Notional Finance; Reviewed & Scored | The Block Note
Lending & Borrowing Protocol Review · Updated August 2026

Notional Finance:
a genuinely distinctive fixed-rate model, and a very recent, very costly lesson about old code.

We tore apart Notional Finance, a fixed-rate lending protocol on Ethereum built around a distinctive fCash tokenization mechanism, across the same lending-adapted scorecard we've used throughout this series. We want to flag directly that our research window closed only days after a significant, still-developing incident, so treat the details below as current to our research rather than a final, settled account. On September 4, 2026, an attacker exploited an unsafe integer downcast in Notional's legacy V1 escrow contract, a version the team had deprecated after winding down its V3 markets following a November 2025 incident where a separate protocol's exploit (Balancer) cascaded into V3's connected vaults. Two calls to a core function created a liability so large it silently wrapped around to zero under an unchecked uint128 conversion, letting the attacker's account read as debt-free and drain roughly $1.73 million, which was swapped to ETH and routed through Tornado Cash within minutes. A detailed technical write-up notes Notional used the safer conversion method elsewhere in the very same file, suggesting an inconsistency in an old code path rather than a systemic design flaw, but also that the deprecated contract was left live and funded rather than swept empty, and that as of the most recent reporting we found, five days after the exploit, Notional had issued no public statement, loss figure, or post-mortem. We also found the protocol's genuinely distinctive fixed-rate value proposition, and a real, disclosed non-custodial design; and landed on a score the marketing page won't show you.

Type Non-Custodial Fixed-Rate Lending Protocol (fCash) Platforms Web · Ethereum Rates Fixed-term, locked-in rates via fCash Discount Offer None
notional
Fixed-Rate Lending Protocol
Sep 4, 2026: $1.73M drained from unswept V1 code
5 days later: still no public statement found

Our take, up front: Notional Finance is a fixed-rate lending protocol on Ethereum built around fCash, a genuinely distinctive tokenization mechanism that represents future cash obligations, letting lenders and borrowers lock in a rate rather than accept the variable rates common to Aave, Compound, and most other protocols in this series. Real, disclosed non-custodial design, with no dedicated in-house wallet. Real, disclosed regular third-party security audits. We want to be direct that our research window closed only days after a significant, still-developing incident, so what follows reflects our research as of publication, not necessarily a final, settled account. On September 4, 2026, an attacker exploited an unsafe integer downcast in Notional's legacy V1 escrow contract, a version the team had deprecated after winding down its V3 markets following a November 2025 incident in which a separate protocol's exploit (Balancer) cascaded into V3's connected vaults. Two calls to a core minting function created a liability so large it silently wrapped around to zero under an unchecked uint128 conversion, letting the attacker's account read as debt-free; they drained roughly $1.73 million (69,257 DAI and 1,658,524 USDC), swapped it to about 689 ETH, tipped a block builder to route the trade privately, and moved the proceeds through Tornado Cash, all within about three minutes of the initial setup transaction. A detailed technical write-up notes Notional used the safer conversion method elsewhere in the very same file, suggesting an inconsistency in an old, deprecated code path rather than a systemic design flaw across the protocol. But the same write-up is direct about the operational lesson: the deprecated V1 contract was left live and funded rather than swept empty, and roughly $60,600 remained in it, still at risk, as of the most recent reporting we found. As of that same reporting, five days after the exploit, Notional had issued no public statement, loss figure, or post-mortem. We weighted all of it below.

Real, extremely recent, well-documented exploit: on Sept 4, 2026, an unsafe uint128 downcast in Notional's deprecated V1 escrow let an attacker create a liability that silently wrapped to zero, draining ~$1.73M within minutes and routing it through Tornado Cash. Real, disclosed nuance: Notional used the safer conversion method elsewhere in the same file, suggesting an inconsistency in old code rather than a systemic flaw. Real, disclosed operational lapse: the deprecated contract was left live and funded rather than swept empty after V3's wind-down, and ~$60,600 remained at risk as of the most recent reporting we found. Real, disclosed communication gap: as of five days post-exploit, Notional had issued no public statement, loss figure, or post-mortem.

Why this scores below the midpoint: a real, sizeable, very recent loss compounded by a real operational hygiene failure (an unswept deprecated contract) and, as of our research, a concerning absence of public communication about it.

Pros

  • The correct, safer conversion pattern existed elsewhere in Notional's own codebase
  • The actively-used, current contracts were not the ones exploited

Cons

  • Sept 4, 2026: ~$1.73M drained via an unswept, deprecated V1 contract
  • The vulnerable contract was left live and funded rather than emptied after deprecation
  • No public statement, loss figure, or post-mortem found as of five days after the exploit
  • ~$60,600 reportedly remained in the same vulnerable contract as of the most recent reporting

Real, disclosed, notably small current NOTE token market value (~$400,700 as of our research), though this reflects token market cap rather than protocol TVL specifically. Real, disclosed wind-down of Notional's more recently promoted V3 markets following the November 2025 Balancer-linked cascade, reducing the protocol's current active scope. Our sources didn't disclose a precise, current TVL figure with the same specificity as some category leaders.

Why this scores below the midpoint: real, disclosed signs of a shrinking current footprint, combined with limited precise disclosure of current scale in our sources.

Pros

  • The protocol remains operational for its core fixed-rate lending function

Cons

  • V3 markets wound down following a Nov 2025 third-party contagion event
  • Notably small current NOTE token market value, per our research

Real, disclosed functioning NOTE governance token. Real, disclosed non-custodial design, with no dedicated in-house wallet. What tempers this: a real, disclosed operational governance lapse, failing to sweep or disable a deprecated contract after winding down V3, and a real, disclosed apparent lack of prompt public communication following a $1.73M loss.

Why this scores below the midpoint: a functioning governance token and non-custodial design are real positives, tempered by a real, disclosed operational security lapse and a concerning post-incident communication gap as of our research.

Pros

  • Functioning NOTE governance token; genuinely non-custodial design

Cons

  • A deprecated contract was left live and funded rather than swept empty
  • No public statement found five days after a $1.73M loss, as of our research

Real, disclosed support for DAI, ETH, USDC, and WBTC on Ethereum, solid and established, though narrower than some category leaders now offer.

Why this scores at the midpoint: solid, established asset support for a fixed-rate model, tempered by a narrower scope than multi-chain category leaders.

Pros

  • Support for major, established assets (DAI, ETH, USDC, WBTC)

Cons

  • Narrower asset and chain scope than several category leaders in this series

Real, disclosed genuinely distinctive fCash mechanism, with a positive and negative balance representing future cash claims and obligations respectively, letting users understand their fixed-rate position clearly. Real, disclosed non-custodial design, connecting via personal wallets rather than platform-held funds.

Why this scores above the midpoint: a genuinely clear, distinctive mechanism for a fixed-rate product, tempered by limited additional disclosed UX detail in our sources.

Pros

  • fCash balances make fixed-rate positions genuinely legible

Cons

  • Limited additional disclosed UX detail in our sources

Real, disclosed genuinely distinctive value proposition: fixed-term, locked-in rates via fCash, directly addressing the rate unpredictability common to Aave, Compound, and most variable-rate protocols in this series.

Why this scores well: a genuinely useful, distinctive rate model that solves a real, disclosed pain point other protocols in this series don't address as directly.

Pros

  • Genuine rate predictability via fixed-term fCash positions

Cons

  • Fixed terms trade away the flexibility of an open-ended variable-rate position

Real, disclosed distinctive fCash tokenization infrastructure. Real, disclosed decline in feature scope following the wind-down of V3's more advanced markets after the November 2025 Balancer-linked cascade.

Pros

  • Genuinely distinctive fCash tokenization mechanic

Cons

  • Reduced feature scope following V3's wind-down
Where to get it

Access only through Notional's official app, and check for updates on the September 2026 incident directly.

Given that our research window closed only days after this exploit with no official statement yet found, check Notional's own channels and governance forum directly for the latest before depositing, and confirm whether the vulnerable legacy contract has since been fully swept and disabled.

0/ 100

A genuinely useful idea, hit by a genuinely avoidable mistake, at a moment we can't yet see the end of.

We want to be fair about what this exploit actually was and wasn't. It wasn't a flaw in Notional's current, actively-used contracts, and the team clearly knew the correct, safer way to handle this exact kind of integer conversion, because they used it elsewhere in the same file. That distinction matters, and it's why this doesn't score as low as Venus's ignored-and-repeated pattern. But we also don't think "it was old code" is much comfort to anyone who had funds anywhere near that contract, and the deeper issue here is a real, disclosed operational one: a deprecated contract that should have been emptied was left funded instead, for reasons we can't determine from our research. What concerns us most, honestly, is what we couldn't find: any public accounting from Notional in the five days since. We're reviewing this protocol at an unusually live moment, and we'd rather be direct about that than pretend we have the full picture. The fixed-rate model itself remains a genuinely useful idea. Whether the team handles what comes next as responsibly as Save's team did with its own past incidents is something we can't yet confirm.

Best forUsers who specifically want fixed-rate exposure and are checking for a current, post-incident update before depositing
Not forAnyone depositing right now without first confirming Notional's official response to the September 2026 exploit
Score Ledger
notional finance · 7 line items
01Security13.5
02Liquidity8.0
03Decentralization6.75
04Assets6.0
05UX6.5
06Rates7.0
07Extras2.5
TOTAL50.25
≈ 50 / 100; Live incident, check for updates

The scorecard above is deliberately general. Whether Notional Finance is right for you depends heavily on which of these you already are.

Best fit

The user who specifically wants fixed-rate exposure and checks for a current, post-incident update before depositing

This is exactly where Notional's genuinely distinctive fCash mechanism delivers real value, provided you confirm the current situation first.

Good fit

The user who understands the difference between a protocol's current, active contracts and its old, deprecated ones

This September 2026 incident specifically hit unswept legacy code, a real, disclosed distinction worth understanding precisely.

Workable fit

The user who verifies directly with Notional whether the vulnerable legacy contract has been fully swept and disabled

Given the real, disclosed remaining funds in that contract as of our research, this specific check genuinely matters right now.

Poor fit

Anyone depositing right now without first confirming Notional's official response to the September 2026 exploit

Kamino and SparkLend, both reviewed earlier in this series, have demonstrated prompt, transparent incident communication that we couldn't yet find here.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the September 4, 2026 exploit timelined precisely, the technical root cause explained, the November 2025 context, and our sixteenth lending-protocol comparison entry.

September 4, 2026, timelined

Time (UTC)What happened
11:58 PM (Thu)Attacker submits two mintfCashPair() calls to Notional's deprecated V1 escrow, creating a liability of exactly 2^128
Immediately afterThe unsafe uint128 downcast silently truncates the liability to zero; the attacker's account reads as debt-free
~3 minutes laterAttacker withdraws 69,257 DAI and 1,658,524 USDC from the escrow
Shortly afterProceeds swapped to ~689 ETH; a 0.07 ETH tip is paid to block builder Titan to route the trade privately
Shortly afterFunds routed through Tornado Cash

The entire exploit, from the first malicious transaction to funds leaving through a mixer, took only a few minutes; we found no evidence of an earlier warning sign that would have allowed intervention.

The technical root cause, explained

Detail
The flawAn unchecked conversion from a signed integer to a uint128 silently truncates values that don't fit, rather than reverting the transaction
The triggerTwo mintfCashPair() calls summed to exactly 2^128, the specific value that conversion flattens to zero
The inconsistencyNotional used a safer, checked conversion method elsewhere in the same file, per a detailed technical write-up
The contextThe vulnerable code lived in the deprecated V1 escrow, not Notional's current, actively-used contracts

A detailed source draws a specific, practical lesson from this: integer type conversions deserve their own dedicated audit pass, since correct-looking surrounding logic can hide an unsafe cast.

The November 2025 context

What happened
Nov 2025A separate protocol, Balancer, suffered an exploit that cascaded into Notional's V3 markets via connected vaults
ResultNotional wound down its V3 markets in response
The gapThe older V1 contracts, already superseded, were left live and funded rather than swept empty

Two incidents, roughly ten months apart, with two different root causes, a third-party contagion event and an internal legacy-code oversight, both ultimately traceable to the operational complexity of maintaining more than one live contract version at once.

Lending protocols, side by side (series continues)

AaveKaminoMorphoSparkLendEulerJupiter LendMapleVenusFluidProject 0SaveNotional
Most severe disclosed history$292M bridge exploitNone found$18M vault lossNone found$197-240M exploit, recoveredNone on contracts~$50-54M in 2022 defaultsKnown vuln., exploited twice3 incidents (~$8.4M)Governance crisis$1.26M, treasury-covered$1.73M, unswept legacy contract (Sept 2026, still developing)
Distinctive modelMulti-network V3/V4Curator-managed marketsImmutable core + vaultsAave fork, blue-chip onlyModular EVK/EVC vaultsSmart Collateral/DebtInstitutional creditCompound forkShared layer, lending+DEXCross-venue prime brokerageSolana's earliest lenderFixed-rate fCash tokenization

Notional is the only fixed-rate protocol in this series, and the most recently affected by a confirmed incident as of our research; both facts are worth weighing together rather than separately.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We're flagging directly that one source (Milk Road) published its review in May 2026, before this incident occurred, so its more favorable framing simply predates information we now have.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands moderately below the aggregated industry average; incident-specific coverage we found focuses on the technical mechanics of the exploit itself rather than rendering an overall protocol verdict, and the one general review we found predates the incident entirely.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, most recently on September 4, 2026, when an attacker exploited an unsafe integer conversion in a deprecated V1 escrow contract to drain roughly $1.73 million. As of five days after the exploit, the most recent reporting we found, Notional had issued no public statement.

An attacker created a liability of exactly 2^128 via two calls to a core minting function. An unsafe, unchecked conversion to a uint128 data type silently truncated this value to zero instead of rejecting it, making the attacker's account read as debt-free and letting them withdraw funds without repaying anything.

No. The vulnerability was in a deprecated V1 escrow contract, not Notional's actively-used infrastructure. However, that deprecated contract had been left live and funded rather than emptied, and reportedly still held about $60,600 as of the most recent reporting we found.

Notional wound down its V3 markets after a November 2025 incident in which a separate protocol's exploit (Balancer) cascaded into V3's connected vaults. The older V1 contracts were superseded but not swept empty or disabled, leaving them as a live, funded, unmonitored attack surface.

A tokenization mechanism representing future cash obligations. A positive fCash balance represents money you'll receive at maturity (lending); a negative balance represents money you owe (borrowing), both at a rate locked in when the position was opened.

Aave and Compound use variable, utilization-based rates that change over time. Notional lets users lock in a fixed rate for a fixed term via fCash, trading flexibility for predictability.

Reporting on this September 2026 incident does not reference a prior major exploit specific to Notional's own contracts, though its V3 markets were indirectly affected by the November 2025 Balancer exploit cascading into connected vaults.

Yes. Our research window closed only days after this exploit, with no official Notional statement found yet. Check Notional's own channels and governance forum directly for the latest before depositing.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Notional Finance.

More Reviews