The DeFi protocol Notional Finance fell victim to a hacker attack on September 4, and this incident once again highlights how dangerous the legacy of outdated smart contracts can be. The attacker found a vulnerability in the old V1 version of the platform's contract, which was no longer actively used but remained part of the ecosystem. The problem lay in incorrect data handling during type conversion: artificially generated debt, which should have been accounted for when checking collateral, was displayed as zero due to an error in the conversion logic. This allowed the attacker to bypass security mechanisms and withdraw funds.

According to specialized auditing services, including CertiK, the total amount of damage was approximately 69,000 DAI and 1.66 million USDC. In total, this amounts to about $1.7 million — a significant sum, but not catastrophic for a project with a multi-million TVL. However, the attack vector itself is telling: the hacker did not break new code but exploited a "dead zone" — a contract that was likely considered obsolete and therefore lacked proper monitoring.

After withdrawing the funds, the cybercriminals converted the stolen stablecoins into approximately 689 ETH. This is standard practice for obscuring traces, but the key step was sending the funds to Tornado Cash — a mixer that remains the primary tool for laundering cryptocurrencies in such attacks. Using this service complicates asset tracking but does not make it impossible: modern blockchain analysis methods allow for partial deanonymization of such transactions.

For Notional Finance, this is not the first blow to its reputation, and now the team will have to not only compensate for the losses but also reconsider its approach to managing old versions of contracts. Ideally, unused protocols should be fully frozen or destroyed to eliminate any possibility of exploitation.

My comment: This case is yet another reminder that in DeFi, "abandoned" code does not disappear but becomes a ticking time bomb. Projects should implement automated monitoring systems for all historical contracts, even if they are inactive. One outdated smart contract can negate years of work and user trust.