Fetch.ai Hack Explained: What Happened to FET, AGIX and NTX?
2026-09-21
Reports of a Fetch.ai hack have raised questions about three tokens: FET, AGIX and NTX. The incident involved token conversion and bridge infrastructure, rather than a reported breach of the FET token contract.
A security researcher reported that roughly 8.7 million FET was taken from a converter and that hundreds of millions of NTX were minted without authorization.
Fetch.ai says the attack also involved SingularityNET’s bridge infrastructure and has paused AGIX-to-FET conversions. Here is the reported sequence, what remains under investigation and what holders need to know.
Key Takeaways
- The ASI Alliance says an unauthorized party withdrew approximately $1.56 million in FET from a token converter, while security researchers estimated the transfer at roughly 8.7 million FET.
- Fetch.ai says the exploit targeted SingularityNET bridge infrastructure, and AGIX-to-FET conversions and an Ethereum-side bridge contract were paused as precautions.
- The ASI Alliance says FET held in personal wallets or on exchanges was not affected, but holders should check official updates before attempting a conversion or bridge transfer.
What Happened in the Fetch.ai Exploit?

(image source: x.com/axisrobotics)
The incident was reported on September 19, 2026. In its September 20 statement, the Artificial Superintelligence Alliance said an unauthorized party had withdrawn approximately $1.56 million in FET from a converter used in its token migration infrastructure.
The Alliance said its team was investigating with security partners and would publish a fuller account after the investigation.
Blockchain security firm PeckShield reported that the same exploiter was linked to activity involving Fetch.ai and NuNet. Its initial assessment put the FET transfer at about 8.7 million FET, worth approximately $1.53 million at the time.
PeckShield also reported an unauthorized mint of about 408.5 million NTX, then valued at roughly $462,730. These dollar amounts are estimates from the time of the alert, not fixed values or a final accounting of losses.
Fetch.ai later clarified the apparent technical scope. According to the project, the attack targeted SingularityNET contracts, primarily the bridge between Ethereum and Cardano, and the unauthorized mint occurred through that route.
Fetch.ai said its own contracts were unaffected and FET continued to operate normally. That distinction matters: the reported loss came from conversion infrastructure, and does not establish that every FET holder’s wallet or the FET token contract was compromised.
Read also: AI Crypto Sector Surge: FET, NEAR, and RENDER Rally
How Did FET, AGIX and NTX Become Involved?
The three tokens play different roles in the reports. FET is the token used by the Artificial Superintelligence Alliance. AGIX is associated with SingularityNET and its migration to FET. NTX is NuNet’s token, used in its decentralized compute network.
The Alliance described the incident as affecting FET migration and bridge architecture, along with other tokens using that infrastructure. Fetch.ai identified the SingularityNET bridge as the main target and said AGIX-to-FET conversions had been paused.
This connects AGIX to the affected conversion route, but the public statements reviewed here do not establish a final, verified quantity of unauthorized AGIX or show that ordinary AGIX holder wallets were drained.
For NTX, PeckShield’s finding is more specific: it reported approximately 408.5 million NTX minted without authorization.
NuNet operates across Ethereum and Cardano, so a reader should distinguish a reported mint connected to cross-chain infrastructure from a claim that every NTX balance on both networks changed. The full effect on valid supply and any subsequent remediation requires an official accounting.
Timeline of the Reported Exploit and Response

(image source: x.com/axisrobotics)
- September 19: Fetch.ai says the exploit occurred. The project has not yet published a final account of its cause and full impact.
- September 20, initial security alert: PeckShield linked the activity to one exploiter and reported the roughly 8.7 million FET transfer and 408.5 million NTX mint. It said some of the assets had been exchanged for approximately 546 ETH by the time of its alert. That figure describes observed activity at that point, not the final amount recovered or lost.
- September 20, Alliance statement: The ASI Alliance confirmed an unauthorized FET withdrawal from the converter, estimated its value at approximately $1.56 million, and said treasury and exchange wallets were unaffected.
- September 20, containment updates: Fetch.ai said it and SingularityNET had deactivated affected wallets and a contract. Fetch.ai subsequently said the exploit was contained, while its investigation continued.
- September 20, service restrictions: Fetch.ai said AGIX-to-FET conversions were paused until further notice. It also paused its Ethereum-side bridge contract as a precaution, while saying it had found no indication of a vulnerability in that particular contract.
Fetch.ai referred to a compromised signing key in a preliminary on-chain analysis, but expressly said that analysis was not final. The precise failure, the complete set of affected transactions and the final loss calculation should therefore remain open questions until the investigation is published.
What Does the Pause Mean for Holders?
A conversion pause prevents users from completing the affected AGIX-to-FET migration through the paused service. A bridge pause can likewise delay transfers through the affected route. Neither announcement, by itself, means tokens already sitting in an ordinary wallet have disappeared.
The distinction between holders is important:
- FET holders: The ASI Alliance said FET held in a personal wallet or on an exchange was not impacted and that holders did not need to take action in response to its announcement.
- AGIX holders planning to convert: The AGIX-to-FET route was paused in Fetch.ai’s September 20 update. Check its official status before connecting a wallet or trying again.
- NTX holders: The reported unauthorized mint raises questions about supply, market confidence and how affected tokens will be handled. Wait for NuNet’s verified accounting rather than assuming an early estimate describes the final impact.
- Users with an in-progress transfer: Review the transaction on the relevant blockchain explorer and use the project’s official support channels if its status is unclear. Do not send another transaction solely because a website or private message urges you to act quickly.
These are separate exposures. A holder may face a temporary inability to use a conversion route, market volatility or uncertainty about token supply without having suffered a direct withdrawal from their wallet.
Read also: What Is the Superintelligence Alliance Token?
Did the Incident Affect the FET Price?
The incident created a reason for traders to reassess bridge security and possible selling pressure, but the available evidence does not isolate its effect on the FET price. Crypto prices also respond to broader market conditions, and a price chart alone cannot prove what caused a move.
PeckShield reported that NTX had fallen about 65% at the time of its September 20 alert. That was a time-specific observation, not a current price or a prediction. Readers assessing either token should check a live market source, the time of its last update and the project’s latest incident statements.
What Should Users Verify Next?
The most useful next update will be a detailed incident report that reconciles the token movements with the affected contracts and explains the remediation. Before interacting with a migration service or a message about the exploit, check:
- Official service status: Has the project explicitly announced that conversions or bridging have resumed?
- Confirmed token accounting: How much FET left the converter, what unauthorized tokens were minted and what happened to them afterward?
- Remediation: Have affected permissions, wallets and contracts been secured, and has any independent review been completed?
- Authentic links: Does a conversion page come from the project’s verified channels? Fetch.ai has warned that it will not send holders direct messages asking them to move tokens.
An incident can attract fake recovery sites and urgent wallet-connection requests. Holders should not sign a transaction, reveal a recovery phrase or move assets based on an unsolicited message. Readers can check the live FET price chart rather than rely on a snapshot from the time of the incident.
Conclusion
The confirmed project response centers on a FET withdrawal from conversion infrastructure and an exploit involving SingularityNET bridge architecture. PeckShield additionally reported a large unauthorized NTX mint.
Fetch.ai says its contracts were unaffected, while the ASI Alliance says FET in personal wallets and exchange wallets was not impacted. AGIX-to-FET conversions and an Ethereum-side bridge contract were paused in Fetch.ai’s latest cited update.
The investigation has not yet produced a final public accounting of all affected tokens and losses. Holders can use the official project channels to verify service status and the eventual incident report before attempting a conversion or bridge transfer.
Readers following the incident can explore available markets on Bitrue Exchange and find further crypto guides on the Bitrue Blog. Check each token’s current availability and the project’s official security updates independently.
FAQ
Was the FET token contract hacked?
Fetch.ai says its contracts were not affected and that FET continued to operate normally. The reported FET withdrawal involved a token converter connected to migration infrastructure. A final incident report is still needed to explain the full technical cause.
Were FET holders’ personal wallets drained?
The ASI Alliance said FET held in personal wallets or on exchanges was not impacted by the reported converter withdrawal. That statement addresses this incident; users should still protect their wallets from unrelated phishing attempts.
Was AGIX minted in the exploit?
Fetch.ai says an unauthorized mint occurred through infrastructure involving the SingularityNET bridge, and it paused AGIX-to-FET conversions. Its cited update does not provide a final verified amount of unauthorized AGIX, so claims about a specific quantity should be treated cautiously.
What happened to NTX?
PeckShield reported that an attacker minted approximately 408.5 million NTX without authorization. The figure was an early security assessment, and holders should look for an official explanation of how the tokens will be accounted for or addressed.
Can I convert AGIX to FET now?
Fetch.ai said AGIX-to-FET conversions were paused until further notice in its September 20 update. Check a newer official announcement before attempting a conversion, and avoid links sent through unsolicited messages.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
Disclaimer: The content of this article does not constitute financial or investment advice.



