Incident case file
Sign in to watchNotional Finance V1 Legacy Escrow Uint128 Cast Exploit — $1.73M
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 3, 2026 at 23:58:47 UTC, an attacker set up an exploit against Notional Finance's deprecated V1 escrow contract, which launched in 2021 and had never been fully decommissioned despite being superseded. The contract's collateral check relied on an unsafe downcast to uint128. The attacker deliberately created a debt position so astronomically large that it exceeded the maximum value the field could store, causing the recorded debt to roll over to zero. Executing at 00:01:35 UTC on September 4 (block 25,900,234), the attacker withdrew 69,257.38 DAI and 1,658,524.86 USDC, a total of $1,727,782.24, in under three minutes. The stolen funds were converted to roughly 689.2 ETH and laundered through Tornado Cash. Notional paused the legacy contract; its current V3 deployment was unaffected. On September 7, the same vulnerability class was replicated against a BSC deployment by two additional, apparently unrelated attackers. No funds have been recovered.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)