SlowMist Says Attackers Are Copying Notional Finance Exploit Pattern on BNB Chain

SlowMist has detected what it described as two attackers replicating the recent Notional Finance exploit on BNB Chain, according to a KuCoin news report citing the security firm. The firm said the activity had already reached the pre-exploitation stage, with malicious fCash positions created using the same vulnerability pattern seen in the earlier incident.
The warning suggests the attackers were preparing to use the same flaw rather than completing a fresh drain. That distinction matters: pre-exploitation activity can show intent and technical replication, but it does not by itself confirm losses on BNB Chain.
Notional Finance’s earlier incident involved its legacy V1 contract, which the project said was exploited for about $1.7 million in user funds. In that case, Notional said the affected contract was paused and that other user assets, including those in Notional Exponent, were not at risk.
Two attackers, one repeated pattern
In its alert, SlowMist said the attackers were using the same vulnerability pattern linked to the Notional exploit. The description points to a copycat attempt rather than a separate, unrelated weakness.
That said, the available information does not yet show whether the BNB Chain activity resulted in a successful exploit, what assets may be exposed, or whether any funds were moved. The key point for readers is that the attack sequence was detected before confirmation of a completed theft.
The report also ties the incident to BNB Chain, where attackers appear to be testing the same mechanics against another deployment or market environment. For now, the evidence supports an active attempt, not a confirmed outcome.
Further detail would be needed to establish which contracts were involved, whether any defenses were triggered, and whether the situation remains contained.






