Notional Finance’s escrow contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses, according to blockchain security monitor Specter and PeckShieldAlert.
On-chain timestamps put the suspected drain in a narrow window just after midnight UTC. The alleged attacker address 0xDaCC…Ce38 first submitted a setup transaction, 0xe158…d60a, at 11:58:47 PM UTC on September 3, 2026, in block 25,900,220. About three minutes later, the drain transaction, 0xc3f…24efa, confirmed at 12:01:35 AM UTC on September 4, 2026, in block 25,900,234.
In a September 4 post on X at 12:59:24 AM UTC, PeckShieldAlert said Specter had reported that the Notional Finance escrow contract “may have been exploited.” The security alert put the reported loss at approximately $1.7 million in DAI and USDC based on prices at the time. According to the alert, the funds were subsequently swapped into approximately 689.2 ETH before being deposited into Tornado Cash. At the time of publication, the available reports did not independently confirm the identity of the party behind the transactions.
$1.7 Million in DAI and USDC Reportedly Moved
The reported incident involves funds held in Notional Finance’s escrow contract at 0x9ab…f683. Etherscan records for the 12:01:35 AM UTC drain show the escrow sent 69,257.38 DAI to 0x265c…C03C and 1,658,524.864122 USDC to 0x4a35…CAfF. Both amounts were forwarded in the same transaction to 0xDaCC…Ce38. Combined, the transfers total about $1.73 million.
The conversion from stablecoins into ETH was followed by transfers into Tornado Cash from a related address, 0xC954…De69. Public explorer records shared with the original PeckShieldAlert show those mixer deposits starting at 12:15:59 AM UTC on September 4, 2026, with successive 100 ETH, 10 ETH, 1 ETH, and 0.1 ETH deposits continuing through at least 12:30:11 AM UTC.
The conversion from stablecoins into ETH was followed by the transfer of the resulting ETH to Tornado Cash, a cryptocurrency mixing service.
Such transfers can make blockchain tracing more difficult because mixing services pool assets from multiple transactions and can obscure the connection between incoming and outgoing funds. The movement of funds to Tornado Cash does not by itself establish who controlled the wallet or whether the entire amount can no longer be recovered.
What Is Not Yet Known
The available security alerts do not establish exactly how the reported exploit occurred. It also remains unclear whether the incident affected other Notional Finance contracts, user funds, or protocol operations beyond the escrow contract identified by Specter.
The distinction is important because a reported abnormal transaction does not necessarily establish the full scope or technical cause of a security incident. PeckShieldAlert used the wording “may have been exploited,” while Specter was identified as the source of the initial report.
Notional Finance had not provided a detailed public explanation of the incident in the sources reviewed for this report. The Crypto Times has reached out to Notional Finance for a comment at 09:22 AM UTC.
Why the Escrow Contract Matters
Escrow contracts can hold assets on behalf of users or protocols until specific conditions are met. A compromise of such a contract can therefore create a direct path for funds to be transferred without the intended authorization.
The reported incident highlights the continuing security risks surrounding DeFi infrastructure, particularly contracts that remain operational or hold assets even when they are not the primary focus of a protocol’s user interface.
What Happens Next
The immediate focus will be on determining whether the reported transaction resulted from a contract vulnerability, compromised credentials or another form of unauthorized access. The movement of the funds into Tornado Cash could make recovery more difficult, although blockchain investigators can continue tracking related addresses and transaction activity.
Until Notional Finance or additional on-chain evidence confirms the incident’s scope and cause, the $1.7 million figure should be treated as a reported loss rather than a final confirmed loss.
For DeFi users, the incident adds to a broader pattern of security concerns surrounding smart contracts and custody mechanisms. PeckShield reported that the crypto industry recorded 50 major hacks in August 2026, resulting in approximately $136.3 million in losses, underscoring the continued scale of security risks across the sector, while Certik pegged the August loss figure at $215 million.
The reported Notional Finance incident remains subject to further investigation, with the next significant development likely to be an official response from the protocol or additional on-chain evidence identifying how the funds were removed.
Also Read: Term Labs Says Attacker Zeroed Governance Delays Before $8.5M Vault Drain
