Notional Finance Suffers $1.7M Drain After Critical Integer Overflow Exploit

TL;DR:
- Estimated total loss: An attacker drained approximately $1.73 million, distributed across 1,658,524 USDC and 69,257 DAI from the legacy Version 1 escrow contract.
- Technical mechanism: The incident stemmed from an overflow and truncation error (unsafe uint128 downcast) in the free-collateral calculation function.
- Route of funds: The stolen assets were converted into 689.2 ether (ETH) and transferred in batches to the privacy protocol Tornado Cash.
During Fridayโs session, approximately $1.73 million was drained from the lending protocol Notional Finance. Unauthorized transactions were detected in its legacy escrow contract, immediately triggering alarms.
The initial alert emerged in the early hours of Friday after Specterโs monitoring systems detected the event. Security firms including PeckShield and CertiK later confirmed the incident.
We have seen an ~$1.7M exploit on @NotionalFinance.
https://t.co/luKD7RcbVAThe attacker used two mintfCashPair() calls to create a -2^128 liability, which was truncated to 0 by an unsafe uint128() downcast in free-collateral valuation.
โฆ Continue reading the full article at the original source below.



