← Back to News
Notional Finance Drained for $1.7M in Legacy V1 Integer Overflow Bug
DeFiBearish1 min readSeptember 4, 2026BeInCrypto

Notional Finance Drained for $1.7M in Legacy V1 Integer Overflow Bug

Notional Finance suffered a $1.73 million drain after an attacker exploited a math downcasting flaw in its legacy V1 contract to reset liabilities to zero. The attacker converted the siphoned stablecoins into 689 ETH and passed them through Tornado Cash. The incident highlights systemic risk in unmaintained, live smart contracts across older DeFi protocols.

An attacker targeted Notional Finance's dormant V1 escrow contract, draining roughly $1.73 million in stablecoins through a precise integer overflow bug. By executing tailored minting calls, the exploiter created a massive debt position that truncated to zero when passed through an unsafe downcast function in the collateral valuation module.

Once the protocol incorrectly calculated total liabilities as zero, the account was flagged as fully solvent. The attacker then withdrew over 1.65 million USDC and 69,000 DAI without providing actual collateral, quickly converting the proceeds into 689 Ether and routing them through private block builders and Tornado Cash to break on-chain tracking.

This drain underlines the persistent operational hazard of unmonitored smart contracts across the Ethereum landscape. Although Notional had moved away from older versions following previous market stress, the live V1 escrow retained unmonitored capital, proving that sunsetting protocols requires absolute code deprecation rather than passive abandonment.

Share