A Dormant Notional Finance Contract Just Lost $1.7M to an Integer Bug

An unsafe integer downcast let an attacker drain about $1.7M from a dormant Notional Finance escrow contract, and the stolen funds moved to Tornado Cash.

Ramy Morton News

Someone drained about $1.73 million from Notional Finance early Friday, and the contract they hit was one the protocol had already walked away from. The Notional Finance exploit never touched the current lending markets. It reached into a legacy V1 escrow contract that stayed live and funded long after the team stopped maintaining it.

The attacker worked fast. On-chain data flagged by PeckShield, CertiK and QuillAudits shows a setup transaction landing at 11:58 p.m. UTC on Thursday, September 4, with the withdrawal following about three minutes later. Out came 69,257 DAI and roughly 1.66 million USDC, swapped into 689 ETH and pushed straight into Tornado Cash.

Asset takenAmount
DAI~69,257
USDC~1,658,524
Converted to689 ETH
Sent toTornado Cash
Left in escrow~$60,600

How an unsafe downcast fooled the collateral check

The mechanics are the kind auditors have flagged for years. The escrow valued free collateral through an unsafe uint128() downcast. The attacker made two mintfCashPair() calls that built a liability of exactly negative 2^128. Cast down into a smaller integer, that negative value truncated to zero. The collateral check then saw nothing owed and released the money.

No flash loan. No oracle games. Just a number that overflowed the box it was stored in, on code that had been sitting untouched.

Why a wound-down protocol still held deposits

Notional Finance began winding down after the November 2025 Balancer exploit rattled the dependencies it relied on. The active product went quiet. The old V1 contracts did not, and they stayed deployed with user deposits still inside. A dormant protocol is not the same thing as an empty one, and this escrow proved the difference. Around $60,600 in tokens remained after the attacker left. By the time the security firms went public, the team had issued no statement, no loss figure, and no post-mortem. That gap between shutting down and cleaning up keeps repeating. Just days earlier, Silicon Network closed with $9.75 million still sitting onchain, another project gone quiet while its money stayed put.

The second integer bug to drain DeFi in a week

This is not a rare flavor of mistake. Days earlier, the same class of integer bug tore through six Cosmos chains, a flaw that had sat in the shared code since April. Contract math has failed loudly before, from a Sandbox exploit that minted 49 billion tokens down to quieter escrow drains. The pattern holds for a simple reason: code flaws make up roughly 60% of crypto hacks while carrying only a sliver of the losses, so they draw far less scrutiny than a nine-figure bridge drain. The stolen Notional funds then took the usual exit, swapped into ETH and pushed through Tornado Cash where tracing gets hard.

The practical lesson lands on users more than on the team. Money left inside deprecated contracts stays exposed for as long as those contracts remain deployed, and pulling out of wound-down protocols is worth the gas it costs.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.