One Wallet. Two Protocols. $2M Gone: The Exploit Nobody Connected Until Now
The same attacker drained roughly $2 million across two separate protocols, and it took security firms tracing a single wallet to connect the dots.
Blockaid has publicly linked the exploits targeting Fetch.ai (FET) and NuNet (NTX) to one wallet address, confirming what on-chain analysts had been quietly flagging. The attacks were not random. They were coordinated, and for a period, nobody was talking about the connection.
NuNet Got Destroyed
NuNet absorbed the most visible damage. NTX lost more than 70% of its value and touched an all-time low on September 20. That kind of drawdown doesn't recover quickly, and for holders who weren't watching closely, the move was nearly impossible to exit cleanly. Liquidity dried up fast.
For a token already operating outside the top 200 by market cap, a 70% collapse tied to an active exploit is not a dip. It's a structural event.
Fetch.ai Was Not Spared
FET, which carries significantly more liquidity and trading volume than NTX, was also caught in the same attacker's crosshairs. The exploit involvement adds an uncomfortable layer of scrutiny to a project that has been positioning itself aggressively within the AI and autonomous agent narrative in crypto.
The damage to FET's price was less catastrophic than NTX, but the reputational weight of being linked to the same attacker as a protocol that just hit an all-time low is not nothing.
Why This Matters Beyond the $2M Number
Two million dollars is not the largest exploit in DeFi history, not even close. But the pattern here matters more than the number.
When a single wallet can move across two separate protocols and extract funds without triggering a coordinated response in real time, it signals a gap in cross-protocol threat monitoring. Security firms identified the link after the fact. That timeline is the problem.
Blockaid's attribution is valuable, but attribution after the damage is already done offers little comfort to NTX holders sitting on 70% losses.
What To Watch Now
If you hold FET or NTX, monitor official channels closely for any incident response updates or compensation announcements. Neither protocol has fully detailed the attack vector publicly, which means the exploited surface may still exist in some form.
For DeFi participants broadly, this is a reminder that cross-protocol risk is real and underpriced. One attacker, two targets, one wallet. The next move could hit a third.
Watch whether either team proposes a recovery plan or token buyback. That response, or the absence of one, will define price action in the coming weeks.