خبری درباره‌ی هیومنیتی (H)

Fetch.ai and NuNet lose $2 million in a private key compromise

Cryptopolitan ۱۱ دقیقه پیش خلاصه‌ی فارسی · ۴۵۸ کلمه
Fetch.ai and NuNet lose $2 million in a private key compromise

An attacker has taken around $2 million from the infrastructure connected with Fetch.ai and NuNet. Both attacks were linked by security firms to the same attacker wallet. Preliminary analysis of Fetch.ai revealed that the attacker used signing credentials that were compromised to gain access to the infrastructure. While a theft of $2 million may be deemed insignificant in the context of an estimated $2.85 trillion crypto market, what is remarkable about this particular event is that compromised privileged credentials gave the hacker access to critical infrastructure and highlighted how weaknesses in key management can spill across connected systems even if those underlying token contracts are not compromised themselves. The same wallet drained FET and received the NTX mint According to PeckShield, the hacker siphoned off a total of 8.7 million FET, valued at an equivalent of $1.53 million, and unauthorizedly minted 408.5 million NTX worth around $462,730. Blockaid has separately observed about $1.56 million in FET removed from a converter, along with approximately $452,000 in newly minted NTX. This brought the total value of this wallet cluster to about $2.01 million while the attack was ongoing. A follow-up post connected the NTX mint to the same receiving wallet. 🚨Blockaid detected an ongoing exploit on @Fetch_ai on Ethereum. The same exploiter wallet then received a large NTX mint from the @nunet_global deployer account. ~$2.01M so far (~$1.56M FET drained from the converter + ~$452k NTX minted) across the cluster. Attack still… — Blockaid (@blockaid_) September 19, 2026 NuNet is also part of the same broader AI-crypto ecosystem. CoinMarketCap describes it as the second spin-off from SingularityNET. The weak point was privileged authorization According to the presented evidence, it cannot be concluded that a single key was responsible for both projects. Based on Fetch.ai’s preliminary analysis, it is likely that the signing key had been compromised. On the other hand, the analysis thereof that was done on the blockchain implies that the minting key from NuNet may also be compromised. In its analysis, SlowMist reported that the TokenConversionManagerV3 relied on only the ECDSA signature from a single externally owned account to authorize the conversionIn() function at the draining of the FET. The said function did not implement a checkLimits(amount) control mechanism against the transaction, and did not check if burn or lock proofs were available on-chain. The drain of the FET happened as soon as the authorizer key was compromised, since a legitimate signature was all that was required for the draining of the converter’s FET balance. Fetch.ai said it worked with SingularityNET to deactivate affected wallets and contracts. A later update said no Fetch.ai contracts were then at risk and AGIX-to-FET conversions had been paused as a precaution. An on-chain analysis of the exploit is now available on ASI:One.

عنوان اصلی (انگلیسی): Fetch.ai and NuNet lose $2 million in a private key compromise

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به هیومنیتی

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.