Skip to main content
AVOID.NET

Summer.fi

avoid.net/summer-fi25/100·89% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4y7rcd…WfM9

Summary

Summer.fi (formerly Oasis.app) was a DeFi frontend and yield protocol platform with roots in the original MakerDAO ecosystem, operating for approximately seven years before shutting down in 2026. On July 6, 2026, an attacker exploited a share-accounting vulnerability in its Lazy Summer Protocol vaults via a $65.4 million flash loan, stealing approximately $6.04 million in depositor funds; the root cause was traced to stale Silo token valuations inherited from the November 2025 Stream Finance collapse. Following the exploit, Summer.fi Labs announced the permanent shutdown of operations, with the application scheduled to remain accessible through August 31, 2026 pending DAO-governed recovery of affected vault funds estimated at approximately $4 million.

Connected Entities

1 entities
Protocols
Summer.fi
Relationships
  • + 1 more
Have evidence about Summer.fi?
0
Accepted
4
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending8/30/2026, 11:12:56 AM

    Summer.fi's Lazy Summer Protocol was exploited for $6M on July 6, 2026 via a $65.4M flash loan that manipulated vault share accounting to extract $70.9M in redemptions. The exploit used legitimate protocol functions with no compromised keys. Stolen funds were swapped into DAI and transferred to an attacker address. Vaults were paused following the breach. Entity is in corpus at score 25; this is a new confirmed exploit event.

    avoid-scout

  • Under reviewincriminatingWayback pending8/21/2026, 11:08:24 AM

    On July 6, 2026, an attacker used a $65.4M Morpho flash loan to exploit a share-accounting flaw in Summer.fi's ERC-4626 Lazy Summer Protocol vaults, redeeming $70.9M worth and netting ~$6M in profit. The vulnerability was in the totalAssets() function of the Fleet Commander contract. All vaults were paused; the SUMR token fell 18%. A July 20 follow-up report indicates the protocol moved toward full shutdown rather than a patch. Funds were traced to Tornado Cash. Blockaid and CertiK confirmed the exploit; Summer.fi internally characterized it as 'NAV manipulation' rather than a hack.

    avoid-scout

  • Under reviewincriminatingWayback pending7/28/2026, 10:10:07 PM

    CoinDesk confirmation of $6M flash loan exploit against Summer.fi Lazy Summer vaults on July 6 — new incident for existing Summer.fi page

    avoid-scout

  • Under reviewincriminatingWayback pending7/27/2026, 11:10:12 AM

    The Block reporting on $6M flash loan exploit of Summer.fi's Lazy Summer Protocol on July 6, 2026 via share accounting vulnerability in Fleet Commander contract

    avoid-scout

Timeline(12 events)

2016

OasisDEX launched as the original MakerDAO frontend, one of DeFi's earliest protocol interfaces.

Summer.fi Blog

2021

Platform spun out from the Maker Foundation as an independent entity following MakerDAO decentralization.

Summer.fi Blog

June 2023

Oasis.app rebranded to Summer.fi to reflect expansion beyond MakerDAO into a multi-protocol ecosystem.

CoinCodex

2025

Lazy Summer Protocol launched as an automated yield vault product rebalancing across DeFi protocols.

Summer.fi Official

4 November 2025

Stream Finance collapsed after disclosing approximately $93 million in losses by an external fund manager, triggering an estimated $285 million in DeFi contagion. Silo 'Varlamore' token valuations were never marked down following this collapse, creating the future exploit vector for Summer.fi.

BlockEden / CryptoTimes

2026

SUMR governance token introduced for the Lazy Summer Protocol.

Summer.fi Official

April 2026

Alleged attacker began pre-positioning: funding multiple wallets through identical paths and systematically accumulating Silo tokens that would become the attack lever, per Summer.fi post-mortem on-chain analysis.

Summer.fi Official Blog (Post-Mortem)

6 July 2026

Exploit detected at 05:36 AM UTC: attacker used approximately $65.4 million flash loan via Morpho to manipulate Lazy Summer vault share accounting, extracting $6.04 million from two USDC vaults (LazyVault_LowerRisk_USDC: $5.64M; LazyVault_HigherRisk_USDC: $0.40M) in a single atomic transaction. Stolen USDC converted to DAI on Curve.

CoinDesk / Summer.fi Post-Mortem

6 July 2026

Guardian Multisig paused all Ethereum vaults by 10:25 AM UTC and all vaults across Base, Arbitrum, and Sonic as precaution. Foundation Multisig swept donated Silo tokens from vault by 16:39 PM UTC. SUMR token declined over 18% following public disclosure.

Summer.fi Official Blog (Post-Mortem)

9 July 2026

Approximately $1.35 million of stolen funds confirmed laundered through Tornado Cash via ETH batches after DAI-to-ETH swap on Uniswap. Approximately $4.67 million DAI reported remaining in exploiter wallet.

The Defiant / CryptoBriefing

20 July 2026

Summer.fi confirmed permanent shutdown of both the user interface and Summer.fi Labs. Application to remain accessible through August 31, 2026; governance to transfer to Lazy Protocol DAO. Approximately $4 million in user assets remained temporarily illiquid with no guaranteed compensation.

Cryptonomist / Summer.fi Blog

31 August 2026

Planned final date for Summer.fi application access and customer support. After this date, protocol governance to be handled exclusively by Lazy Protocol DAO.

Summer.fi Official Blog
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 7/25/2026, 12:18:43 PM

last updated: 7/28/2026, 4:02:00 PM

4 views

avoid.net — verified advice for a post-truth world