The DeFi sector has once again become an arena for an attack: this time, the Notional Finance protocol fell victim. The incident occurred on September 4, and, as my analysis shows, the root of the problem lies in an outdated smart contract from the first version (V1), which was never fully deactivated after the migration to the new architecture.
The attacker discovered a critical vulnerability related to incorrect data type conversion. As a result, artificially generated debt appeared as zero during collateral verification. This is a classic case of manipulation of validation logic, where the system sees not what is actually there, but what the attacker has fed it. This approach allows bypassing security mechanisms without resorting to brute-force hacking.
According to my data, the hacker managed to withdraw about 69,000 DAI and 1.66 million USDC from the contract. The total damage exceeded $1.7 million, confirming the seriousness of the problem even for protocols considered battle-hardened. Security specialists, including the CertiK team, promptly responded to the incident and recorded traces of the attack.
Notably, the stolen assets did not remain in their original form. The cybercriminal converted them into approximately 689 ETH and routed the funds to Tornado Cash. Using a mixer is a standard step to conceal traces, which complicates transaction tracking and fund recovery. This underscores how important it is for projects not only to close vulnerabilities but also to implement mechanisms for monitoring suspicious activity.
Analyst conclusions
This case is yet another reminder that DeFi protocols must pay special attention to the lifecycle of smart contracts. Leaving old versions active after an upgrade is a ticking time bomb. In my view, Notional Finance should conduct a full audit of all unused contracts and implement automatic "safeguards" that block operations with suspicious parameters. The industry learns from mistakes, but the price of these lessons keeps rising.