Security

SlowMist flags copycat Notional Finance exploit prep on BNB Chain

SlowMist said it has detected two attackers on BNB Smart Chain who are creating malicious fCash positions that mirror the vulnerability pattern seen in Notional Finance, warning that the positions may be used later if they mature. The security firm urged the affected project, identified by contract address 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0, to act immediately.

The alert was posted by SlowMist on X, which said the attackers have already completed the setup stage and that transaction links support its finding. The firm described the activity as a copycat attempt tied to the Notional Finance exploit pattern, rather than a confirmed drain at the time of the post.

Positions are waiting for maturity before any possible settlement

According to SlowMist, the current stage is not the final step. The attackers have created the positions and are now waiting for them to mature before any potential settlement or withdrawal. That means the immediate risk flagged by the firm is preparatory activity, with the next outcome dependent on what happens when the positions reach maturity.

SlowMist did not say in the alert that funds had already been taken. Instead, its warning focused on the existence of the malicious positions and the need for prompt mitigation before the mechanism can be used further.

The alert adds another security concern for BNB Chain participants following a pattern that SlowMist says resembles the Notional Finance vulnerability. For now, the key confirmed detail is the creation of those positions and the firm’s call for immediate action from the affected project.