← Summer.fi Lazy Summer Exploit (July 2026)1 decision on this page
Audit log
Every state-changing event for Summer.fi Lazy Summer Exploit (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-29 23:34:18ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
H4RtDfem93dV…z6JGDzQ8sha256 → base58
verifying row…canonical bytes (23699 B) ▸
{"actor":"system:backfill","investigation_id":"6e55f8b2-3144-47ec-94b4-ab11d0f072c2","kind":"publish","page_slug":"summer-fi-exploit-july-2026","published_at":"2026-07-29T23:34:18.530Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Summer.fi Lazy Summer Exploit (July 2026)","sections":[{"content":"Summer.fi originated as Oasis.app, built within the Maker Foundation as the original front-end for the Maker Protocol starting in 2016. Following the Maker Foundation's decentralization in 2021, Oasis.app was spun out as an independent company. In June 2023, it rebranded to Summer.fi, expanding from a MakerDAO-centric product to a multi-protocol DeFi interface supporting Aave, Morpho, Compound, and others. In August 2023, the company closed a $6 million Series A funding round led by Libertus Capital. The Lazy Summer Protocol — an automated yield vault system — was launched in early 2025. In January 2026, the SUMR governance token was introduced and began trading on January 21, 2026, tied to protocol revenue and on-chain governance rights. Prior to the July 2026 exploit, Summer.fi had no publicly documented major security incidents since its 2023 rebrand.","heading":"Background: Summer.fi and Lazy Summer Protocol","severity":"low","sources":[{"credibility":1,"name":"Oasis.app Rebrands To Summer.fi (Official Blog)","type":"official","url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"credibility":2,"name":"Shaping DeFi's Horizon: A Conversation with Chris Bradbury, CEO of Summer.fi","type":"news_article","url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"credibility":1,"name":"Lazy Summer Governance Recap – January 2026 (Official Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-governance-recap-january-2026/"}]},{"content":"The exploit's underlying precondition traces to the November 2025 collapse of Stream Finance, in which an external fund manager disclosed a $93 million loss, causing Stream's stablecoin xUSD to lose approximately 77% of its value and triggering an estimated $285 million in contagion across DeFi lending platforms including Euler, Silo, and Morpho. Following the collapse, Silo 'Varlamore USDC Growth' vault tokens — which had been positioned as a yield strategy within Summer.fi's Lazy Summer vaults — were never marked down on-chain. Their reported valuation continued to reflect pre-collapse prices while interest kept accruing on stranded, economically impaired USDC. The Lazy Summer Protocol had begun the process of decommissioning this Ark (strategy adapter) by setting its deposit cap to zero, but the Ark remained counted in the Fleet Commander contract's totalAssets() calculation, meaning its stale, inflated valuation continued to be incorporated into vault share pricing. This left a dormant mispricing vulnerability in place for approximately eight months before the July 2026 exploit.","heading":"Root Cause: Stale Valuation Inherited from the Stream Finance Collapse","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Official Summer.fi Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"credibility":2,"name":"Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation (Verichains)","type":"research","url":"https://blog.verichains.io/p/lazy-summer-hack-analysis-stale-asset"},{"credibility":2,"name":"Stream Finance Hack (2025) - $93.0M Lost (Smart Contract Hacking)","type":"research","url":"https://smartcontractshacking.com/hacks/stream-finance-hack-2025"}]},{"content":"According to Summer.fi's official post-mortem and independent security analysis, the attacker began positioning for the exploit at least three months in advance, with wallets funded through a common path in early April 2026, systematically accumulating the stale-valued Silo Varlamore USDC Growth tokens. On July 6, 2026 at approximately 05:17 AM UTC, the attacker executed the exploit in a single atomic transaction. The attack proceeded as follows: the attacker donated the overvalued Silo tokens into a Lazy Summer Protocol Ark that was still included in the vault's totalAssets() computation despite having its deposit cap set to zero. Because the donated tokens carried stale, inflated on-chain valuations, the donation raised the vault's reported totalAssets() — and therefore its share price — without any real assets backing the increase. The attacker then used a $65.4 million flash loan sourced from Morpho to redeem shares at the artificially inflated price, extracting genuine depositor assets at a profit. The primary affected vault was LazyVault_LowerRisk_USDC (managed by Block Analitica), from which approximately $5.64 million was extracted, with an additional approximately $0.40 million drained from the LazyVault_HigherRisk vault. Total extracted funds amounted to approximately $6.04 million in USDC. During the exploit, the vault's displayed APY briefly surged to approximately 2.08 million percent, an anomaly flagged by on-chain monitoring. Stolen USDC was subsequently swapped to DAI via Curve and transferred to the attacker's beneficiary address at 0x7BF716167B48CF527725722C6d79494b45B3BDCa, executed through a contract at 0x0514F827C129C16418a0933E03C99A6AF982FC61.","heading":"Attack Mechanism and Execution","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Official Summer.fi Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million (The Block)","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss (Bitcoin.com News)","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"},{"credibility":2,"name":"Exploiters drain $6M from Summer.fi Lazy Summer USDC vault (Bitget News)","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605491891"}]},{"content":"Blockchain security firm Blockaid issued the first public alert at approximately 05:36 AM UTC on July 6, 2026, roughly 19 minutes after the exploit executed. Security firms PeckShield and CertiK subsequently confirmed the attack and identified the affected vault. Summer.fi acknowledged the incident publicly, stating on X: 'We are aware of the reported exploit a little earlier today and are investigating the root cause. The protocol guardians are currently pausing all Vaults across the Lazy Summer Protocol.' Block Analitica, the vault manager, froze deposit caps at 06:42 AM UTC. The Guardian multisig completed a full pause of all Ethereum and Base vaults at 10:25 AM UTC. The Summer.fi Foundation swept the donated stale tokens at 16:39 PM UTC to stop further NAV distortion. The protocol had a reported total value locked of approximately $22 million at the time of the incident.","heading":"Detection and Incident Response","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Official Summer.fi Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"Summer.fi Hit by $6M Exploit as Blockaid Tracks DAI Drain on Ethereum (MoneyCheck)","type":"news_article","url":"https://moneycheck.com/summer-fi-hit-by-6m-exploit-as-blockaid-tracks-dai-drain-on-ethereum"},{"credibility":2,"name":"Blockaid Flags $6 Million Exploit on DeFi Platform Summer.fi (CryptoRank)","type":"news_article","url":"https://cryptorank.io/news/feed/432cb-blockaid-flags-6-million-exploit-on-defi-platform-summer-fi-as-security-challenges-mount"}]},{"content":"Following the exploit, the attacker's beneficiary wallet (0x7BF716167B48CF527725722C6d79494b45B3BDCa) received approximately 6.017 million DAI. The attacker subsequently began moving funds through Tornado Cash, the sanctioned cryptocurrency mixer. According to reporting by The Defiant and confirmed in Summer.fi's post-mortem, the attacker moved approximately $1.35 million in DAI by swapping it for ETH on Uniswap and routing it through an intermediary wallet into Tornado Cash. As of reporting, approximately $4.67 million in DAI remained in the original attacker wallet. Summer.fi stated it is conducting ongoing tracing with security partners and noted potential law enforcement coordination, while withholding fine details of attribution to protect active investigations. The use of Tornado Cash significantly complicates fund recovery prospects.","heading":"Fund Movement and Laundering","severity":"critical","sources":[{"credibility":2,"name":"Summer.fi Hacker Moves $1.35M Into Tornado Cash (The Defiant)","type":"news_article","url":"https://thedefiant.io/news/hacks/summer-fi-hacker-moves-1-35m-into-tornado-cash"},{"credibility":2,"name":"Summer.fi Hacker Launders $1M Through Tornado Cash After $6M Exploit (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/summer-fi-hacker-launders-tornado-cash/"},{"credibility":2,"name":"Summer.fi Hacker Moves $6M In Stolen DAI Through Tornado Cash Mixer (Bitcoin World)","type":"news_article","url":"https://bitcoinworld.co.in/summer-fi-hacker-laundering-dai-tornado-cash/"},{"credibility":3,"name":"Summer.fi Hack Update: Investigation and Recovery (CoinGabbar)","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/summerfi-hack-update-investigation-and-recovery"}]},{"content":"The SUMR governance token, which had begun trading on January 21, 2026, declined by more than 18% immediately following public disclosure of the exploit on July 6, 2026. Trading data noted the token near $0.00193 in the 24-hour period following the incident. The exploit represents one of the first significant tests of the SUMR token's resilience following its launch six months prior.","heading":"Market Impact: SUMR Token","severity":"high","sources":[{"credibility":2,"name":"Hackers Reportedly Drain $6 Million From DeFi Protocol Summer.fi (BeInCrypto)","type":"news_article","url":"https://beincrypto.com/summer-fi-exploit-6-million-sumr/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"}]},{"content":"Following the incident, Summer.fi announced that all Lazy Summer Protocol vaults would remain paused while patches are developed and reviewed. The protocol's post-mortem identified the root failure as incomplete Ark decommissioning: the deposit cap was set to zero but the Ark was not fully removed from the totalAssets() calculation, allowing stale-valued tokens to inflate vault NAV. Remediation includes a review of all Ark removal procedures to prevent dormant-but-active states and an evaluation of Guardian module requirements. Governance was tasked with deciding on exclusion of attacker shares from SUMR snapshots, and capital return mechanisms for affected depositors. No formal compensation program for affected users had been announced as of reporting. Approximately $4 million in user assets remained outstanding and temporarily illiquid. Summer.fi also announced that its application would remain operational through August 31, 2026, with customer support via email and Discord through that date. After August 2026, responsibility for the Lazy Summer Protocol infrastructure was stated to shift entirely to the Lazy Summer DAO.","heading":"Protocol Remediation and Governance Transition","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Official Summer.fi Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":3,"name":"Summer.fi Hack Update: Investigation and Recovery (CoinGabbar)","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/summerfi-hack-update-investigation-and-recovery"},{"credibility":3,"name":"Summer.fi Shuts Down After $6 Million Exploit Sends Shockwaves Through DeFi (HOKANEWS)","type":"news_article","url":"https://www.hokanews.com/2026/07/summerfi-shuts-down-after-6-million.html"}]},{"content":"Security researchers and analysts highlighted the Summer.fi exploit as a case study in DeFi composability risk. The Crypto Times described the dynamic as follows: 'in composable DeFi, a collapse is never fully over: the mispriced debris it leaves behind can sit dormant on-chain for months, waiting for someone patient enough to turn it into a weapon.' The exploit demonstrates that third-party protocol failures — in this case Stream Finance's November 2025 collapse — can leave latent vulnerabilities in downstream protocols that integrate their tokens or strategies, even after the primary incident is considered resolved. The eight-month gap between the Stream Finance collapse and the Summer.fi exploit illustrates the extended time horizon over which such vulnerabilities can persist undetected. Independent security firm Verichains published a technical analysis of the stale-asset donation and ERC-4626 share-price manipulation mechanics involved.","heading":"Systemic Risk: DeFi Composability and Stale Oracle Contagion","severity":"high","sources":[{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"credibility":2,"name":"Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation (Verichains)","type":"research","url":"https://blog.verichains.io/p/lazy-summer-hack-analysis-stale-asset"},{"credibility":2,"name":"Anatomy of a $285M DeFi Contagion: The Stream Finance xUSD Collapse (BlockEden)","type":"research","url":"https://blockeden.xyz/blog/2025/11/08/m-defi-contagion/"}]}],"sources_used":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Official Summer.fi Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million (The Block)","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":2,"name":"Hackers Reportedly Drain $6 Million From DeFi Protocol Summer.fi (BeInCrypto)","type":"news_article","url":"https://beincrypto.com/summer-fi-exploit-6-million-sumr/"},{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"credibility":2,"name":"Summer.fi Hacker Moves $1.35M Into Tornado Cash (The Defiant)","type":"news_article","url":"https://thedefiant.io/news/hacks/summer-fi-hacker-moves-1-35m-into-tornado-cash"},{"credibility":2,"name":"Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation (Verichains)","type":"research","url":"https://blog.verichains.io/p/lazy-summer-hack-analysis-stale-asset"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss (Bitcoin.com News)","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"},{"credibility":2,"name":"Summer.fi Hacker Launders $1M Through Tornado Cash After $6M Exploit (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/summer-fi-hacker-launders-tornado-cash/"},{"credibility":1,"name":"Oasis.app Rebrands To Summer.fi (Official Blog)","type":"official","url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"credibility":1,"name":"Lazy Summer Governance Recap – January 2026 (Official Blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-governance-recap-january-2026/"},{"credibility":2,"name":"Anatomy of a $285M DeFi Contagion: The Stream Finance xUSD Collapse (BlockEden)","type":"research","url":"https://blockeden.xyz/blog/2025/11/08/m-defi-contagion/"},{"credibility":2,"name":"Stream Finance Hack (2025) - $93.0M Lost (Smart Contract Hacking)","type":"research","url":"https://smartcontractshacking.com/hacks/stream-finance-hack-2025"},{"credibility":2,"name":"Summer.fi Hit by $6M Exploit as Blockaid Tracks DAI Drain on Ethereum (MoneyCheck)","type":"news_article","url":"https://moneycheck.com/summer-fi-hit-by-6m-exploit-as-blockaid-tracks-dai-drain-on-ethereum"},{"credibility":2,"name":"Exploiters drain $6M from Summer.fi Lazy Summer USDC vault (Bitget News)","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605491891"},{"credibility":2,"name":"Summer.fi Suffers $6M DeFi Exploit After Alleged Flash Loan Manipulates Vault Accounting (Metaverse Post)","type":"news_article","url":"https://mpost.io/summer-fi-suffers-6m-defi-exploit-after-alleged-flash-loan-manipulates-vault-accounting/"},{"credibility":3,"name":"Summer.fi Hack Update: Investigation and Recovery (CoinGabbar)","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/summerfi-hack-update-investigation-and-recovery"},{"credibility":2,"name":"Registry of Lenders Impacted by Stream and Stable Labs Incidents (Silo Finance / Medium)","type":"official","url":"https://silofinance.medium.com/registry-of-lenders-impacted-by-stream-and-stable-labs-incidents-19c6b1f13a5b"}],"summary":"On July 6, 2026, an attacker drained approximately $6.04 million from Summer.fi's Lazy Summer Protocol vaults using $65.4 million in flash loans sourced from Morpho. The exploit exploited stale on-chain valuations of Silo 'Varlamore USDC Growth' tokens — mispriced assets left over from the November 2025 Stream Finance collapse — to artificially inflate vault net asset values and redeem shares at fraudulent prices. Stolen funds were converted to DAI and subsequently laundered through Tornado Cash.","timeline":[{"date":"2016-01-01","event":"Oasis.app created within the Maker Foundation as the original front-end for the Maker Protocol.","source":"Summer.fi Official Blog","source_url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"date":"2021-06-01","event":"Oasis.app spun out as an independent company following the Maker Foundation's decentralization.","source":"CoinCodex","source_url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"date":"2023-06-01","event":"Oasis.app rebrands to Summer.fi, expanding beyond MakerDAO to a multi-protocol DeFi interface.","source":"Summer.fi Official Blog","source_url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"date":"2023-08-01","event":"Summer.fi closes a $6 million Series A funding round led by Libertus Capital.","source":"CoinCodex","source_url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"date":"2025-11-07","event":"Stream Finance collapses following a $93 million loss disclosure; xUSD stablecoin loses approximately 77% of value. Silo Varlamore USDC Growth tokens become economically impaired but are never marked down on-chain.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"date":"2026-01-21","event":"SUMR governance token begins trading for the first time.","source":"Summer.fi Official Blog","source_url":"https://blog.summer.fi/lazy-summer-governance-recap-january-2026/"},{"date":"2026-04-01","event":"Alleged attacker wallets are funded and begin systematically accumulating stale-valued Silo Varlamore USDC Growth tokens in preparation for the exploit, according to Summer.fi's post-mortem.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"At 05:17 AM UTC, attacker executes exploit using $65.4 million Morpho flash loan, donating stale-valued tokens to inflate LazyVault NAV and extracting approximately $6.04 million from LowerRisk and HigherRisk USDC vaults.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"At 05:36 AM UTC, Blockaid issues first public alert about the exploit.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"Stolen USDC is converted to DAI via Curve and transferred to attacker address 0x7BF716167B48CF527725722C6d79494b45B3BDCa.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"date":"2026-07-06","event":"At 06:42 AM UTC, Block Analitica freezes deposit caps. PeckShield and CertiK confirm the attack.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"SUMR token declines by more than 18% following public disclosure of the exploit.","source":"BeInCrypto","source_url":"https://beincrypto.com/summer-fi-exploit-6-million-sumr/"},{"date":"2026-07-06","event":"At 10:25 AM UTC, Guardian multisig completes pause of all Ethereum and Base Lazy Summer Protocol vaults.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"At 16:39 PM UTC, Summer.fi Foundation sweeps donated stale tokens to halt further NAV distortion.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-08","event":"Attacker moves approximately $1.35 million in DAI through Tornado Cash mixer, converting to ETH via Uniswap before routing through an intermediary wallet.","source":"The Defiant","source_url":"https://thedefiant.io/news/hacks/summer-fi-hacker-moves-1-35m-into-tornado-cash"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 132c1e09-2cf5-4194-b4fb-0222f4efad09
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.