PublicAML

Notional Finance Exploited for $1.73M in Legacy Contract Attack

Notional Finance's legacy V1 Escrow contract was exploited, resulting in a loss of approximately $1.73 million. The attacker exploited a vulnerability in the contract's valuation mechanism to mint fake claims and withdraw funds.

Notional Finance's legacy V1 Escrow contract was exploited, leading to a significant financial loss. The attacker took advantage of an unsafe uint128 cast in the free-collateral valuation process, which allowed them to create a fabricated liability that truncated to zero. This bypassed the necessary solvency checks, enabling the minting of fake fCash claims and the withdrawal of approximately 69,257.37 DAI and 1,658,524.86 USDC, totaling around $1.73 million.

The stolen funds were subsequently swapped for roughly 689.2 ETH and deposited into Tornado Cash. In response to the incident, the Notional Finance team paused the affected contract to prevent further losses and stated that other user assets were not at risk. They are currently pursuing recovery options for the stolen funds.

The incident occurred on the Ethereum blockchain, which allows for the tracing of transactions. The on-chain record would reflect the addresses involved in the withdrawals and subsequent transactions, providing a trail that could be analyzed for recovery efforts.

Sources

Share:XTelegramLinkedIn
Notional Finance Exploited for $1.73M in Legacy Contract Attack | PublicAML