Notional Finance loses $1.7 million in exploit of legacy escrow contract
An unidentified attacker drained approximately $1.7 million in DAI and USDC from a legacy Version 1 escrow contract belonging to DeFi protocol Notional Finance early on September 4, 2026. According to security researchers, the exploit leveraged an integer overflow vulnerability in a raw uint128 conversion that allowed a massive debt to register as zero. The stolen stablecoins were quickly swapped for 689.2 ETH and routed through the Tornado Cash mixer. Notional Finance has not yet released an official statement.
Notional Finance escrow exploit
▪The attacker tipped block builder Titan 0.07 ETH to route the Notional Finance escrow drain transaction privately.
▪The Notional Finance exploit occurred between 11:58 PM UTC on September 3, 2026, and 12:01 AM UTC on September 4, 2026, moving 69,257 DAI and over 1.65 million USDC from the escrow contract.
▪An escrow contract tied to the decentralized finance protocol Notional Finance was exploited for approximately $1.7 million in cryptocurrency assets.
Integer overflow vulnerability
▪According to an analysis by QuillAudits, Notional Finance used a checked conversion method elsewhere in the same file but failed to use it for the vulnerable uint128 conversion.
▪The Notional Finance exploit was caused by an integer overflow bug where a raw uint128 conversion flattened an enormous debt figure to zero, making the attacker's account read as debt-free.
Tornado Cash fund laundering
▪On-chain records show successive deposits of 100 ETH, 10 ETH, 1 ETH, and 0.1 ETH into Tornado Cash from address 0xC954…De69 starting at 12:15 AM UTC on September 4, 2026.
▪The attacker swapped the stolen DAI and USDC for approximately 689.2 ETH and deposited the funds into the cryptocurrency mixer Tornado Cash to obscure the transaction trail.
Unconfirmed security firm reports
▪As of September 4, 2026, Notional Finance had not released an official statement, loss estimate, or technical explanation regarding the reported exploit.
▪Blockchain security firm PeckShield, citing analysis by Specter, first flagged the suspected exploit of Notional Finance's escrow contract on September 4, 2026.
Dormant legacy contract risks
▪The exploit of Notional Finance's legacy contract parallels a June 2026 incident where an attacker drained legacy Solana liquidity pools at Raydium.
▪The exploited escrow contract belonged to Notional Finance's legacy Version 1 (V1) protocol, which remained funded and active even though the protocol wound down its third version after a November 2025 Balancer exploit.
Story comments
Loading comments…