← Summer.fi (Lazy Summer Protocol)1 decision on this page
Audit log
Every state-changing event for Summer.fi (Lazy Summer Protocol): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.
- #1publishby system:backfill2026-07-22 01:56:44ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
DSpaQaaeVSTh…V5XvWhx4sha256 → base58
verifying row…canonical bytes (17847 B) ▸
{"actor":"system:backfill","investigation_id":"db58e427-021a-4ee9-93db-ae60a628db8d","kind":"publish","page_slug":"summer-fi-lazy-summer-protocol","published_at":"2026-07-22T01:56:44.459Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Summer.fi (Lazy Summer Protocol)","sections":[{"content":"On July 6, 2026 at approximately 05:17 UTC, an attacker executed a single atomic transaction that manipulated the share-price accounting of two Lazy Summer Protocol USDC vaults on Ethereum mainnet. According to Summer.fi's own post-mortem and multiple news outlets, the attacker flash-borrowed roughly $65.4 million in stablecoins (reported by some outlets as sourced via Morpho), deposited approximately $64.8 million into the protocol's Fleet Commander-managed vaults at an honest share price, then donated over-valued 'Silo: Varlamore USDC Growth' vault tokens into a capped but not fully decommissioned 'Ark' sub-strategy. This donation inflated the vault's reported totalAssets() by roughly 9.5% without adding any real withdrawable liquidity, allowing the attacker to redeem shares at an inflated price and extract approximately $70.9 million in USDC — a net profit of about $6.04 million after repaying the flash loan. The stolen funds were converted to DAI, with proceeds later moved through additional wallets and, according to some reports, partially routed through Tornado Cash.","heading":"The July 6, 2026 Exploit","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem: What Happened and What Comes Next (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million; analysts point to flash loan attack","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"}]},{"content":"Summer.fi's post-mortem states the exploit was 'not caused by compromised private keys, administrative privileges, or a coding bug.' Instead, the vulnerability stemmed from an operational failure: certain 'Arks' (sub-strategy contracts connecting a vault to an underlying lending market) had been paused with zeroed deposit caps following what the post-mortem describes as '2025 issues,' but were allegedly not fully removed from the fleet's net-asset-value (NAV) calculations as intended. This left a channel through which stale, over-valued tokens could be donated into the vault's accounting to artificially inflate the share price. On-chain analysis cited by Summer.fi and multiple outlets indicates the attack was planned well in advance: the attacker allegedly funded multiple wallets around April 6, 2026 and spent roughly three months accumulating the stale-valued Silo vault tokens used in the attack, rather than acting opportunistically.","heading":"Root Cause: Operational Oversight, Not a Contract Bug","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"Summer.fi reveals months-long preparation behind $6M DeFi exploit","type":"news_article","url":"https://ambcrypto.com/summer-fi-reveals-months-long-preparation-behind-6m-defi-exploit/"}]},{"content":"Losses were split across two vaults: approximately $5.64 million from the LazyVault_LowerRisk_USDC vault and approximately $0.40 million from the LazyVault_HigherRisk_USDC vault, for a total of roughly $6.04 million extracted from depositors. Reporting indicates the protocol's total value locked stood at around $22 million at the time of the exploit (with Summer.fi's own shutdown announcement citing $200 million in TVL reached across the broader Lazy Summer ecosystem in the nine months prior to the incident), and that the SUMR governance token declined more than 18% following disclosure of the attack. The attack pushed cumulative 2026 DeFi exploit losses past $840 million industry-wide, according to contemporaneous reporting.","heading":"Financial Impact","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":2,"name":"Summer Finance Faces $6M Loss Following Flash Loan Vulnerability Exploit","type":"news_article","url":"https://moneycheck.com/summer-finance-faces-6m-loss-following-flash-loan-vulnerability-exploit/"}]},{"content":"Security firm Blockaid first flagged the exploit at approximately 05:36 UTC on July 6, 2026, roughly 19 minutes after the attack transaction. Summer.fi states it zeroed deposit caps on the affected vaults by 06:42 UTC, and its Guardian Module paused all Ethereum and Base network vaults by 10:25 UTC, followed by Arbitrum and Sonic vaults by 11:38 UTC. The Summer Foundation reportedly swept illiquid donated shares from the lower-risk vault by 16:39 UTC the same day. Security firms Cyvers and CertiK also published independent technical analyses of the share-accounting manipulation. Summer.fi has stated that 'the Guardians did not and cannot move user funds,' framing the pause mechanism as a permissioned circuit-breaker rather than custodial control.","heading":"Incident Response","severity":"medium","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"Blockaid Detects $6M Exploit on Summer.fi Platform","type":"news_article","url":"https://www.kucoin.com/news/flash/blockaid-detects-6m-exploit-on-summer-fi-platform"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million; analysts point to flash loan attack","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"}]},{"content":"On July 15, 2026, Summer.fi Labs announced it would 'sunset' both the Summer.fi application and the Labs company, stating there was 'no viable path forward other than to wind down operations' following the exploit's financial impact, compounded by what it described as a broadly difficult year for DeFi (citing over $635 million in industry-wide losses in April 2026 alone). The Summer.fi app is scheduled to remain live only until August 31, 2026, after which support channels, including Discord and email support, will also close. The underlying Lazy Summer Protocol is DAO-governed and will reportedly continue to exist independently of the Labs company's operations, with the Lazy Summer DAO tasked with working to resume withdrawals and redemptions across all vaults, including the two exploited ones. Summer.fi (formerly Oasis.app) had operated for roughly five years, since spinning out of the Maker Foundation in June 2021 and rebranding from Oasis.app to Summer.fi in June 2023.","heading":"Company Wind-Down","severity":"critical","sources":[{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":2,"name":"Summer.fi Winds Down After $6M Lazy Summer Vault Exploit","type":"news_article","url":"https://cryptoadventure.com/summer-fi-winds-down-after-6m-lazy-summer-vault-exploit/"},{"credibility":2,"name":"$6 Million Vault Exploit Forces DeFi Platform Summer.fi to Wind Down","type":"news_article","url":"https://cryptorank.io/news/feed/46710-summer-fi-shutdown-lazy-summer-exploit"}]},{"content":"As of the wind-down announcement, Summer.fi had not guaranteed compensation for depositors affected by the exploit. The company's post-mortem states plainly that 'compensation is a Lazy Summer DAO governance decision' and that any discussion of reimbursement would take place through the DAO's governance forum rather than being unilaterally committed to by the team. Approximately $4 million reportedly remained within the affected vaults after the attack, much of it held in illiquid positions requiring a DAO-approved distribution process. This leaves affected users dependent on a future, non-guaranteed governance vote for any recovery of lost funds, a material ongoing risk factor for anyone with capital still in the affected vaults.","heading":"User Compensation Remains Undecided","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"Summer.fi to Wind Down After $6.04 Million Vault Exploit","type":"news_article","url":"https://cryip.co/summer-fi-to-wind-down-after-6-04-million-vault-exploit/"}]},{"content":"Summer.fi began as Oasis.app in 2016, originally built within the Maker Foundation as the primary front-end for the Maker Protocol, before spinning out as an independent entity in June 2021 following MakerDAO's decentralization. It rebranded to Summer.fi in June 2023 as it expanded into a multi-protocol DeFi yield-optimization platform. The company is led by CEO Chris Bradbury, a former MakerDAO product manager. Prior to the July 2026 exploit, Summer.fi reported maintaining a bug bounty program on Immunefi and commissioning smart-contract audits from firms including ChainSecurity, with audit reports made publicly available. News coverage characterized Summer.fi as having no prior exploit history before this incident. It is alleged (per the post-mortem's reference to unspecified '2025 issues' that led certain Arks to be paused) that at least one prior operational problem with the same strategy contributed indirectly to the eventual exploit vector, though details of that earlier issue were not independently found in available reporting and this claim should be treated as low-confidence pending further sourcing.","heading":"Background and Prior Security Posture","severity":"low","sources":[{"credibility":1,"name":"Oasis.app Rebrands To Summer.fi (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":1,"name":"Audits | Summer.fi Knowledge Base","type":"official","url":"https://docs.summer.fi/summer.fi/audits"}]}],"sources_used":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem: What Happened and What Comes Next (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":1,"name":"Oasis.app Rebrands To Summer.fi (Summer.fi official blog)","type":"official","url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"credibility":1,"name":"Audits | Summer.fi Knowledge Base","type":"official","url":"https://docs.summer.fi/summer.fi/audits"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million; analysts point to flash loan attack (The Block)","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss (Bitcoin.com News)","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"},{"credibility":2,"name":"DeFi Protocol Summer.fi Loses $6M in Suspected Flash Loan Attack (KuCoin)","type":"news_article","url":"https://www.kucoin.com/news/flash/defi-protocol-summer-fi-loses-6m-in-suspected-flash-loan-attack"},{"credibility":2,"name":"Blockaid Detects $6M Exploit on Summer.fi Platform (KuCoin)","type":"news_article","url":"https://www.kucoin.com/news/flash/blockaid-detects-6m-exploit-on-summer-fi-platform"},{"credibility":2,"name":"Summer.fi reveals months-long preparation behind $6M DeFi exploit (AMBCrypto)","type":"news_article","url":"https://ambcrypto.com/summer-fi-reveals-months-long-preparation-behind-6m-defi-exploit/"},{"credibility":2,"name":"Summer Finance Faces $6M Loss Following Flash Loan Vulnerability Exploit (MoneyCheck)","type":"news_article","url":"https://moneycheck.com/summer-finance-faces-6m-loss-following-flash-loan-vulnerability-exploit/"},{"credibility":2,"name":"Summer.fi Winds Down After $6M Lazy Summer Vault Exploit (Crypto Adventure)","type":"news_article","url":"https://cryptoadventure.com/summer-fi-winds-down-after-6m-lazy-summer-vault-exploit/"},{"credibility":2,"name":"$6 Million Vault Exploit Forces DeFi Platform Summer.fi to Wind Down (CryptoRank)","type":"news_article","url":"https://cryptorank.io/news/feed/46710-summer-fi-shutdown-lazy-summer-exploit"},{"credibility":3,"name":"Summer.fi to Wind Down After $6.04 Million Vault Exploit (Cryip)","type":"news_article","url":"https://cryip.co/summer-fi-to-wind-down-after-6-04-million-vault-exploit/"}],"summary":"Summer.fi, a DeFi yield-optimization platform formerly known as Oasis.app that spun out of the Maker Foundation in 2021, operated the DAO-governed Lazy Summer Protocol until a July 6, 2026 exploit drained roughly $6.04 million from two of its USDC vaults via a flash-loan-funded share-price manipulation of the Fleet Commander accounting contract. Summer.fi's own post-mortem attributes the loss to an operational oversight — an old, capped strategy that was never fully removed from vault net-asset-value calculations — rather than a smart-contract bug or compromised keys. The Summer.fi Labs company announced on July 15, 2026 that it would wind down and shut off its app by August 31, 2026, leaving user compensation and the fate of roughly $4 million in illiquid affected-vault holdings to a future Lazy Summer DAO governance vote.","timeline":[{"date":"2021-06-01","event":"Oasis.app (later Summer.fi) spins out as an independent entity following the decentralization of the Maker Foundation.","source":"Summer.fi official blog","source_url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"date":"2023-06-01","event":"Oasis.app rebrands to Summer.fi, expanding beyond its Maker-centric roots into a multi-protocol yield platform.","source":"Summer.fi official blog","source_url":"https://blog.summer.fi/oasis-app-rebrands-to-summer-fi/"},{"date":"2026-04-06","event":"Attacker allegedly begins funding multiple wallets used later in the exploit, according to Summer.fi's post-mortem on-chain analysis.","source":"Summer.fi post-mortem blog","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"At approximately 05:17 UTC, an attacker executes a single atomic transaction using a ~$65.4M flash loan to manipulate Fleet Commander vault share pricing, redeeming ~$70.9M against ~$64.8M deposited and netting roughly $6.04M in stolen USDC across two vaults.","source":"Summer.fi post-mortem blog / The Block","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"Blockaid flags the exploit at approximately 05:36 UTC; Summer.fi zeroes deposit caps by 06:42 UTC and pauses Ethereum/Base vaults by 10:25 UTC, then Arbitrum/Sonic vaults by 11:38 UTC.","source":"Summer.fi post-mortem blog","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"News outlets including CoinDesk and The Block report the exploit and Summer.fi's vault pause.","source":"CoinDesk / The Block","source_url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"date":"2026-07-15","event":"Summer.fi Labs announces it will wind down the company and shut off the Summer.fi app by August 31, 2026, citing the exploit's financial impact.","source":"Summer.fi official blog","source_url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"date":"2026-08-31","event":"Planned date for the Summer.fi application and support channels to cease operating.","source":"Summer.fi official blog","source_url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 090e9107-38f0-459e-b92f-56b4fc540f52
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.