Notional Finance Hit by $1.73M Integer Overflow Exploit
A critical integer overflow exploit drained approximately $1.73 million from the lending protocol Notional Finance.
The incident occurred on September 3-4, 2026, when an attacker exploited a vulnerability in the legacy Version 1 escrow contract.
The technical mechanism behind the exploit was an unsafe uint128 downcast in the free-collateral calculation function, which allowed the attacker to create a -2^128 liability and subsequently drain funds from the system.
The stolen assets were converted into 689.2 ether (ETH) and transferred in batches to the privacy protocol Tornado Cash.