Skip to main content
Sign in
Summer.fi1 decision on this page

Audit log

Every state-changing event for Summer.fi: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-25 12:18:51Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    3LZz5Nyo4Aps…yb7AFDQGsha256 → base58
    verifying row…
    canonical bytes (23486 B) ▸
    {"actor":"system:backfill","investigation_id":"89db5df3-1d24-4420-8518-f09e5bb3f720","kind":"publish","page_slug":"summer-fi","published_at":"2026-07-25T12:18:51.116Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Summer.fi","sections":[{"content":"On July 6, 2026, an attacker exploited two Lazy Summer Protocol USDC vaults on Ethereum mainnet in a single atomic transaction, extracting approximately $6.04 million in depositor funds. The attack was detected at 05:36 AM UTC by blockchain security firm Blockaid. The attacker used a flash loan of approximately $65.4 million in USDC sourced through Morpho to manipulate the vault share pricing mechanism. The exploit targeted a flaw in the FleetCommander contract, which sits above a set of strategy adapters called Arks. Vault share prices are derived from the sum of total assets reported by all active Arks. An Ark designated for offboarding had its deposit cap set to zero but remained counted in the vault's net asset value calculation. The attacker deposited approximately $64.8 million USDC at the true share price of approximately 1.0665 USDC per share, then donated overvalued Silo 'Varlamore USDC Growth' tokens into the capped Ark, artificially inflating reported NAV by approximately 9.5% with no real backing. Shares were then redeemed at the inflated price of approximately 1.1678 USDC per share, extracting approximately $70.9 million before repaying the flash loan. The two affected vaults were LazyVault_LowerRisk_USDC (loss of approximately $5.64 million) and LazyVault_HigherRisk_USDC (loss of approximately $0.40 million). Extracted funds came from other depositors' liquid positions in Morpho, Spark, and Sky Arks. The stolen USDC was converted to DAI on Curve before being transferred to the attacker's wallet.","heading":"July 2026 Exploit: Flash Loan Attack on Lazy Summer Protocol","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem: What Happened and What Comes Next - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit - CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million - The Block","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss - Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"}]},{"content":"The Summer.fi post-mortem directly traced the root cause of the exploit to mispriced assets left behind after Stream Finance's collapse in November 2025. On November 4, 2025, Stream Finance disclosed that an external fund manager had lost approximately $93 million in assets, triggering an estimated $285 million in cascading DeFi losses. The yield-bearing token xUSD fell 77% within 24 hours, freezing approximately $160 million in user deposits. The Stream Finance collapse left Silo 'Varlamore USDC Growth' market tokens reporting stale on-chain valuations that were never marked down to reflect reality, even as interest continued to accrue on stranded USDC. Lazy Summer Protocol's Ark for these Silo tokens had its deposit cap zeroed as part of post-2025 cleanup, but zeroing caps blocks only new inflows. The impaired market remained priced into vault NAV calculations during the deactivation-to-removal window -- the precise vulnerability exploited. The Summer.fi post-mortem confirmed: 'Donating an over-valued token into any Ark that is still in the active set raises the vault's totalAssets(), and therefore its share price, with no real assets behind the increase.' The eight-month window between the Stream Finance collapse and the July 2026 exploit represented a period during which the stale valuation was present in the system but not remediated.","heading":"Root Cause: Stale Silo Token Valuations from Stream Finance Collapse","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"credibility":2,"name":"Anatomy of a $285M DeFi Contagion: The Stream Finance xUSD Collapse - BlockEden","type":"news_article","url":"https://blockeden.xyz/blog/2025/11/08/m-defi-contagion/"}]},{"content":"The Summer.fi post-mortem stated that evidence points to an operation planned at least three months in advance. The attacker funded multiple wallets through identical paths in early April 2026, then systematically accumulated the Silo tokens that became the attack lever across multiple addresses to obscure the accumulation pattern. This demonstrated deliberate preparation rather than opportunistic exploitation of a publicly known vulnerability. The entire attack executed in a single atomic transaction using approximately $65 million in flash-loaned stablecoins. Summer.fi's security partners, including SEAL 911, conducted on-chain tracing of the attacker's wallet movements following the exploit.","heading":"Premeditated Attack: Evidence of Three-Month Planning","severity":"critical","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"}]},{"content":"Following the exploit, the attacker converted stolen USDC to approximately 6.017 million DAI on Curve. The attacker then swapped DAI to ETH via Uniswap through intermediary wallets and routed the proceeds through Tornado Cash, a cryptocurrency mixer subject to U.S. Treasury OFAC sanctions, in batches of 10 ETH. Approximately $1.35 million was confirmed as laundered through Tornado Cash as of reporting by The Defiant and CryptoBriefing in early July 2026, with approximately 4.67 million DAI reported as remaining in the exploiter's primary wallet at that time. Summer.fi stated in its post-mortem that fund tracing 'breaks down' once assets are swapped out of stablecoins and deposited into a mixer. Security partners including SEAL 911 continued to trace the remaining funds. The use of Tornado Cash significantly complicates law enforcement recovery efforts.","heading":"Fund Laundering via Tornado Cash","severity":"critical","sources":[{"credibility":2,"name":"Summer.fi hacker launders $1M through Tornado Cash - CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/summer-fi-hacker-launders-tornado-cash/"},{"credibility":2,"name":"Summer.fi Hacker Moves $1.35M Into Tornado Cash - The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/summer-fi-hacker-moves-1-35m-into-tornado-cash"},{"credibility":3,"name":"Summer.fi Hacked: $6M Stolen as Funds Vanish Into Tornado Cash - MEXC News","type":"news_article","url":"https://www.mexc.com/news/1198957"}]},{"content":"Following detection by Blockaid at 05:36 AM UTC on July 6, 2026, Block Analitica froze deposits on the affected vaults at 06:42 AM UTC. The Guardian Multisig executed emergency actions at 10:25 AM UTC, setting all DAO-managed vault deposit caps to zero, pausing all Ethereum vaults, and pausing vaults on Base, Arbitrum, and Sonic as a precaution. At 16:39 PM UTC, the Foundation Multisig swept the donated Silo tokens from the vault to prevent continued NAV distortion. The Guardian Module operates under narrowly scoped authority: it can only pause vaults, override deposit caps, and cancel governance proposals -- it cannot move user funds. Security firms PeckShield and CertiK also independently reported the suspicious activity. All vaults remained paused pending DAO governance decisions on compensation methodology, remediation of affected vaults, and removal of obsolete Arks from active fleet calculations.","heading":"Protocol Response and Guardian Actions","severity":"high","sources":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit - CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"}]},{"content":"Summer.fi announced the permanent shutdown of both its user interface and Summer.fi Labs following the exploit. The official blog post stated: 'The financial hit was immediate and personal: a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild.' The company explored alternatives but determined shutdown was the only viable path given market conditions and the loss of operational capital. The Summer.fi application was scheduled to remain accessible through August 31, 2026, with customer support available via email and Discord through the same date. After August 31, responsibility for the Lazy Summer Protocol infrastructure was to transfer entirely to the Lazy Protocol DAO, which would govern vault recovery decisions. The SUMR governance token fell over 18% following the exploit announcement. Approximately $4 million in user assets remained outstanding and temporarily illiquid as of reporting, with no guarantee of full compensation provided by the company; any recovery plan required DAO governance decisions. The shutdown represented the end of approximately seven years of continuous operation, with the platform tracing its origins to MakerDAO's original DeFi frontend.","heading":"Permanent Shutdown of Summer.fi and Labs","severity":"critical","sources":[{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":2,"name":"SummerFi DeFi Shutdown: $6M Exploit Ends 7 Years of Building - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/summerfi-defi-shutdown/"},{"credibility":2,"name":"Summer.fi Confirms Shutdown Following Major USDC Vault Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/summer-fi-confirms-shutdown-following-exploit/"},{"credibility":2,"name":"Summer.fi shuts down after exploit - Bitget News","type":"news_article","url":"https://www.bitget.com/asia/news/detail/12560605509769"}]},{"content":"Following the exploit and subsequent vault pauses, users were unable to access their funds in Lazy Summer Protocol vaults. Approximately $4 million in user assets remained outstanding and temporarily illiquid as of reporting. Summer.fi Labs provided no guarantee of full compensation to affected depositors. Any recovery plan and timeline were contingent on decisions by the Lazy Protocol DAO, which was working through governance processes to resume withdrawals and redemptions across all paused vaults, including the two directly exploited vaults. Depositors in the two exploited vaults faced direct losses of approximately $6.04 million total, while depositors in non-exploited paused vaults faced temporary illiquidity pending DAO action. The company characterized its decision to shut down as unavoidable given the elimination of operational runway caused by the exploit affecting the team's own capital held in the affected vaults.","heading":"Depositor Impact and Outstanding Liabilities","severity":"high","sources":[{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":2,"name":"Summer.fi Confirms Shutdown Following Major USDC Vault Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/summer-fi-confirms-shutdown-following-exploit/"},{"credibility":2,"name":"$6 Million Vault Exploit Forces DeFi Platform Summer.fi to Wind Down - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/46710-summer-fi-shutdown-lazy-summer-exploit"}]},{"content":"Summer.fi operated as one of DeFi's longest-running protocol frontends. The platform originated within the Maker Foundation as the original frontend for the Maker Protocol, with roots as OasisDEX dating to 2016. Following the decentralization of the Maker Foundation, the platform was spun out into an independent entity in 2021. In June 2023, the platform rebranded from Oasis.app to Summer.fi to reflect its expansion beyond MakerDAO into a multi-protocol ecosystem supporting Aave, Morpho, Compound, and other protocols. In early 2025, Summer.fi launched the Lazy Summer Protocol, an automated yield vault product that rebalanced positions across lending protocols to optimize risk-adjusted returns. The SUMR governance token was introduced in January 2026. At its peak, the platform reportedly reached $200 million in total value locked. Prior to the exploit, the protocol held approximately $22 million in TVL according to DeFiLlama data. No prior security incidents were identified in available reporting before the July 2026 exploit.","heading":"Background and Operational History","severity":"low","sources":[{"credibility":1,"name":"The story of DeFi's original frontend - Summer.fi Blog","type":"official","url":"https://blog.summer.fi/the-story-of-defis-original-frontend/"},{"credibility":2,"name":"Shaping DeFi's Horizon: A Conversation with Chris Bradbury, CEO of Summer.fi - CoinCodex","type":"news_article","url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"credibility":2,"name":"Summer.fi Confirms Shutdown Following Major USDC Vault Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/summer-fi-confirms-shutdown-following-exploit/"}]}],"sources_used":[{"credibility":1,"name":"Lazy Summer USDC Vault Exploit Post-Mortem - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"credibility":1,"name":"Sunsetting Summer.fi and the Labs Company - Summer.fi Official Blog","type":"official","url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"},{"credibility":1,"name":"The story of DeFi's original frontend - Summer.fi Blog","type":"official","url":"https://blog.summer.fi/the-story-of-defis-original-frontend/"},{"credibility":1,"name":"DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit - CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"credibility":1,"name":"DeFi protocol Summer Finance exploited for $6 million - The Block","type":"news_article","url":"https://www.theblock.co/post/407198/summer-finance-exploited"},{"credibility":2,"name":"$6M Lazy Summer Exploit Traces Back to November's Stream Finance Collapse - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"credibility":2,"name":"Summer.fi hacker launders $1M through Tornado Cash - CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/summer-fi-hacker-launders-tornado-cash/"},{"credibility":2,"name":"Summer.fi Hacker Moves $1.35M Into Tornado Cash - The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/summer-fi-hacker-moves-1-35m-into-tornado-cash"},{"credibility":2,"name":"SummerFi DeFi Shutdown: $6M Exploit Ends 7 Years of Building - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/summerfi-defi-shutdown/"},{"credibility":2,"name":"Summer.fi Confirms Shutdown Following Major USDC Vault Exploit - Crypto Economy","type":"news_article","url":"https://crypto-economy.com/summer-fi-confirms-shutdown-following-exploit/"},{"credibility":2,"name":"Summer Finance Pauses Vaults After $65.4M Flash Loan Attack - Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/"},{"credibility":2,"name":"Anatomy of a $285M DeFi Contagion: The Stream Finance xUSD Collapse - BlockEden","type":"news_article","url":"https://blockeden.xyz/blog/2025/11/08/m-defi-contagion/"},{"credibility":2,"name":"Just-In: Summer.fi Hit By Suspected $6M Flash Loan Exploit - CoinGape","type":"news_article","url":"https://coingape.com/summer-fi-hit-by-suspected-6m-flash-loan-exploit-as-defi-vaults-targeted/"},{"credibility":2,"name":"Summer.fi shuts down after exploit - Bitget News","type":"news_article","url":"https://www.bitget.com/asia/news/detail/12560605509769"},{"credibility":2,"name":"$6 Million Vault Exploit Forces DeFi Platform Summer.fi to Wind Down - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/46710-summer-fi-shutdown-lazy-summer-exploit"},{"credibility":2,"name":"Shaping DeFi's Horizon: A Conversation with Chris Bradbury, CEO of Summer.fi - CoinCodex","type":"news_article","url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"credibility":3,"name":"Summer.fi Hacked: $6M Stolen as Funds Vanish Into Tornado Cash - MEXC News","type":"news_article","url":"https://www.mexc.com/news/1198957"}],"summary":"Summer.fi (formerly Oasis.app) was a DeFi frontend and yield protocol platform with roots in the original MakerDAO ecosystem, operating for approximately seven years before shutting down in 2026. On July 6, 2026, an attacker exploited a share-accounting vulnerability in its Lazy Summer Protocol vaults via a $65.4 million flash loan, stealing approximately $6.04 million in depositor funds; the root cause was traced to stale Silo token valuations inherited from the November 2025 Stream Finance collapse. Following the exploit, Summer.fi Labs announced the permanent shutdown of operations, with the application scheduled to remain accessible through August 31, 2026 pending DAO-governed recovery of affected vault funds estimated at approximately $4 million.","timeline":[{"date":"2016-01-01","event":"OasisDEX launched as the original MakerDAO frontend, one of DeFi's earliest protocol interfaces.","source":"Summer.fi Blog","source_url":"https://blog.summer.fi/the-story-of-defis-original-frontend/"},{"date":"2021-01-01","event":"Platform spun out from the Maker Foundation as an independent entity following MakerDAO decentralization.","source":"Summer.fi Blog","source_url":"https://blog.summer.fi/the-story-of-defis-original-frontend/"},{"date":"2023-06-01","event":"Oasis.app rebranded to Summer.fi to reflect expansion beyond MakerDAO into a multi-protocol ecosystem.","source":"CoinCodex","source_url":"https://coincodex.com/article/31177/shaping-defis-horizon-a-conversation-with-chris-bradbury-ceo-of-summerfi"},{"date":"2025-01-01","event":"Lazy Summer Protocol launched as an automated yield vault product rebalancing across DeFi protocols.","source":"Summer.fi Official","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2025-11-04","event":"Stream Finance collapsed after disclosing approximately $93 million in losses by an external fund manager, triggering an estimated $285 million in DeFi contagion. Silo 'Varlamore' token valuations were never marked down following this collapse, creating the future exploit vector for Summer.fi.","source":"BlockEden / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/08/6m-lazy-summer-exploit-traces-back-to-novembers-stream-finance-collapse/"},{"date":"2026-01-01","event":"SUMR governance token introduced for the Lazy Summer Protocol.","source":"Summer.fi Official","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-04-01","event":"Alleged attacker began pre-positioning: funding multiple wallets through identical paths and systematically accumulating Silo tokens that would become the attack lever, per Summer.fi post-mortem on-chain analysis.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-06","event":"Exploit detected at 05:36 AM UTC: attacker used approximately $65.4 million flash loan via Morpho to manipulate Lazy Summer vault share accounting, extracting $6.04 million from two USDC vaults (LazyVault_LowerRisk_USDC: $5.64M; LazyVault_HigherRisk_USDC: $0.40M) in a single atomic transaction. Stolen USDC converted to DAI on Curve.","source":"CoinDesk / Summer.fi Post-Mortem","source_url":"https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit"},{"date":"2026-07-06","event":"Guardian Multisig paused all Ethereum vaults by 10:25 AM UTC and all vaults across Base, Arbitrum, and Sonic as precaution. Foundation Multisig swept donated Silo tokens from vault by 16:39 PM UTC. SUMR token declined over 18% following public disclosure.","source":"Summer.fi Official Blog (Post-Mortem)","source_url":"https://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/"},{"date":"2026-07-09","event":"Approximately $1.35 million of stolen funds confirmed laundered through Tornado Cash via ETH batches after DAI-to-ETH swap on Uniswap. Approximately $4.67 million DAI reported remaining in exploiter wallet.","source":"The Defiant / CryptoBriefing","source_url":"https://cryptobriefing.com/summer-fi-hacker-launders-tornado-cash/"},{"date":"2026-07-20","event":"Summer.fi confirmed permanent shutdown of both the user interface and Summer.fi Labs. Application to remain accessible through August 31, 2026; governance to transfer to Lazy Protocol DAO. Approximately $4 million in user assets remained temporarily illiquid with no guaranteed compensation.","source":"Cryptonomist / Summer.fi Blog","source_url":"https://en.cryptonomist.ch/2026/07/20/summerfi-defi-shutdown/"},{"date":"2026-08-31","event":"Planned final date for Summer.fi application access and customer support. After this date, protocol governance to be handled exclusively by Lazy Protocol DAO.","source":"Summer.fi Official Blog","source_url":"https://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 6047a4f7-9fb1-44e8-a0a5-136d72b1d375
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.