Blockchain security firm SlowMist has detected two attackers attempting to replicate the exploit that recently drained approximately $1.7 million from Notional Finance’s legacy V1 contract. The attackers have already created malicious fCash positions on BNB Chain, but the withdrawal stage of the attack has not yet been executed.
According to a SlowMist security alert, the potentially vulnerable contract is 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0. SlowMist said the malicious positions are currently waiting to mature, after which the attackers may be able to settle them and withdraw assets if no mitigation occurs first.
Attackers Copy Notional fCash Exploit
The setup mirrors the vulnerability pattern used against Notional Finance’s legacy V1 infrastructure earlier in September. In that incident, an attacker manipulated the protocol’s fCash accounting mechanism and withdrew roughly $1.7 million in DAI and USDC. Notional subsequently confirmed that it identified the vulnerability and paused the affected legacy contract.
The project also said other user assets, including funds associated with Notional Exponent, were not at risk. The original exploit was therefore isolated to legacy V1 infrastructure rather than representing a compromise of Notional’s entire current product stack.
On BNB Chain, SlowMist identified two transactions associated with the new preparation stage. The actors appear to have reproduced the malicious position-creation sequence before maturity, effectively creating a delayed security threat that remains visible on-chain before the potential withdrawal can occur.
That delay creates an unusual mitigation window. Unlike exploits where assets are removed immediately after the vulnerable transaction is submitted, the fCash positions must mature before the attackers can attempt final settlement, giving the affected project time to pause, patch or otherwise restrict the relevant contract.
BNB Chain Funds Have Not Yet Been Drained
SlowMist has not disclosed the identity of the project associated with the 0x0795…D9F0 contract or quantified how much capital could ultimately be exposed. There is therefore no confirmed loss figure for the BNB Chain incident, and describing the current activity as a completed exploit would be premature.
The security firm urged the affected project to take immediate action before the malicious positions reach maturity. Whether the attempted attack succeeds now depends partly on whether operators can neutralize the vulnerable settlement path before those positions become executable.
The incident also illustrates how disclosed or observable DeFi vulnerabilities can quickly be copied across chains when similar contract logic has been deployed elsewhere. A successful exploit against one protocol can become a template for attackers searching for reused code or related accounting assumptions in other environments.
For now, the most important distinction is between preparation and loss. Two attackers have established malicious fCash positions on BNB Chain using the Notional exploit pattern, but the funds have not yet been reported as withdrawn, leaving mitigation possible while security teams monitor the contracts ahead of maturity.
