The DeFi protocol Summer.fi, formerly known as Oasis.app, has fallen victim to a targeted hacker attack. According to preliminary data, losses from the exploit have already exceeded $6 million. The incident was recorded on Monday morning by monitoring systems of leading analytical platforms, including Blockaid, Certik, PeckShield, and BlockSec.

Security experts quickly disclosed key details of the attack, including the attacker's address, the exploit smart contract, and vulnerable contracts within the Lazy Summer ecosystem. Among the affected contracts are Summer.fi and Lazy Summer, as well as the LazyVault_LowerRisk_USDC (LVUSDC) vault, whose risks were monitored by the Block Analitica platform.

Technical Details: Liquidity Manipulation and Flash Loan

Analysis conducted by blockchain researchers revealed that the primary cause of the attack was a vulnerability in position valuation within the Ark integrations of the Summer.fi protocol. The MorphoV2VaultArk and SiloManagedVaultArk components apparently assessed positions based on the spot exchange rate of underlying vaults.

The attacker exploited this vulnerability to artificially inflate the reported totalAssets value within a single transaction, then transferred this distortion to the FleetCommander accounting. Notably, before the main attack, the hacker accumulated a large volume of outdated vgUSDC tokens, likely almost for free, which became a key element for the subsequent share price manipulation.

According to BlockSec Phalcon's estimates, the attack unfolded in three stages. First, the attacker triggered a redistribution of funds within the vaults, distorting the pricing of shares in underlying vaults. Then, they made a deposit to receive an inflated share of participation. In the final stage, they withdrew funds against the inflated asset accounting of FleetCommander, extracting money from the protocol.

Certik researchers also reported the use of a $65.4 million flash loan to manipulate liquidity. Following the attack, the displayed yield (APY) within the LVUSDC vault briefly reached 2.08 million.

Market Reaction and Context

The SUMR token, the native asset of the Summer.fi ecosystem, reacted to the incident with a 5.3% decline over 24 hours, trading near $0.00193. Notably, the global market gained over 1% during the same period, highlighting the local nature of the negative pressure.

This incident is the second major crypto hack recorded in July. For comparison, in June, a series of 40 hacker attacks resulted in crypto platforms losing $75.87 million, with the majority of funds lost due to the Humanity Protocol (H) incident.

Expert Opinion: This exploit is a vivid example of how the complexity of integrations in DeFi becomes the Achilles' heel of protocols. The vulnerability in position valuation based on the spot rate rather than internal accounting is a classic architectural error that can be exploited for manipulation. The Summer.fi incident once again underscores the critical need for thorough auditing and stress testing of all interaction points between components of the DeFi ecosystem.