Notional Finance’s legacy escrow contract was exploited late Thursday UTC in an attack that drained roughly $1.73 million, according to the reported on-chain activity described in the source article. The exploit was tied to an integer overflow issue in an older part of the protocol’s infrastructure rather than its newer contracts.
The reported sequence shows the attacker manufacturing a large negative liability that the contract’s collateral checks effectively treated as zero. That opened the way for withdrawals of 69,257 DAI and 1,658,524 USDC, which were later converted into about 689.2 ETH and routed through Tornado Cash.
How the bug was reportedly used
The source article says the exploit came from an unsafe uint128() downcast inside the legacy escrow contract’s free-collateral valuation logic. By using two mintfCashPair() calls, the attacker allegedly created a liability of -2^128.
Because of the downcast, that value was truncated in a way that made the system read the liability as zero. As a result, the account could appear to have no debt even though it had created a massive negative position, allowing the attacker to withdraw funds from the escrow.
Timeline of the attack
According to the report, the setup transaction took place at 11:58 p.m. UTC on Thursday. The withdrawal followed about three minutes later.
The attacker is also said to have paid a 0.07 ETH tip to a block builder in order to route the trade privately. After the assets were removed, the stolen DAI and USDC were swapped into roughly 689.2 ETH. The ETH was later routed through Tornado Cash, based on the source article’s description of the wallet flow.
What was taken and what remains
The amounts withdrawn from the legacy escrow were reported as 69,257 DAI and 1,658,524 USDC, bringing the total loss to about $1.73 million. The article says the escrow contract now holds only about $60,600 in leftover tokens.
It remains unclear whose funds were ultimately affected. The source article says there was no confirmation at publication on whether the drained cash belonged to users, to Notional’s treasury, or to a third party.
Legacy contract exposure and next steps
The incident appears to center on infrastructure from an older generation of the protocol. The source article says Notional had already wound down its V2 and other older contracts before the exploit, but that V1 contracts were still live and funded.
As of publication, Notional had not issued a public statement or a post-mortem. That leaves several key questions unanswered, including the ownership of the drained assets and whether any further remediation or recovery steps will be announced. The protocol’s token, NOTE, was reported trading near $0.0065, giving it a market value of about $400,700 at the time mentioned in the source article.
Source: beincrypto.com