Notional V1 Exploit Post-Mortem

Teddy Woodward
Teddy Woodward

On September 3, 2026, Notional V1 was exploited on Ethereum for roughly 1.65M USDC and 69K DAI. The Notional Team paused the affected contract shortly afterward to protect remaining user funds. 

Notional V1 was publicly deprecated in January 2022 following the launch of Notional V2, but withdrawals remained available indefinitely for users who kept assets in the protocol. The exploited funds were residual assets that remained in the legacy V1 Escrow contract.

No exploited funds have been recovered, but the team is engaging with US law enforcement and a leading crypto incident response firm to pursue any possible recovery. No other funds in any Notional product are at risk.

The exploit

The attacker caused an integer overflow error related to the mintfCashPair function. This error enabled him to create a large debt in one account, bypass the collateral check on that account, and then transfer an unbacked collateral position to a second account. 

Following this setup, the attacker borrowed against that unbacked collateral position from the second account and drained the Notional V1 Escrow.

Exploited contract: 0x9abd0b8868546105F6F48298eaDC1D9c82f7f683

Exploit transaction: 0xc3f3e318f7ab2d0daaba59e6ec901d25d1fe8a89aafe2b2b62e3b9aee1a24efa

Find a deep-dive on the details of the exploit on the Quill Audits blog.

The response

Immediately following the exploit, the Notional Team investigated the transaction, confirmed that it was likely an exploit, and moved to pause the contract to protect remaining funds. Shortly after this initial investigation, the team upgraded the Notional V1 contract and paused all operations.

Pause transaction: 0x012fc554b165b3b3ccf3121018ae26503cab50031fa84adea29253b1cd5831d9

The Notional Team alerted security partners shortly thereafter and has since engaged with US law enforcement and Zero Shadow, a crypto incident response firm, to pursue all possible avenues toward recovery.

These recovery efforts are ongoing and the Notional Team will make an additional announcement in the event of any asset recovery or distribution.

Legacy contract management

This exploit highlights a shortcoming in Notional’s policy of legacy contract management. Although Notional V1 had been deprecated for nearly five years, substantial user assets remained. Given the pace of evolution in smart contract security, legacy contracts must be handled with the same ongoing scrutiny as production contracts. Smart contract security is a moving target, not a static one. 

Going forward, any Notional smart contract deprecation plan will include a mechanism to migrate or return all user assets to ensure that no funds are left idle indefinitely in legacy contracts.

Thank you for your patience as we work to resolve this incident.

Teddy Woodward

Co-Founder and CEO