the market with only the brutal consensus that "high permission concentration = attacker priority playbook." For projects positioned as decentralized AI/computing infrastructure, such a single point failure is not just a matter of roughly 2 million USD in losses on paper, but will be magnified into a systemic skepticism towards the entire sector's technical narrative and security commitments.

What to Watch Next: Project Repairs and Next Steps of the Attacker

Next, what truly determines whether this series of attacks "injures the skin or the bone" is not the approximately 8.7 million FET or 408.5 million NTX in numerical terms, but how Fetch.ai and NuNet publicly address the technical root causes, reconstruct the permission system, and whether they provide clear user compensation and governance improvement plans. Current public materials remain at the levels of loss scale, minting numbers, and price declines, without uniform detailed explanations regarding specific repair processes, permission tightening methods, whether to change keys or upgrade contracts, etc., and whether there are signs of recovering assets is still unknown. On the other hand, this event, already locked in as "the same attacker," provides the market with a sustainable tracking clue for on-chain identification: if the same address or similar methods start to spread to more decentralized AI/computing projects, then it is no longer an issue of individual project risk management failure, but a systemic alarm for urgent strengthening of the entire sector's security infrastructure; conversely, if project parties can raise the industry's security threshold post-incident with verifiable technical changes and publicly transparent remediation plans, this incident could be rewritten as an expensive yet effective stress test, the results of which will directly feed back into whether future funds and developers are willing to continue betting on the trust pricing of this sector.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink