On September 4, DeFi protocol Notional Finance got hit by a hack. The attacker found a bug in the old V1 contract: thanks to a data conversion glitch, a fake debt would show up as zero when checking collateral. That loophole let the hacker pull funds without any real risk checks or getting locked out.
How the Exploit Worked
The core issue was bad data type handling in the V1 smart contract. When it came time to check collateral, any debt created by the attacker was counted as zero. That made their balance look solid, so the contract greenlit withdrawals that should’ve been blocked under normal circumstances.
How Much Was Stolen and in What Assets
The attacker drained about 69,000 DAI and 1.66 million USDC—roughly $1.7 million total. After the hack, the stolen tokens were swapped for around 689 ETH.
Where the Funds Went
The ETH was then sent through Tornado Cash. This all went down in the legacy Notional Finance V1 contract, whose vulnerability opened the door for the exploit.
