Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug
Covered by 2 sources · 2 articles
Notional Finance suffered a $1.73 million exploit through an integer overflow vulnerability in its legacy V1 code. The attacker accessed the protocol's escrow system, extracted the funds, and converted them to approximately 689 ETH before routing the proceeds through Tornado Cash to obscure the transaction trail.
Integer overflow bugs occur when calculations exceed a system's maximum value threshold, potentially allowing attackers to manipulate balances or approvals. The fact that the vulnerability existed in deprecated V1 code raises questions about legacy contract maintenance and whether Notional had adequately monitored or deprecated its older systems.
- Legacy V1 code contained an integer overflow flaw that allowed direct access to the escrow, bypassing current protocol safeguards.
- The attacker converted stolen assets to ETH and used privacy routing, suggesting intent to obscure fund movement and complicate recovery or tracing.
- The incident underscores ongoing risks from unmaintained or insufficiently monitored older contract versions running parallel to active protocols.
All coverage
Notional Finance Loses $1.73M in Ethereum (ETH) via Integer Overflow Exploit
Attacker drained $1.73M from Notional Finance's escrow via an integer overflow bug, swapped funds into 689 ETH and routed them through Tornado Cash.
Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug
An attacker drained $1.73 million from Notional Finance's legacy escrow using an integer overflow bug in V1 code.