Notional Finance Loses $1.7 Million in Coding Exploit
An attacker drained over $1.7 million from a legacy Notional Finance contract by using a clever math trick to bypass collateral checks.
NOTEcoinbeat.news
NOTE/USD live chart
LIVEThe fixed rate lending protocol Notional Finance suffered a major security breach late Thursday. An attacker targeted a legacy escrow contract, successfully draining approximately $1.73 million in DAI and USDC. The stolen assets were quickly converted into 689 ether and funneled through a privacy tool to obscure the movement of funds.
The attack succeeded due to an integer overflow error in the protocol code. By executing two specific transactions, the hacker created a massive liability that was incorrectly calculated as zero by the system. This allowed the attacker to withdraw the funds while the protocol incorrectly registered the account as debt free. The exploiter even paid a fee to a block builder to ensure the transaction remained private.
While Notional Finance moved on to newer versions of its protocol after previous market disruptions, the legacy V1 contracts remained active and contained real capital. This incident highlights the risks associated with leaving older, unmonitored code running on the blockchain. Security experts noted that proper checks in the code would have rejected the faulty input and prevented the theft entirely.
At the time of this report, Notional Finance has not issued an official statement regarding the incident or the status of the affected funds. Traders are watching to see if the project provides a recovery plan or clarification on whether the losses belong to individual users or the protocol treasury. The project token, NOTE, has seen minimal movement despite the news.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!






