Skip to main content
AVOID.NET

Audit log

Every state-changing event for Notional Finance (V1 Legacy Escrow): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-13 17:52:24Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,764,476
    sig
    4kHvnKXCkr8a…ZH9v6jzYexplorer ↗
    hash
    6RFMgboyGbhc…Npx6BfsPsha256 → base58
    verifying row…full verify ↗
    canonical bytes (17069 B) ▸
    {"actor":"system:backfill","investigation_id":"38c80912-5b84-4a86-9d63-f6089c32374e","kind":"publish","page_slug":"notional-finance-v1-legacy-escrow","published_at":"2026-09-13T17:52:24.614Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Notional Finance (V1 Legacy Escrow)","sections":[{"content":"Notional Finance is an Ethereum-based decentralized protocol that introduced fixed-rate, fixed-term lending using a tokenized future-cash (fCash) accounting system. The protocol deployed a series of successive contract versions — V1, V2, and V3 — over its history. In November 2025, Notional V3 suffered cascading losses when the Balancer V2 smart contract was exploited, draining collateral from five leveraged vaults across Ethereum mainnet and Arbitrum. The resulting bad debt — 632.8 ETH on mainnet and 80.2 ETH on Arbitrum — led the Notional team to fully wind down V3 operations and migrate cross-currency borrowers to Aave. Despite that shutdown, the much older V1 escrow contract remained deployed on mainnet and continued to hold user-deposited stablecoins. No sweep or formal decommission of the V1 contract was documented prior to the September 2026 exploit.","heading":"Overview and Protocol Background","severity":"high","sources":[{"credibility":1,"name":"Notional Finance — Balancer Hack Response (official blog)","type":"official","url":"https://blog.notional.finance/balancer-hack-response/"},{"credibility":2,"name":"Notional V3 to Cease Operations on Mainnet and Arbitrum — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/notional-v3-to-cease-operations-on-mainnet-and-arbitrum-users-to-be-migrated-to-aave"}]},{"content":"On September 4, 2026, an attacker drained approximately $1.73 million from Notional Finance's V1 legacy escrow contract. According to security firms CertiK and PeckShield, the attacker submitted a setup transaction at 11:58:47 PM UTC on September 3, 2026 (Ethereum block 25,900,220), and the drain transaction confirmed at 12:01:35 AM UTC on September 4, 2026 (block 25,900,234) — an elapsed time of roughly three minutes. The escrow contract address involved is reported as 0x9ab...f683. Two attacker-linked addresses were identified by on-chain researchers: 0xDaCC...Ce38 (the primary execution address) and 0xC954...De69 (used in fund routing). The assets drained consisted of 69,257.38 DAI and 1,658,524.86 USDC, for a combined value of approximately $1.73 million. Approximately $60,600 in residual assets reportedly remained in the escrow contract after the drain.","heading":"The September 2026 V1 Escrow Exploit","severity":"critical","sources":[{"credibility":2,"name":"Notional Finance Suffers $1.7M Drain After Critical Integer Overflow Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"credibility":2,"name":"Notional Finance Escrow Contract Faces Reported $1.7M Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/04/notional-finance-escrow-contract-faces-reported-1-7m-exploit/"},{"credibility":2,"name":"Notional Finance faces suspected $1.7M exploit — crypto.news","type":"news_article","url":"https://crypto.news/notional-finance-faces-suspected-1-7m-exploit/"},{"credibility":2,"name":"$1.73M Notional Finance Hack: Integer Bug Exposed [2026] — Shattered.io","type":"research","url":"https://shattered.io/notional-finance-exploit-integer-truncation-2026/"}]},{"content":"Security analysts — including CertiK, QuillAudits, and SlowMist — attributed the exploit to an unsafe integer type-conversion in the V1 contract's free-collateral valuation logic. The V1 escrow was compiled under Solidity 0.6.x, a version that does not enable checked arithmetic by default, leaving overflow and underflow conditions unprotected. According to CertiK's analysis, the attacker called the mintfCashPair() function twice to construct matched long and short fCash positions that together produced an accounting liability of exactly -2^128. When the free-collateral check in the ExchangeRate._convertToETH function converted that liability's absolute value into ETH terms, it applied an unsafe uint128() downcast. Because 2^128 exceeds the maximum value representable by a uint128 type (2^128 - 1), the cast wrapped the result to zero rather than reverting. The protocol therefore treated a maximally insolvent account as debt-free and permitted an unrestricted withdrawal. QuillAudits noted that safer conversion methods existed elsewhere in the same codebase but were absent in the targeted path. SlowMist published an independent analysis, titled 'The Vanishing Debt,' corroborating this mechanism. The presence of the vulnerability in legacy V1 code while corrected patterns existed in later versions suggests the flaw had existed since the V1 deployment and was never backported or patched.","heading":"Technical Vulnerability: Integer-Overflow in Free-Collateral Valuation","severity":"critical","sources":[{"credibility":2,"name":"Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug — BeinCrypto (citing CertiK)","type":"news_article","url":"https://beincrypto.com/notional-finance-exploit-integer-overflow-bug/"},{"credibility":2,"name":"Notional Finance V1 Exploited for $1.7M Through Integer-Overflow Bug — Blockfence (citing QuillAudits)","type":"research","url":"https://blockfence.io/notional-finance-v1-exploited-for-1-7m-through-integer-overflow-bug/"},{"credibility":2,"name":"The Vanishing Debt — An Analysis of the Notional Finance Hack — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/the-vanishing-debt-an-analysis-of-the-notional-finance-hack-a79b00fa2e47"},{"credibility":2,"name":"$1.73M Notional Finance Hack: Integer Bug Exposed [2026] — Shattered.io","type":"research","url":"https://shattered.io/notional-finance-exploit-integer-truncation-2026/"}]},{"content":"Following the drain, the attacker converted the 69,257 DAI and 1,658,524 USDC into approximately 689.2 ETH via decentralized swaps. The ETH was then routed through Tornado Cash, a mixing protocol that obscures on-chain transaction tracing, in batches of 100, 10, and 1 ETH increments. According to reporting by Crypto Economy and Crypto Times, the Tornado Cash deposits began at approximately 12:15:59 AM UTC on September 4, 2026, and were substantially complete by 12:30 AM UTC — within roughly 30 minutes of the original drain. No recovery or freezing of funds had been reported by any source as of the time of this writing. The use of Tornado Cash is consistent with a deliberate effort to obscure beneficial ownership of the stolen assets.","heading":"Fund Movement and Laundering","severity":"critical","sources":[{"credibility":2,"name":"Notional Finance Escrow Contract Loses $1.7M as Funds Move to Tornado Cash — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/notional-finance-escrow-contract-loses-1-7m-as-funds-move-to-tornado-cash/"},{"credibility":2,"name":"Notional Finance Suffers $1.7M Drain After Critical Integer Overflow Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"credibility":2,"name":"Notional Finance faces suspected $1.7M exploit — crypto.news (citing PeckShield)","type":"news_article","url":"https://crypto.news/notional-finance-faces-suspected-1-7m-exploit/"}]},{"content":"As of the dates covered by available reporting, Notional Finance had not published an official incident report, a post-mortem, or any public confirmation of the exploit. The team did not pause contracts, contact USDC or DAI issuers to freeze on-chain balances, or issue alerts through official social media channels. Multiple outlets — including Crypto Times, Crypto Adventure, and crypto.news — each noted that Notional Finance had not responded to requests for comment at time of publication. The identity of the attacker has not been established. It also remained unclear at the time of reporting whether the drained funds constituted user deposits, protocol-owned treasury reserves, or a combination of both. Separately, Notional Finance had issued a detailed response to the November 2025 Balancer exploit affecting V3, demonstrating the team was capable of public incident disclosure; no comparable disclosure was made for the V1 drain.","heading":"Protocol Response and Absence of Incident Disclosure","severity":"high","sources":[{"credibility":2,"name":"Notional Finance Escrow Contract Faces Reported $1.7M Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/04/notional-finance-escrow-contract-faces-reported-1-7m-exploit/"},{"credibility":2,"name":"Notional Finance Escrow Contract Loses $1.7M as Funds Move to Tornado Cash — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/notional-finance-escrow-contract-loses-1-7m-as-funds-move-to-tornado-cash/"},{"credibility":1,"name":"Notional Finance — Balancer Hack Response (official blog, V3 incident)","type":"official","url":"https://blog.notional.finance/balancer-hack-response/"}]},{"content":"The exploit highlights a documented risk class in DeFi: protocol teams that migrate to newer contract versions while leaving earlier, audited-for-older-standards contracts funded and operational. Notional Finance wound down V3 following the November 2025 Balancer cascade but did not sweep or formally decommission the V1 escrow. Security commentary cited in multiple reports noted that the V1 contract was running Solidity 0.6.x, a compiler version predating default overflow protections, and that the arithmetic flaw in the free-collateral path was a known category of vulnerability. The residual $60,600 balance remaining after the drain confirms the contract held live user or protocol funds at the time of the attack. No evidence of an audit of the V1 contract following the V3 wind-down has been found in available sources.","heading":"Legacy Contract Risk and Decommission Failure","severity":"high","sources":[{"credibility":2,"name":"Notional Finance Suffers $1.7M Drain After Critical Integer Overflow Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"credibility":2,"name":"$1.73M Notional Finance Hack: Integer Bug Exposed [2026] — Shattered.io","type":"research","url":"https://shattered.io/notional-finance-exploit-integer-truncation-2026/"},{"credibility":2,"name":"Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug — BeinCrypto","type":"news_article","url":"https://beincrypto.com/notional-finance-exploit-integer-overflow-bug/"}]},{"content":"The Notional V1 drain occurred in the same week as a reported $320 million hack of the Liquid Network, which multiple sources identified as the largest exploit of that period. The coincidence of two significant DeFi incidents in the same week prompted commentary about systemic fragility in legacy or partially-wound-down protocol infrastructure. No causal connection between the two events has been reported.","heading":"Broader Context: September 2026 DeFi Exploit Environment","severity":"low","sources":[{"credibility":2,"name":"Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug — BeinCrypto","type":"news_article","url":"https://beincrypto.com/notional-finance-exploit-integer-overflow-bug/"}]}],"sources_used":[{"credibility":1,"name":"Notional Finance — Balancer Hack Response (official blog)","type":"official","url":"https://blog.notional.finance/balancer-hack-response/"},{"credibility":2,"name":"Notional Finance Hit by $1.7 Million Exploit From Integer Overflow Bug — BeinCrypto","type":"news_article","url":"https://beincrypto.com/notional-finance-exploit-integer-overflow-bug/"},{"credibility":2,"name":"Notional Finance V1 Exploited for $1.7M Through Integer-Overflow Bug — Blockfence","type":"research","url":"https://blockfence.io/notional-finance-v1-exploited-for-1-7m-through-integer-overflow-bug/"},{"credibility":2,"name":"Notional Finance Escrow Contract Faces Reported $1.7M Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/04/notional-finance-escrow-contract-faces-reported-1-7m-exploit/"},{"credibility":2,"name":"Notional Finance faces suspected $1.7M exploit — crypto.news","type":"news_article","url":"https://crypto.news/notional-finance-faces-suspected-1-7m-exploit/"},{"credibility":2,"name":"Notional Finance Suffers $1.7M Drain After Critical Integer Overflow Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"credibility":2,"name":"Notional Finance Escrow Contract Loses $1.7M as Funds Move to Tornado Cash — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/notional-finance-escrow-contract-loses-1-7m-as-funds-move-to-tornado-cash/"},{"credibility":2,"name":"$1.73M Notional Finance Hack: Integer Bug Exposed [2026] — Shattered.io","type":"research","url":"https://shattered.io/notional-finance-exploit-integer-truncation-2026/"},{"credibility":2,"name":"The Vanishing Debt — An Analysis of the Notional Finance Hack — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/the-vanishing-debt-an-analysis-of-the-notional-finance-hack-a79b00fa2e47"},{"credibility":2,"name":"Notional Finance Loses $1.73M in Ethereum via Integer Overflow Exploit — COINOTAG","type":"news_article","url":"https://en.coinotag.com/notional-finance-1-73m-ethereum-integer-overflow-exploit"},{"credibility":2,"name":"Notional V3 to Cease Operations on Mainnet and Arbitrum — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/notional-v3-to-cease-operations-on-mainnet-and-arbitrum-users-to-be-migrated-to-aave"},{"credibility":2,"name":"Notional Finance custody contract suspected of being attacked — PANews","type":"news_article","url":"https://panews.io/articles/01a069f5-9697-778d-bcf2-2aff4cd45d06"}],"summary":"Notional Finance is an Ethereum-based fixed-rate lending protocol. On September 4, 2026, the protocol's undecommissioned V1 legacy escrow contract was drained of approximately $1.73 million in stablecoins via an integer-overflow exploit in the free-collateral valuation logic. The stolen funds were converted to approximately 689 ETH and laundered through Tornado Cash. No official post-mortem or recovery plan had been published by the Notional Finance team at the time reporting was conducted.","timeline":[{"date":"2025-11-03","event":"Notional V3 suffers cascading losses when Balancer V2 is exploited. Five leveraged vaults are drained across Ethereum mainnet and Arbitrum, accumulating 632.8 ETH and 80.2 ETH in bad debt respectively. Notional announces full V3 wind-down.","source":"Notional Finance official blog — Balancer Hack Response","source_url":"https://blog.notional.finance/balancer-hack-response/"},{"date":"2026-09-03","event":"Attacker address 0xDaCC...Ce38 submits a setup transaction at 11:58:47 PM UTC (Ethereum block 25,900,220), constructing paired fCash positions to engineer a -2^128 liability in the V1 escrow contract.","source":"Crypto Times — Notional Finance Escrow Contract Faces Reported $1.7M Exploit","source_url":"https://www.cryptotimes.io/2026/09/04/notional-finance-escrow-contract-faces-reported-1-7m-exploit/"},{"date":"2026-09-04","event":"Drain transaction confirmed at 12:01:35 AM UTC (block 25,900,234). 69,257.38 DAI and 1,658,524.86 USDC are withdrawn from the V1 escrow contract at 0x9ab...f683.","source":"Crypto Economy — Notional Finance Suffers $1.7M Drain","source_url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"date":"2026-09-04","event":"Stolen stablecoins are swapped into approximately 689.2 ETH and deposited into Tornado Cash in batches beginning at approximately 12:15:59 AM UTC. Laundering is substantially complete by 12:30 AM UTC.","source":"Crypto Economy — Notional Finance Suffers $1.7M Drain","source_url":"https://crypto-economy.com/notional-finance-suffers-1-7m-drain-after-critical-integer-overflow-exploit/"},{"date":"2026-09-04","event":"Specter monitoring systems issue a security alert at 12:59:24 AM UTC. PeckShield and CertiK subsequently confirm the incident publicly.","source":"Crypto Times — Notional Finance Escrow Contract Faces Reported $1.7M Exploit","source_url":"https://www.cryptotimes.io/2026/09/04/notional-finance-escrow-contract-faces-reported-1-7m-exploit/"},{"date":"2026-09-04","event":"Multiple crypto news outlets publish initial reporting. Notional Finance issues no public statement, incident report, or contract pause in response.","source":"crypto.news — Notional Finance faces suspected $1.7M exploit","source_url":"https://crypto.news/notional-finance-faces-suspected-1-7m-exploit/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 76d92133-b3de-450b-8bfa-d7bcc2ac7944
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.