T
iTokenly

Notional Finance (V1 escrow) hack — September 2026

Verified — 4 sourcesLast checked September 7, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$1,727,782Price at time of incident
MethodContract logic errorTwo calls to mintfCashPair() created a debt of negative two to the power 128, which an unchecked uint128() downcast in the free-collateral valuation truncated to zero, so the account read as holding no debt at all and could withdraw the escrow
ChainsEthereum
OutcomeUnresolved

What happened

An abandoned Notional Finance escrow contract was emptied of about $1.73m in the small hours of 4 September 2026. The setup transaction landed at 23:58:47 UTC on 3 September in block 25,900,220 and the drain confirmed two minutes and forty-eight seconds later, at 00:01:35 UTC, in block 25,900,234. The contract gave up 69,257.38 DAI and 1,658,524.86 USDC.

The bug is arithmetic. The attacker called mintfCashPair() twice to build a future-cash liability of negative two to the power 128. The free-collateral valuation then cast that number down to a uint128 without checking whether it fit, and the excess digits were simply discarded, leaving a debt that evaluated to zero. An account with no debt may withdraw everything, and it did. CertiK's reading is that an explicit overflow check would have reverted the transaction rather than silently dropping the digits.

The proceeds were converted to 689.2 ETH and pushed through Tornado Cash in a sequence of transfers between 00:15:59 and 00:30:11 UTC, inside half an hour of the drain.

What makes this worth recording is not the size. The contract at 0x9abd...f683 is a legacy deployment: mintfCashPair() belongs to Notional's first version, and Notional had already wound the protocol down elsewhere. On 3 November 2025 the Balancer V2 exploit hit five leveraged vaults across Ethereum and Arbitrum, reducing their collateral to zero and leaving 632.8 ETH of bad debt on mainnet and 80.2 ETH on Arbitrum. Notional concluded it could not return V3 to a working state, wound it down, migrated cross-currency borrowers to Aave and distributed what remained, with mainnet ETH lenders taking a 56.019% haircut on their ETH asset value. The V1 contracts were never part of any of that. They stayed deployed and funded, and nobody swept them. This is the second such case in five days: the Balancer V1 rounding bug of 31 August, recorded elsewhere in this registry, drained another unmaintained deployment whose company no longer exists.

The figure should be read as preliminary. Specter's monitoring flagged the transactions and PeckShield issued its alert using the word may; Notional has published no incident report and confirmed no loss. The DefiLlama dataset lists this entry under the name Notional V2, but the exploited function and the contract's own labelling are V1's.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-09-07
  2. Crypto EconomySecondary · retrieved 2026-09-07
  3. crypto.newsSecondary · retrieved 2026-09-07
  4. Notional Finance, on the V3 wind-down after the Balancer V2 exploitPrimary · retrieved 2026-09-07

Changes to this entry

  • Recorded three days after the incident from on-chain analysis by Specter, relayed by PeckShield and CertiK. Notional Finance has published no incident report and has not confirmed a loss figure, so the amount is a reported loss rather than a final one. The affected contract is identified as a legacy V1 escrow on the strength of the mintfCashPair() function and the contract's own labelling; the DefiLlama dataset calls it V2.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Notional Finance (V1 escrow) hack — September 2026", iTokenly, accessed 2026-09-07, https://itokenly.com/hacks/notional-finance-v1-escrow
https://itokenly.com/hacks/notional-finance-v1-escrow

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.