The DeFi protocol Summer.fi (formerly known as Oasis.app) suffered a targeted hacker attack, resulting in the theft of over $6 million. The incident was detected on Monday morning by the security systems of Blockaid, Certik, PeckShield, and BlockSec, which promptly disclosed the details of the breach.

Attack Scheme and Vulnerable Points

Transaction analysis shows that the attacker used a complex multi-stage scheme. The key vulnerability was an error in position valuation within the Ark integrations of the Summer.fi protocol. The MorphoV2VaultArk and SiloManagedVaultArk components incorrectly calculated asset values using the spot exchange rate of underlying vaults. This allowed the hacker to artificially inflate the totalAssets indicator in one transaction and then transfer this distortion to the FleetCommander accounting.

Before the main attack, the attacker accumulated a large volume of outdated vgUSDC tokens, almost for free, which became an important element for the subsequent distortion of share prices. Then, using a $65.4 million flash loan from Morpho, they manipulated liquidity. The scheme included three stages: redistributing funds in vaults to distort share pricing, making a deposit to obtain an inflated share of participation, and finally withdrawing funds against the inflated asset accounting of FleetCommander.

Affected Assets and Market Reaction

The main affected vault was LazyVault_LowerRisk_USDC (LVUSDC), monitored by Block Analitica. After the attack, the displayed yield (APY) within this vault briefly reached an astronomical 2.08 million. The SUMR token, the native asset of the Summer.fi ecosystem, reacted with a 5.3% drop over the day, trading near $0.00193. Notably, the global market grew by more than 1% over the same period, highlighting the local nature of the negative impact.

Expert opinion: This incident is a vivid example of how the complexity of DeFi protocols becomes their Achilles' heel. The vulnerability related to incorrect position valuation in integrations is not just a bug but a systemic issue that requires developers to conduct more thorough audits of pricing mathematical models. The market must consider that such attacks will recur, and the cost of security in DeFi will only increase.