← Radar

Incident case file

Sign in to watch

Notional Finance V1 Legacy Escrow Uint128 Cast Exploit — $1.73M

Incident date Sep 3, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumArithmetic error / unsafe integer downcastCluster: NOTIONAL-ETH-2026-09

Estimated loss

$1.7M

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

Stolen DAI and USDC were swapped into approximately 689.2 ETH and routed through Tornado Cash.

Linked

Escrow contract (legacy V1, deprecated but still holding user deposits): 0x9abd0b8868546105F6F48298eaDC1D9c82f7f683. Attacker addresses not publicly disclosed in full.

Chronology

1 beat
  1. On September 3, 2026 at 23:58:47 UTC, an attacker set up an exploit against Notional Finance's deprecated V1 escrow contract, which launched in 2021 and had never been fully decommissioned despite being superseded. The contract's collateral check relied on an unsafe downcast to uint128. The attacker deliberately created a debt position so astronomically large that it exceeded the maximum value the field could store, causing the recorded debt to roll over to zero. Executing at 00:01:35 UTC on September 4 (block 25,900,234), the attacker withdrew 69,257.38 DAI and 1,658,524.86 USDC, a total of $1,727,782.24, in under three minutes. The stolen funds were converted to roughly 689.2 ETH and laundered through Tornado Cash. Notional paused the legacy contract; its current V3 deployment was unaffected. On September 7, the same vulnerability class was replicated against a BSC deployment by two additional, apparently unrelated attackers. No funds have been recovered.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)