Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain

Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain

Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

The last 24 hours saw one confirmed smart-contract exploit on Ethereum alongside fund movements from prior incidents and a new malware campaign targeting mobile wallets. Security monitors flagged the Notional event early Friday; older exploits continued to surface residual activity. No major bridge or oracle incidents were confirmed in the window.

Notional Finance — ~$1.7M Escrow Drain (Confirmed)

Notional Finance’s legacy V1/V2 escrow contracts on Ethereum were drained of approximately $1.7 million in DAI and USDC. The attack exploited an integer-handling flaw in free-collateral valuation.

Protocol / chain / asset: Notional Finance (fixed-rate lending), Ethereum, DAI + USDC from escrow.

Loss: ~$1.7M–$1.73M (69k DAI + 1.66M USDC). Funds swapped to ~689 ETH and deposited into Tornado Cash. No recovery reported; live loss remains ~$1.7M.

Attack type: Smart-contract logic / integer truncation (unsafe uint128 downcast).

Technical details: Attacker used two mintfCashPair() calls via ERC1155Trade.safeTransferFrom → Portfolios.mintfCashPair(). First call with amount 1 succeeded due to rounding that treated a -1 liability as 0 in DAI→ETH conversion. Second with 2^256-1 produced a -2^128 liability in int256 that truncated to 0 under uint128(balance.abs()) inside free-collateral checks. This allowed a massively insolvent position to appear solvent. Settled matured assets then permitted withdrawal of real tokens from escrow. Attacker EOA was fresh, funded via NEAR Intents; exploit used private order flow (Titan builder tip).

Key transactions / addresses:

Status: Confirmed by CertiK, GoPlus, PeckShield (citing Specter). Protocol has not issued a public statement at time of writing. Funds mixed.

Sources: https://x.com/CertiKAlert/status/2095797115788443893, https://x.com/GoPlusSecurity/status/2095805157732675843, https://x.com/PeckShieldAlert/status/2095678080241303915

UPDATE: Tectonic Exploiter Funds to Tornado Cash

Address linked to the late-August Tectonic / Cronos incident deposited ~2,658.9 ETH (~$6.65M) into Tornado Cash. This follows the earlier ~$120M bad-debt creation (largely rolled back on Cronos) with ~$6.65M bridged out previously. Confirmed movement; no new protocol drain.

Sources: https://x.com/CertiKAlert/status/2095689606805233726, https://x.com/PeckShieldAlert/status/2095657464251506901

Also noted

  • DarkSword iOS Safari campaign (SlowMist): Ongoing n-day reuse of the six-CVE DarkSword chain targeting iPhone Safari (iOS 18.4–18.6.2). Decoy free-VPS pages deliver WebKit RCE + sandbox escapes, then implant plugins that harvest Keychain, app containers, and keyboard input from imToken / TokenPocket / TronLink. Confirmed IOCs published; update to patched iOS recommended. Not a smart-contract exploit. https://x.com/SlowMist_Team/status/2095829317544824953
  • Balancer DAO on-chain notice to a wallet linked to the 31 Aug V1 exploit, offering cooperation/bounty before 8 Sep. Older incident. https://x.com/DefimonAlerts/status/2095551771192025522
  • Reported (not new exploit): $2.1M FXRP phishing via ChatGPT-supplied link (incident dated June 2026, publicized 3–4 Sep). Approval phishing; funds partially mixed.

Sources & references

Editor’s note: The Notional case again highlights boundary-condition arithmetic in legacy lending code. Always verify free-collateral and casting paths independently of audits.