The DeFi protocol Notional Finance fell victim to a targeted attack, resulting in the attacker withdrawing funds totaling approximately $1.7 million. The incident occurred on September 4, and its cause was a critical flaw in the outdated smart contract of the platform's first version (V1).

The essence of the vulnerability lay in incorrect data handling during type conversion. As a result, artificially generated debt appeared as zero in the system during collateral checks. This bug allowed the hacker to manipulate the protocol's logic and bypass asset verification mechanisms, ultimately leading to the unauthorized withdrawal of liquidity.

According to my data, confirmed by independent security experts, including the CertiK team, the stolen funds included approximately 69,000 DAI and 1.66 million USDC. This is a classic example of how even long-running protocols can carry hidden risks if their codebase is not subjected to regular audits and updates.

After the attack was completed, the attacker converted the stolen stablecoins into approximately 689 ETH. The assets were then moved through the Tornado Cash mixer—a standard tool for concealing transaction traces in such schemes. This makes the recovery of funds unlikely and the hacker's identity extremely difficult to determine.

This case highlights a systemic problem in DeFi: many projects continue to use legacy contracts that do not meet modern security standards. In my practice, this is not the first incident where an old version of a smart contract becomes the weak link, negating all efforts to protect newer versions. Notional Finance should have deactivated the V1 contracts in advance or carried out a forced upgrade of them.

For investors, this is another reminder of the importance of diversifying risks and carefully studying the architecture of the protocols they invest in, especially if the platform operates with multiple generations of smart contracts simultaneously.