On September 4, 2026, a chain warning from the security monitoring service Specter broke the calm: an alert issued through PeckShieldAlert indicated that an abnormal fund outflow occurred from the custody contract related to Notional Finance, which was quickly categorized by several media outlets as "suspected attack." In this warning and subsequent reports, a clear yet unsettling fund path was outlined—approximately $1.7 million worth of assets (valued in DAI and USDC) was transferred out of the custody contract, immediately exchanged on the chain for about 689.2 ETH, completing the conversion from dollar-denominated assets to ETH, before the entire amount of ETH flowed into the mixing protocol Tornado Cash, attempting to erase traces of the fund source in a typical "pool mixing" manner. Custody contracts within such DeFi protocols are supposed to lock and manage user assets, and once exploited, the impact often extends beyond a single address, but key pieces of information surrounding this transaction are still absent: the specific identity of the unknown attacker, whether the contract was hacked or if there were other abnormal operational motives, and no complete explanation or loss confirmation has come from official channels of Notional Finance. It is precisely because core information is highly dependent on the third-party monitoring source Specter/PeckShieldAlert that the incident continues to be marked as a "suspected attack" in public discourse, leaving a gray area between truth and panic that awaits filling by both official statements and subsequent on-chain evidence.
Source of Alerts from Specter and PeckShield
The suspected attack event was not initially disclosed by Notional Finance itself, but was captured on-chain by the third-party security monitoring service Specter after noticing anomalous operations with the custody contract, which then issued an alert through the PeckShieldAlert account. The alert used phrases like "custody contract may have been exploited" and "suspected attack," without concluding "confirmed attack," but it clearly pointed out: about $1.7 million worth of DAI and USDC had been anomalously transferred out from the custody contract associated with Notional, exchanged for approximately 689.2 ETH, and subsequently flowed into the mixing protocol Tornado Cash. Immediately following, media such as Planet Daily, PANews, TechFlow, and others referred to the same alert source within the same day or a short period, incorporating the aforementioned fund path and loss scale into their reports, causing the event to rapidly gain wider attention in public discourse.
It is important to emphasize that the core information in currently available public materials heavily relies on this monitoring lead from Specter/PeckShieldAlert: there is hardly any significant difference among media reports, and no public narratives contradicting the alert's conclusion have yet emerged, but the information itself remains at a third-party perspective. For the DeFi industry, the value of such external alerts lies in their ability to raise a "safety red flag" at the first sign of abnormal fund paths on-chain, alerting the community, project parties, and potentially affected users to the risks associated with this critical custody contract; but the limitations are equally evident—monitoring parties often can only infer anomalies based on transaction records, lacking complete context regarding the design of internal permissions, operations, and subsequent handling by the project party, thus can only give a "suspected" judgment without replacing the official technical analysis and loss confirmation. At this stage, readers need to consider Specter/PeckShieldAlert as an early risk signal rather than a final conclusion; whether Notional Finance provides a detailed on-chain review and delineation of responsibilities will determine whether this suspected attack event remains at the warning level or is formally recognized as a contract being attacked.
689 ETH and Tornado's Money Laundering Path
According to publicly monitored and media-referenced materials, the suspected attacker, after completing the anomalous outflow from the custody contract, did not remain in the forms of accounting assets like DAI and USDC, but quickly converted about $1.7 million worth of tokens into approximately 689.2 ETH. The asset's on-chain trajectory clearly delineates a one-way channel: funds from the custody contract were withdrawn, aggregated into mainstream assets like ETH, and then the entire amount of approximately 689.2 ETH was sent to the well-known mixing protocol Tornado Cash, with the on-chain accounting halting here. Current public information remains at the node of "entering Tornado Cash," with no further breakdown transactions or secondary transfer data presented, which means on a verifiable level, the fund path is confirmed only up to the mixing entrance.
The "stable asset → ETH → mixing protocol" three-step path has formed some sort of "precedent" in past DeFi security incidents: first consolidating the stolen tokens into a more market-acceptable asset, then mixing the sources of funds through a mixing pool, combining assets from different attack incidents and different addresses. Technically, one of the design goals of Tornado Cash is to disrupt the direct correlation between addresses, which attackers exploit, making it challenging for investigators to trace back to specific receiving addresses or ultimate ownership on the public chain. For parties associated with Notional, the quick conversion of funds into a mixing pool not only significantly increases the difficulty of subsequent on-chain tracking but also realistically compresses the space for accountability and asset recovery.
Custody Contracts Targeted: A Weak Link in DeFi
In this suspected event, the first pointed out as having anomalies was the custody contract related to Notional Finance. According to publicly available materials, approximately $1.7 million worth of assets, valued in DAI and USDC, were anomalously transferred out of this custody contract and quickly escaped along the path of "exchanged for about 689 ETH, then entered the mixing protocol." In most DeFi protocols, custody contracts are responsible for locking user or protocol assets during specific transaction or lending processes, only releasing funds under preset conditions, thus often located at key nodes of "fund aggregation." In the public description of Notional, it is often viewed as a fixed-rate lending product; if this positioning is subsequently confirmed by official channels, then the relevant custody contract is likely to assume the role of locking collaterals, segmental interest settlement, or maturity payment responsibilities, meaning that once a problem arises, the impact extends beyond a single address to the entire lending and settlement chain.
From a broader industry perspective, the reason custody, collateral, and other asset-intensive contracts frequently become targets of attacks is due to their simultaneous overlap of asset concentration and logical complexity: on one hand, large amounts of funds are concentrated and locked in a few contract addresses, providing a clear and quantifiable "prey" for attackers; on the other hand, these contracts require precise coordination of fund flows across different roles and time points, and the design of permissions, boundary condition judgments, and interactions with external contracts are more susceptible to turning into exploitable vulnerabilities due to a single oversight or a failed assumption. Numerous past security events have repeatedly proven that as long as there are even minor implementation deviations at the custody layer, the impact often spreads to the fund security of many participants. In the current situation where the suspected attack has not yet been confirmed officially, this type of contract still exposes a simple reality: once design flaws are compounded by asset concentration, the custody layer becomes the segment of the entire DeFi system most easily targeted by precision strikes.
Official Silence and the Tug-of-War of Community Trust
After exposing the weak reality of the custody layer, another layer of unease comes from the information vacuum—up to now, there has been no technical explanation, loss confirmation, or review report from Notional Finance in mainstream channels regarding this suspected attack. This silence stands in stark contrast with the intense discussions surrounding the alerts released by Specter through PeckShieldAlert from various media and social accounts: on one side, the path of approximately $1.7 million DAI and USDC being transferred from the custody contract, exchanged for approximately 689.2 ETH and flowing into Tornado Cash, is constantly amplified, while on the other side, the project party has yet to provide a direct response to "Is this an attack? Who is affected? How will it be remedied?" resulting in heightened anxiety among users and the community.
In the absence of an official narrative during this vacuum period, the community can only treat third-party monitoring and media references as a "temporary factual framework," imagining the nature of the attack, the subjects of loss, and emergency plans around the claims from Specter/PeckShieldAlert, but cannot determine which are established facts on-chain and which are merely unverified inferences. Information asymmetry here not only means that users find it difficult to make rational decisions on whether to continue participating in the protocol in the short term, but it also erodes brand image over a longer time horizon—past events in the DeFi field have repeatedly verified that the speed and transparency of official responses are often highly correlated with the progress of trust recovery. At this stage, all readers can do is remain prudent: distinguish confirmed fund paths from unverified interpretations, and view this incident as an evolving risk case rather than a concluded accident until more authoritative information emerges.
Upcoming Focus on Security Remediation and Accountability
This event, which still remains in the "suspected attack" stage, has already revealed two layers of real risks: on one hand, the custody contract acted almost as a single point of failure in the on-chain path of funds being transferred from the custody pool, exchanged for approximately 689.2 ETH, and then flowing into Tornado Cash; once exploited, it could simultaneously jeopardize the asset security of multiple parties. On the other hand, the community's awareness of the anomaly highly relies on the third-party alerts thrown out by Specter through PeckShieldAlert; in the long-term silence from the project party, a dangerous window has formed between the monitoring mechanism and information disclosure. The genuinely concerning variables moving forward are whether Notional will explicitly acknowledge the attack, clarify the range of losses and boundaries of responsibility, whether it will suspend related custody contracts, engage external security teams, and provide verifiable technical analyses and review reports, or choose to only make minimal repairs. More broadly, the industry's ongoing demand for security audits and real-time monitoring has been uplifted after various incidents involving custody contracts and lending protocols; this event may likely be incorporated into the next round of discussions in the DeFi community regarding the safety of custody contracts, risk sharing, and insurance mechanisms, and the actual implementation degree of these discussions will directly determine whether similar risks are compressed or repeated in the future.
Join our community to discuss, and let's grow stronger together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。




