{"id":6762,"date":"2026-09-04T13:11:59","date_gmt":"2026-09-04T13:11:59","guid":{"rendered":"https:\/\/areeblog.com\/?p=6762"},"modified":"2026-09-04T13:11:59","modified_gmt":"2026-09-04T13:11:59","slug":"notional-finance-loses-1-7m-in-integer-overflow-attack","status":"publish","type":"post","link":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/","title":{"rendered":"Notional Finance Loses $1.7M in Integer Overflow Attack"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"6763\" data-permalink=\"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/notional-finance-1568x882\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png\" data-orig-size=\"1568,882\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}\" data-image-title=\"notional-finance-1568&amp;#215;882\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-1024x576.png\" class=\"aligncenter size-full wp-image-6763\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png\" alt=\"Notional Finance Loses $1.7M in Integer Overflow Attack\" width=\"1568\" height=\"882\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png 1568w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-300x169.png 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-1024x576.png 1024w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-768x432.png 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-1536x864.png 1536w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1-860x484.png 860w\" sizes=\"auto, (max-width: 1568px) 100vw, 1568px\" \/><\/p>\n<p>Notional Finance appears to have suffered a $1.73 million <a href=\"https:\/\/areeblog.com\/flow-evm-lending-protocol-more-markets-hit-by-9-3-million-exploit\/\">exploit<\/a> involving a legacy V1 Escrow contract, after an attacker abused an integer conversion flaw to bypass collateral checks and withdraw stablecoins held by the protocol.<\/p>\n<p>On-chain investigators and security firms reported that the attacker extracted about 69,257.37 DAI and 1,658,524.86 USDC from the Escrow contract. The assets were later converted into roughly 689 ETH and moved through Tornado Cash.<\/p>\n<p>The affected contract is the <a href=\"https:\/\/etherscan.io\/address\/0x9abd0b8868546105f6f48298eadc1d9c82f7f683\">Notional Finance Escrow contract on Ethereum<\/a>, identified by the address <code>0x9abd0b8868546105F6F48298eaDC1D9c82f7f683<\/code>. Its implementation is listed as <code>0x8a134e651432A902041643668940C9a9cD270633<\/code>.<\/p>\n<p>According to <a href=\"https:\/\/www.quillaudits.com\/blog\/hack-analysis\/notional-finance-integer-overflow-exploit\">QuillAudits&#8217; technical analysis<\/a>, the attack did not depend on a flash loan, price manipulation or a compromised private key.<\/p>\n<p>Instead, the attacker exploited a flaw in the way Notional&#8217;s V1 contracts handled large signed integer values during collateral calculations.<\/p>\n<p>The vulnerable path involved the <code>mintfCashPair()<\/code> function and the collateral calculation used to determine whether an account had enough free collateral.<\/p>\n<p>The attacker created liabilities designed to reach exactly <code>2<sup>128<\/sup><\/code>. This was done using a liability of 1 together with another liability of <code>2<sup>128<\/sup> - 1<\/code>.<\/p>\n<p>The combined value was therefore <code>2<sup>128<\/sup><\/code>, or 340,282,366,920,938,463,463,374,607,431,768,211,456.<\/p>\n<p>The critical issue was an unchecked conversion from a larger integer type to <code>uint128<\/code>. In the affected calculation, the enormous value could be truncated when converted to 128 bits.<\/p>\n<p>As a result, <code>2<sup>128<\/sup><\/code> became zero after the narrowing conversion.<\/p>\n<p>That caused the attacker&#8217;s enormous liability to appear as zero in the relevant ETH-denominated collateral calculation, allowing the free-collateral check to pass.<\/p>\n<p>The exploit also took advantage of how <code>mintfCashPair()<\/code> handled paired payer and receiver positions. The payer&#8217;s collateral was checked, while the receiver side was not subjected to the same validation described in the technical analysis.<\/p>\n<p>This allowed the attacker to create receiver claims corresponding to assets held by the Escrow while avoiding the intended solvency restrictions.<\/p>\n<p>QuillAudits&#8217; reconstruction identified values corresponding to approximately 69,257.37 DAI and 1.66 million USDC. The attacker subsequently called <code>settleMaturedAssets()<\/code>, turning the fabricated claims into recognized cash balances.<\/p>\n<p>The attacker then used <code>Escrow.withdraw()<\/code> to remove the underlying assets.<\/p>\n<p>The core transactions happened within minutes. Crypto Times reported that the setup transaction was confirmed at about 11:58:47 p.m. UTC on September 3, 2026, while the drain transaction was confirmed at about 12:01:35 a.m. UTC on September 4.<\/p>\n<p>The drain was recorded in Ethereum block 25,900,234, according to the report.<\/p>\n<p>The setup transaction was <a href=\"https:\/\/etherscan.io\/tx\/0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a\"><code>0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a<\/code><\/a>, while the reported drain transaction was <a href=\"https:\/\/etherscan.io\/tx\/0xc3f3e318f7ab2d0daaba59e6ec901d25d1fe8a89aafe2b2b62e3b9aee1a24efa\"><code>0xc3f3e318f7ab2d0daaba59e6ec901d25d1fe8a89aafe2b2b62e3b9aee1a24efa<\/code><\/a>.<\/p>\n<p>After withdrawing the stablecoins, the attacker consolidated the funds and swapped them into approximately 689 ETH before sending the ETH to Tornado Cash, according to on-chain analysis reported by Specter and other security researchers.<\/p>\n<p>The investigation identified several addresses associated with the activity, including <code>0xDaCC235a494750193695A111D715c2ca12b5Ce38<\/code>, <code>0x8aaf01B6F9AcC973274B8718BE4D1C1be10E3be6<\/code> and <code>0xC95496c917A41a394EfdAC3e0882F5903D24De69<\/code>.<\/p>\n<p>Several contracts were also identified in the transaction flow, including <code>0xec434a2f9b7b93aad1bed77d6bc512a75ae90d78<\/code>, <code>0x5872B67d58CeF954B52dEb8E97f9F614BB12fa3d<\/code>, <code>0x84A060Ed81316E6741Af216A099cFea8bCDd3489<\/code>, <code>0x265ccfF3673bCAb03867988081cd51bFd919C03C<\/code> and <code>0x4a3508C5aC0677325932f3bC786Ae7A1C3e9CAfF<\/code>.<\/p>\n<p>A notable part of the incident is its connection to a much older security review.<\/p>\n<p>In its <a href=\"https:\/\/www.openzeppelin.com\/news\/notional-audit\">December 2020 audit of Notional V1<\/a>, OpenZeppelin identified a finding concerning type casting without overflow checks.<\/p>\n<p>The audit specifically pointed to the <code>_convertToETH<\/code> function in <code>ExchangeRate.sol<\/code>, where an <code>int256<\/code> balance was cast to <code>uint128<\/code>. OpenZeppelin recommended using its <code>SafeCast<\/code> library to prevent truncation and unexpected values.<\/p>\n<p>The connection is significant because the 2026 exploit analysis also identifies an unsafe narrowing conversion involving <code>uint128<\/code> in the collateral valuation path.<\/p>\n<p>However, the available evidence does not establish that the exact finding from the 2020 audit remained unchanged in the deployed contract until the September 2026 incident. The historical audit and the current exploit analysis should therefore be treated as a documented technical connection rather than proof that an unresolved audit finding directly caused the attack.<\/p>\n<p>Notional&#8217;s own <a href=\"https:\/\/docs.notional.finance\/notional-v3\/smart-contracts\/audits\">security audit history<\/a> lists the OpenZeppelin V1 audit from December 2020, followed by additional security reviews covering later versions of the protocol.<\/p>\n<p>Notional&#8217;s <a href=\"https:\/\/docs.notional.finance\/developers\/smart-contract-documentation\/escrow\">Escrow documentation<\/a> describes the contract&#8217;s role in account balances, deposits, withdrawals, cash balances, collateral and settlement. It also documents the use of free collateral in withdrawal checks.<\/p>\n<p>The incident is separate from the protocol&#8217;s previous V3 security problems. In 2025, Notional responded to the Balancer exploit and later announced the wind-down of Notional V3. The current incident, according to the available technical reporting, concerns legacy V1 Escrow infrastructure.<\/p>\n<p>At the time of the available reports, Notional had not publicly confirmed the incident, released an official post-mortem or published an official loss figure. The $1.7 million estimate therefore comes from on-chain analysis and security researchers rather than a confirmed statement from Notional.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Notional Finance appears to have suffered a $1.73 million exploit involving a legacy V1 Escrow contract, after an attacker abused an integer conversion flaw to bypass collateral checks and withdraw stablecoins held by the protocol. On-chain investigators and security firms reported that the attacker extracted about 69,257.37 DAI and 1,658,524.86 USDC from the Escrow contract. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6763,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[164],"tags":[30],"class_list":["post-6762","post","type-post","status-publish","format-standard","has-post-thumbnail","category-tech-updates","tag-cybersecurity"],"share_on_mastodon":{"url":"https:\/\/mastodon.social\/@Areeblog\/117212962605308360","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Notional Finance Loses $1.7M in Integer Overflow Attack - Aree Blog<\/title>\n<meta name=\"description\" content=\"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Notional Finance Loses $1.7M in Integer Overflow Attack\" \/>\n<meta property=\"og:description\" content=\"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-04T13:11:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1568\" \/>\n\t<meta property=\"og:image:height\" content=\"882\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"Notional Finance Loses $1.7M in Integer Overflow Attack\",\"datePublished\":\"2026-09-04T13:11:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/\"},\"wordCount\":706,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/notional-finance-1568x882-1.png\",\"keywords\":[\"cybersecurity\"],\"articleSection\":[\"Tech Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/\",\"name\":\"Notional Finance Loses $1.7M in Integer Overflow Attack - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/notional-finance-1568x882-1.png\",\"datePublished\":\"2026-09-04T13:11:59+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/notional-finance-1568x882-1.png\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/notional-finance-1568x882-1.png\",\"width\":1568,\"height\":882,\"caption\":\"Notional Finance Loses $1.7M in Integer Overflow Attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/notional-finance-loses-1-7m-in-integer-overflow-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Notional Finance Loses $1.7M in Integer Overflow Attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Notional Finance Loses $1.7M in Integer Overflow Attack - Aree Blog","description":"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/","og_locale":"en_US","og_type":"article","og_title":"Notional Finance Loses $1.7M in Integer Overflow Attack","og_description":"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...","og_url":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/","og_site_name":"Aree Blog","article_published_time":"2026-09-04T13:11:59+00:00","og_image":[{"width":1568,"height":882,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","type":"image\/png"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"Notional Finance Loses $1.7M in Integer Overflow Attack","datePublished":"2026-09-04T13:11:59+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/"},"wordCount":706,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","keywords":["cybersecurity"],"articleSection":["Tech Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/","url":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/","name":"Notional Finance Loses $1.7M in Integer Overflow Attack - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","datePublished":"2026-09-04T13:11:59+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"Notional Finance loses $1.7M in a V1 Escrow exploit after an integer overflow bypassed collateral checks...","breadcrumb":{"@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","width":1568,"height":882,"caption":"Notional Finance Loses $1.7M in Integer Overflow Attack"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/notional-finance-loses-1-7m-in-integer-overflow-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"Notional Finance Loses $1.7M in Integer Overflow Attack"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6622,"url":"https:\/\/areeblog.com\/cosmos-evm-vulnerability-tied-to-multi-chain-attacks-after-millions-in-tokens-drained\/","url_meta":{"origin":6762,"position":0},"title":"Cosmos EVM Vulnerability Tied to Multi-Chain Attacks After Millions in Tokens Drained","author":"Daniel Chinonso John","date":"August 27, 2026","format":false,"excerpt":"A vulnerability in the shared Cosmos EVM software module has been linked to a multi-chain security incident that forced validators on several Cosmos-based networks to halt block production and resulted in large token losses on KiiChain and TAC. The affected networks publicly identified so far include KiiChain, TAC, MANTRA and\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Cosmos EVM Vulnerability Tied to Multi-Chain Attacks After Millions in Tokens Drained","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident-1.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":6686,"url":"https:\/\/areeblog.com\/cronos-halts-blockchain-after-tectonic-exploit-puts-about-75-million-at-risk\/","url_meta":{"origin":6762,"position":1},"title":"Cronos Halts Blockchain After Tectonic Exploit Puts About $75 Million at Risk","author":"Daniel Chinonso John","date":"August 31, 2026","format":false,"excerpt":"The Cronos blockchain halted block production on Sunday after an exploit targeted Tectonic, the network\u2019s largest decentralized lending protocol, with on-chain researchers estimating that about $75 million in assets was affected. Cronos Network said it had identified an exploit in Tectonic and halted the network while the situation was investigated.\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Cronos Halts Blockchain After Tectonic Exploit Puts About $75 Million at Risk","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-44.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-44.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-44.jpeg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":5841,"url":"https:\/\/areeblog.com\/common-mfa-bypass-techniques-attackers-use-today\/","url_meta":{"origin":6762,"position":2},"title":"Common MFA Bypass Techniques Attackers Use Today","author":"Daniel Chinonso John","date":"January 19, 2026","format":false,"excerpt":"Multi-factor authentication is often described as the extra lock on the door of a digital account. It adds a second step beyond a password, usually a code, a prompt on a phone, or a physical security key. Because of this, many people assume accounts protected by multi-factor authentication are close\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Common MFA Bypass Techniques Attackers Use Today","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260119-WA0017.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260119-WA0017.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260119-WA0017.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260119-WA0017.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260119-WA0017.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6008,"url":"https:\/\/areeblog.com\/supply-chain-attacks-why-small-vendors-are-prime-targets\/","url_meta":{"origin":6762,"position":3},"title":"Supply Chain Attacks: Why Small Vendors Are Prime Targets","author":"Daniel Chinonso John","date":"March 22, 2026","format":false,"excerpt":"Supply chain attacks do not begin at the front door. They slip in through a trusted partner, a software update, a shared library, or a service provider that already has a place in the environment. That is what makes supply chain attacks so effective: the request, file, or login often\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Supply Chain Attacks: Why Small Vendors Are Prime Targets","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/03\/IMG-20260322-WA0001.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/03\/IMG-20260322-WA0001.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/03\/IMG-20260322-WA0001.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/03\/IMG-20260322-WA0001.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/03\/IMG-20260322-WA0001.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6610,"url":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","url_meta":{"origin":6762,"position":4},"title":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent","author":"Daniel Chinonso John","date":"August 25, 2026","format":false,"excerpt":"Security researchers at Oasis Security have disclosed a vulnerability in NVIDIA\u2019s NemoClaw AI-agent environment that can allow a malicious webpage to reach the local Ollama server used for model inference and alter how an AI model processes instructions. The vulnerability, tracked as CVE-2026-65105, was reported to NVIDIA\u2019s Product Security Incident\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":6619,"url":"https:\/\/areeblog.com\/cosmos-orders-evm-based-chains-to-halt-block-production-amid-active-security-incident\/","url_meta":{"origin":6762,"position":5},"title":"Cosmos Orders EVM-Based Chains to Halt Block Production Amid Active Security Incident","author":"Daniel Chinonso John","date":"August 26, 2026","format":false,"excerpt":"Cosmos Labs has urged public blockchains using vulnerable versions of its Cosmos EVM module to immediately halt block production and upgrade their software, following attacks that disrupted MANTRA, KiiChain and TAC. The warning came as Cosmos Labs' security and engineering teams investigated an ongoing incident involving Cosmos EVM, the software\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Cosmos Orders EVM-Based Chains to Halt Block Production Amid Active Security Incident","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/Cosmos-EVM-Security-Incident.png?resize=1400%2C800&ssl=1 4x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/09\/notional-finance-1568x882-1.png","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=6762"}],"version-history":[{"count":1,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6762\/revisions"}],"predecessor-version":[{"id":6764,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6762\/revisions\/6764"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/6763"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=6762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=6762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=6762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}