Last Wednesday, September 4, the DeFi protocol Notional Finance faced a serious security incident. The hack was made possible by exploiting a critical flaw in an outdated contract from the platform's first version (V1), which still remained active in the project's infrastructure.

The root of the problem lies in incorrect data handling during type conversion. The attacker artificially generated a debt position that, when checking the collateral ratio, appeared as zero due to a bug in the conversion logic. This allowed bypassing collateral control mechanisms and withdrawing liquidity directly from the pool.

Scale of losses and attack route

According to my data, the total damage amounted to approximately 69,000 DAI and 1.66 million USDC, which in equivalent terms exceeds $1.7 million. The attack was technically sophisticated: the hacker acted quickly and deliberately, minimizing the time window for possible intervention by the team or monitoring services.

The withdrawn stablecoins were immediately converted into approximately 689 ETH. The funds then moved to Tornado Cash — a mixer that significantly complicates transaction tracking on the public blockchain. This is standard practice for professional cybercriminals seeking to hide their tracks before further capital movement.

The incident highlights a systemic problem in many DeFi protocols: even after migrating to new versions, old contracts often remain "time bombs." Teams need to conduct a full audit and verification of all historical smart contracts, not just the current ones.

My analysis: This case is yet another reminder that liquidity in DeFi always carries the risk of legacy code. Notional Finance will have to not only compensate for losses but also reconsider its approach to managing the lifecycle of its contracts. Investors, meanwhile, should take into account that even projects with strong reputations can be vulnerable through forgotten versions of their software.