The DeFi protocol Notional Finance fell victim to a targeted attack on September 4. The attacker exploited a critical flaw in the outdated V1 smart contract, which allowed bypassing collateral verification mechanisms and withdrawing significant liquid funds.
The Essence of the Vulnerability
The issue lay in incorrect data handling during type conversion. As a result, artificially generated debt appeared as zero during collateral audits, giving the hacker the ability to manipulate positions without actual coverage. This is a classic example of how architectural flaws in legacy code become an attack vector even after migration to new protocol versions.
During the exploit, the attacker withdrew approximately 69,000 DAI and 1.66 million USDC. The total damage is estimated at around $1.7 million. According to my security monitoring, the stolen assets were promptly converted into 689 ETH and sent through the Tornado Cash mixer, significantly complicating transaction tracking.
The incident highlights a systemic problem in the DeFi industry: even time-tested protocols are not immune to errors hidden in code considered outdated. Notional Finance has faced security challenges before, but this case demonstrates that auditing and reviewing all generations of contracts must be an ongoing process, not a one-time measure.
My professional opinion: this exploit is yet another reminder that liquidity in DeFi always carries the risk of technical debt. Investors should diversify their positions and closely monitor protocol updates, while teams should prioritize forensic analysis of older code versions. The market has already responded to such incidents by raising requirements for insurance funds, but that is not enough.