Notional Finance Escrow Contract Drained of $1.7M as Stolen Funds Move Through Tornado Cash
Key Takeaways
- •An exploit of a Notional Finance escrow contract resulted in losses of approximately $1.73 million, consisting of about 69,242 DAI and 1.658 million USDC.
- •The attacker converted the stolen stablecoins into roughly 689 ETH and deposited the funds into Tornado Cash within hours of the theft.
- •Two addresses linked to the theft have been identified as 0xC954...De69 and 0xDaCC...Ce38, but the technical root cause of the unauthorized withdrawals has not been established.
- •Notional's escrow contract sits at the center of user asset custody, handling deposits, withdrawals, collateral, settlement, and liquidations, which means a compromise of its authorization paths could expose funds across those functions.
- •This is Notional's second major security incident in under a year, following the November 2025 Balancer V2 exploit that forced a full wind-down of Notional V3 and caused losses for leveraged-vault users and ETH lenders.

A Notional Finance escrow contract appears to have been exploited for approximately $1.7 million, with the stolen stablecoins swapped into Ether and deposited into Tornado Cash within hours of the drain.
The affected assets comprised roughly 69,242 DAI and 1.658 million USDC, bringing the combined loss to nearly $1.73 million. Two addresses linked to the theft have been identified as 0xC954...De69 and 0xDaCC...Ce38.
Stablecoins Converted Into 689 ETH
The stolen DAI and USDC were consolidated and exchanged for approximately 689 ETH before the funds were moved into Tornado Cash.
Notional's escrow architecture handles core protocol functions, including deposits, withdrawals, account balances, collateral used for trading, settlement, and liquidations. Because such a contract sits at the center of user asset custody rather than at the protocol's edge, a compromise of its authorization paths can expose funds across those functions at once. Onchain evidence identifies an escrow contract as the source of the drained assets, but a technical root cause has not yet been established, leaving unclear which function or authorization path permitted the withdrawal.
The transaction trail points to unauthorized withdrawals from the Notional escrow contract, though the precise failure mechanism remains undetermined. Crypto Adventure contacted Notional Finance for confirmation of the affected contract, the root cause, and any potential user exposure, but had not received a response by publication time. Until Notional publishes a postmortem, the open questions to watch are whether the flaw was specific to the escrow contract's logic or to a compromised key or operator privilege, and whether any user balances beyond the escrowed collateral were affected.
Stolen ETH Routed to Tornado Cash
After converting the value out of DAI and USDC, the attacker deposited the resulting ETH into Tornado Cash. Mixer deposits sever the direct public link between the originating wallet and subsequent withdrawal addresses, meaning further tracing depends on additional onchain activity or interactions with identifiable services. The speed of the swap-and-mix sequence — completed within hours — matches a now-standard playbook among DeFi attackers, leaving investigators reliant on withdrawal-side clustering and exchange KYC touchpoints for recovery leads.
Similar laundering paths have followed other recent DeFi thefts. The attacker behind the Hinkal exploit converted roughly 797,000 USDC into ETH, then routed 410 ETH through Tornado Cash and another portion into Bitcoin via THORChain.
The movement also comes days after the far larger Tectonic exploit on Cronos, where unauthorized borrowing produced an estimated $74 million loss and attacker-linked ETH has since begun entering Tornado Cash. Cross-chain movement has surfaced in other recent thefts as well: Bitcoin tied to the Coldcard Wave 3 attack began moving for the first time this week, with roughly 4.2 BTC converted into about 135 ETH through THORChain while most of the stolen Bitcoin remained in the original attacker addresses. Taken together, the cluster of incidents underscores that infrastructure-level contracts — escrow, oracle, and lending components alike — have remained the dominant attack surface in recent months.
Notional Previously Wound Down V3 After Balancer Losses
Notional experienced a separate major disruption in November 2025, when the Balancer V2 exploit created bad debt across leveraged vaults on Ethereum and Arbitrum. The damage forced a full wind-down of Notional V3, with affected leveraged-vault users losing their positions and ETH lenders taking haircuts. That incident stemmed from a dependency on a third-party protocol, whereas the current drain originates within Notional's own escrow contract. Notional subsequently launched its Exponent product in January 2026 as a new leveraged-yield architecture, making this the second major security setback for the protocol in under a year.
By early September 4, the addresses tied to the latest theft had converted the drained stablecoins into approximately 689 ETH and deposited the funds into Tornado Cash.
The post Notional Finance Escrow Contract Loses $1.7M as Funds Move to Tornado Cash appeared first on Crypto Adventure.