The decentralized finance (DeFi) protocol Notional Finance has reportedly fallen victim to a security breach targeting its custody contract. According to data provided by blockchain security firm PeckShield on September 4, 2026, the attackers managed to drain approximately 1.7 million US dollars in stablecoins. This incident adds to a growing list of smart contract vulnerabilities within the lending and borrowing sector of the cryptocurrency ecosystem.
Details of the Exploit and Asset Movement
The security breach specifically impacted the protocol's custody mechanisms, allowing the malicious actor to withdraw significant reserves of DAI and USDC. Following the successful extraction of these assets, the attacker immediately initiated a series of transactions to obfuscate the trail of funds.
- The total value stolen is estimated at 1.7 million USD.
- The stolen assets consisted primarily of DAI and USDC stablecoins.
- The attacker converted the stablecoins into 689.2 ETH via decentralized exchanges.
Converting volatile or traceable stablecoins into Ethereum is a common tactic used by exploiters to prepare for the final stage of money laundering through privacy-preserving protocols.
Funds Transferred to Tornado Cash
Following the conversion of the stolen capital into Ether, monitoring tools tracked the movement of the 689.2 ETH directly to Tornado Cash. This decentralized mixing protocol is frequently used by hackers to break the on-chain link between the source of funds and the final destination.
The attacker has converted the stolen funds to 689.2 ETH and deposited them into the Tornado Cash mixing protocol.
This maneuver significantly complicates recovery efforts for the Notional Finance team and law enforcement agencies, as the transaction history becomes anonymized once processed through the mixer. At the time of reporting, Notional Finance has not released a formal post-mortem regarding the specific nature of the smart contract vulnerability that allowed the exploit to occur.
The incident serves as a critical reminder of the inherent risks associated with DeFi custody contracts and the necessity for rigorous, continuous security audits. As the investigation continues, users of the protocol are advised to monitor official communication channels for updates on potential reimbursements or security patches to prevent further asset depletion.
Frequently Asked Questions
Quick answers to the most common questions about this topic.