Summer.fi hit by attack with about $6 million stolen

Summer.fi hit by attack with about $6 million stolen

Summer.fi’s incident analysis said an attacker manipulated two Lazy Summer Protocol USDC vaults in one atomic transaction by exploiting NAV calculations tied to legacy-valued tokens, describing the issue as a decommissioning failure rather than a code bug.

USDC

Summary

Summer.fi said an attacker manipulated the share prices of two Lazy Summer Protocol USDC vaults in a single atomic transaction on July 6, extracting about $6.04 million from depositors. Its incident analysis said the exploit targeted NAV calculation after tokens carrying legacy valuations were donated to a paused but not fully removed Silo Ark, inflating total assets by about 9.5%. Summer.fi described the incident as a decommissioning-process failure rather than a smart-contract code bug. The disclosure adds detail to earlier findings from on-chain security firms that estimated roughly $6 million was stolen through flash-loan-backed price manipulation and a flaw in the Fleet Commander contract’s asset accounting logic, allowing the attacker to redeem more than was fairly deposited. Summer.fi had already paused all Lazy Summer vaults, set deposit caps to zero across networks and urged users not to interact with the protocol while it assesses the incident.

Terms & Concepts
  • NAV: Net asset value, a measure of a vault’s assets used to help determine the value of each share.
  • atomic transaction: A transaction whose steps either all execute together or all fail, allowing complex onchain strategies to be completed instantly.
  • Silo Ark: A component referenced in Summer.fi’s analysis that remained paused but still affected vault asset accounting during the exploit.