# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-20 18:50 UTC)
## @GoPlusSecurity (GoPlus Security 🚦) · 09-20 08:22 · ♥20 ↻1 💬6 🚨 GoPlus Security Alert: On Sept 20, @Fetch_ai and @nunet_global contracts were exploited. The attacker drained 8,721,530 ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 from TokenConversionManagerV3 and illicitly minted 408,532,878 $NTX. The attacker walked away with about $2M.
🔍 Root cause A leaked @Fetch_ai conversion-authorizer private key, plus conversionIn() with no hard cap and no counterparty lock/burn proof. The contract ran as designed: it verified a valid ECDSA signature, then flushed every FET in the bridge to the attacker. The @nunet_global Deployer sat in the same compromised ops key cluster, so NTX was minted straight to the max cap.
Attacker 0x1572F2af7696b39c85E3221CDE8EFb640F86c362
Compromised @Fetch_ai conversion authorizer 0x69e5446b07b23de0a76730062c3252152216c85c
Compromised @nunet_global NuNet Deployer 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165
Exploited @Fetch_ai contract (FET) 0xab424A430CC09864fA1277A38193111705ADF3A3
Exploited @nunet_global contract (NTX) 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935
Payout wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE
Attack txs https://t.co/IH0uxnZPYD
https://t.co/x16KaficZq > 引用 @Fetch_ai: We're aware of reports of an exploit involving a https://t.co/CwbPmOj7TU token conversion contract. Our team is investigating and will share an update soon.
Please rely only on official https://t.co/CwbPmOj7TU channels. We will never DM you or ask you to move your tokens. https://x.com/GoPlusSecurity/status/2101587915230871570