Notional is a decentralized protocol for borrowing and lending at fixed rates and fixed terms. With variable rate lending, DeFi can only serve a small segment of the crypto lending market, as variable interest rates do not offer the certainty that lenders and borrowers need. Notional solves this by creating a true market for lenders and borrowers, empowering individual investors, business owners, and institutional investors.
According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), two attackers are replicating the recent Notional Finance vulnerability exploit on the BSC chain. Having completed the pre-attack phase, they have created malicious fCash positions using the same vulnerability pattern. The attack has not yet been fully executed; the malicious positions are currently awaiting maturity. Once mature, the attackers may settle the positions and withdraw assets from the protocol. The potentially vulnerable address is 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0. SlowMist strongly recommends that relevant projects take immediate mitigation measures before the positions mature. Previously, the Notional Finance V1 contract was exploited on September 5, resulting in approximately $1.7 million in user funds lost. The affected contracts have been paused.
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.
According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), two attackers are replicating the recent Notional Finance vulnerability exploit on the BSC chain. Having completed the pre-attack phase, they have created malicious fCash positions using the same vulnerability pattern. The attack has not yet been fully executed; the malicious positions are currently awaiting maturity. Once mature, the attackers may settle the positions and withdraw assets from the protocol. The potentially vulnerable address is 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0. SlowMist strongly recommends that relevant projects take immediate mitigation measures before the positions mature. Previously, the Notional Finance V1 contract was exploited on September 5, resulting in approximately $1.7 million in user funds lost. The affected contracts have been paused.
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.