An attacker drained roughly $1.73 million from Notional Finance’s legacy escrow contract early Friday, exploiting a coding flaw that made an enormous fabricated debt register as zero.
The stolen DAI and USDC became about 689 ether (ETH). The funds then went through Tornado Cash, a service that breaks the trail between wallets. Notional has said nothing publicly.
We have seen an ~$1.7M exploit on @NotionalFinance.
https://t.co/luKD7RcbVAThe attacker used two mintfCashPair() calls to create a -2^128 liability, which was truncated to 0 by an unsafe uint128() downcast in free-collateral valuation.
Stay Vigilant! pic.twitter.com/5T7E0XQfWJ
— CertiK Alert (@CertiKAlert) September 4, 2026
How the Notional Finance Exploit Worked
Notional Finance is a fixed-rate lending protocol on Ethereum. Its first version recorded future cash obligations as tokens called fCash. The system screened borrowers for collateral before letting them add debt.
That screening converted debt into ether terms through a raw uint128 conversion. Two mints summed to exactly two raised to the power of 128. That is the single value the conversion flattens to zero, QuillAudits found.
A checked conversion would have rejected the figure instead of quietly dropping its digits. Notional used the safer method elsewhere in the same file, according to the write-up.
The account then read as debt free. Etherscan records show the setup landed at 11:58 p.m. UTC Thursday and the withdrawal three minutes later.
That second transaction moved 69,257 DAI and 1,658,524 USDC out of the escrow. The attacker also tipped block builder Titan 0.07 ETH to route the trade privately.
Security firm PeckShield relayed a warning from on-chain monitor Specter. The escrow now holds about $60,600 in leftover tokens.
#PeckShieldAlert Specter has reported that the Notional Finance escrow contract may have been exploited, resulting in $1.7M in ethereum:0x6b175474e89094c44da98b954eedeac495271d0f and $USDC lost.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into… pic.twitter.com/Wd5Dc3MWtL— PeckShieldAlert (@PeckShieldAlert) September 4, 2026
Dormant V1 Contracts Still Held Real Money
Notional wound down its third version after the November 2025 Balancer exploit cascaded into its vaults. The V1 contracts stayed live and funded, and nobody swept them.
Independently audited protocols still account for most crypto hack losses, so an old review offered no cover here. June brought a close parallel, when an attacker drained legacy Solana pools at Raydium.
Notional’s NOTE token trades near $0.0065, up 3.5% over 24 hours, on a market value close to $400,700.
Notional had issued no statement, loss figure, or post-mortem at publication. Whether the drained cash belonged to users, the treasury, or a third party remains unconfirmed.
The post Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug appeared first on BeInCrypto.







