The DeFi protocol Summer.fi (formerly Oasis.app) has suffered a targeted hacker attack. Preliminary estimates indicate losses have already exceeded $6 million. The incident was recorded on Monday morning by monitoring systems of leading blockchain analysts, including Blockaid, Certik, PeckShield, and BlockSec.

Security experts quickly disclosed the key addresses involved in the attack: the attacker's address, the exploit smart contract, as well as the vulnerable Summer.fi and Lazy Summer contracts. The main blow fell on the LazyVault_LowerRisk_USDC (LVUSDC) vault, whose risks are monitored by Block Analitica. According to PeckShield analysts, after the attack, the displayed yield (APY) within this vault briefly reached astronomical values — 2.08 million percent.

Certik researchers identified that the attacker used a flash loan of $65.4 million to manipulate liquidity. According to BlockSec Phalcon, the attack itself was carried out in three stages:

  • First stage: The hacker accumulated a large volume of outdated vgUSDC tokens, likely almost for free, and initiated a redistribution of funds in the vaults, artificially distorting the pricing of shares in underlying pools.
  • Second stage: Using the distorted prices, the attacker made a deposit, receiving an inflated share of participation in the protocol.
  • Third stage: In the final stage, he withdrew funds against the inflated asset accounting of FleetCommander, extracting money from the protocol.

The key vulnerability was the incorrect valuation of positions within the Ark integrations of the Summer.fi protocol. The MorphoV2VaultArk and SiloManagedVaultArk components valued positions through the spot exchange rate of underlying vaults, which allowed the attack to be carried out.

The market reaction was immediate: the native token SUMR fell by 5.3% over the day and was trading near $0.00193 at the time of analysis. Notably, the global market gained more than 1% over the same period.

This incident is the second crypto hack recorded in July. For comparison, in June, platforms lost $75.87 million as a result of 40 hacker attacks.

Expert opinion from Cryptalist

This case is a classic example of an attack on the pricing mechanism in complex DeFi protocols. The use of flash loans to manipulate oracles and liquidity shares is becoming increasingly sophisticated. Projects, especially those building multi-layered integrations like Lazy Summer, need to prioritize auditing the logic of asset valuation, not just the security of individual smart contracts. The Summer.fi incident is a serious wake-up call for the entire DeFi sector.