
Notional Finance may have suffered a $1.7 million exploit involving an escrow contract, blockchain investigators reported on Sept. 4. The reported losses include approximately $69,242 in DAI and $1.66 million in USDC.
Summary
- Researchers reported $1.7 million in DAI and USDC leaving an escrow contract linked to Notional.
- The reported losses comprise $69,242 in DAI and $1,658,423 in USDC, according to Specter researchers.
- The suspected attacker exchanged the stablecoins for 689.2 ETH before depositing funds into Tornado Cash.
- PeckShield cited Specter’s findings, while Notional had not publicly confirmed the incident when last checked.
- The exploit’s technical cause, affected users and prospects for recovering assets remain publicly unconfirmed.
Security firm PeckShield cited findings published by blockchain investigation group Specter. Neither report provided a complete technical explanation of how the assets left the contract.
“The Notional Finance escrow contract may have been exploited,” PeckShield said, preserving uncertainty about the incident’s status.
Notional Finance exploit report identifies two addresses
Researchers identified two Ethereum addresses allegedly connected to the movement of the assets. The first address is 0xC954…De69, while the second is 0xDaCC…Ce38.
The addresses were labelled as theft addresses by Specter. That description remains an investigator attribution rather than a finding confirmed by Notional Finance, law enforcement or a court.
The available reports do not identify the precise escrow function involved. They also do not establish whether the event resulted from a smart-contract vulnerability, compromised credentials, faulty permissions or another cause.
Stablecoins were reportedly converted into 689.2 ETH
The suspected attacker reportedly exchanged the DAI and USDC for approximately 689.2 ETH. The Ether was then deposited into Tornado Cash, according to Specter and PeckShield.
Tornado Cash is a set of Ethereum smart contracts designed to reduce the visible connection between deposits and later withdrawals. Its use can complicate blockchain tracing, although depositing assets into the protocol does not independently prove criminal ownership or intent.
The rapid conversion of stablecoins may also reduce opportunities for issuers or centralized platforms to restrict the assets. Both DAI and USDC can be followed publicly before conversion, while subsequent withdrawals from a mixer become harder to associate with the original address.
In related coverage, crypto.news reported that an address tied to the Drift Protocol exploiter moved $44 million through Tornado Cash after remaining inactive for several months.
No technical cause or official response is available
Notional Finance had not published a public incident report or confirmation through its official account when checked. The project had also not disclosed whether contracts were paused, whether remaining assets were secured or whether users needed to take protective action.
The lack of confirmation means the reported $1.7 million loss should remain described as preliminary. It is also unclear whether the affected assets belonged directly to users, the protocol treasury or another party using the escrow contract.
No verified market reaction can be attributed to the report. Without an official assessment, linking token-price movements or changes in deposited value directly to the suspected exploit would be premature.
Previous recoveries depended on rapid containment
DeFi projects commonly respond to suspected exploits by pausing vulnerable contracts, contacting stablecoin issuers and exchanges, tracing connected wallets and offering return agreements. Those options can become more limited after assets enter privacy protocols.
Some projects have still recovered positions or protected unaffected products after an attack. As crypto.news reported, Term Labs recovered its affected fixed-rate positions following an $8.5 million governance exploit, although several products remained closed.
Stake DAO also secured its Ethereum backing and closed a bridge after an unauthorized minting incident, according to related coverage. Those cases involved direct project responses that are not yet available for Notional Finance.
Meanwhile, Notional Finance operates as an Ethereum-based lending protocol focused on fixed-rate, fixed-term borrowing. Its documentation explains that deposited currencies can support borrowing obligations denominated in other currencies.
This makes contract-level accounting and collateral controls central to maintaining solvent user positions. However, researchers have not established whether the reported escrow incident affected Notional’s primary lending system, a separate integration or an older contract.
DAI and USDC have long formed part of Notional’s supported lending markets. The protocol’s technical materials describe currency pairs connecting those stablecoins with their interest-bearing equivalents.
The reported loss therefore involves assets used within Notional’s broader lending architecture, but the available evidence does not show that open loans, collateral balances or fixed-term positions were affected. An official contract identification is needed before the exposure can be measured accurately.
What happens next for Notional Finance
The next confirmed update would likely need to establish which contract was involved, how the transactions were authorized and whether other funds remain exposed. A post-mortem could also clarify the ownership of the lost assets.
Investigators may continue tracking any Ether withdrawn from Tornado Cash. Exchanges and blockchain analytics companies could monitor later transactions, but the reported mixer deposits make attribution and recovery more difficult. Until Notional publishes an assessment, the scale, cause and effect on users remain unresolved.
