Summer.fi loses $6M in flash loan exploit on vault logic

Summer.fi lost $6M in a flash loan exploit that manipulated vault accounting logic, exposing vulnerabilities in its automated DeFi systems. The attacker used $65.4M in borrowed funds to drain DAI.

Summer.fi, a DeFi yield-optimization platform, recently suffered a significant exploit resulting in the loss of approximately $6 million, mainly in DAI. The attack was detected by Blockaid and involved a $65.4 million flash loan in USDC and USDT, which was repaid within a single transaction. The attacker manipulated the protocol’s accounting logic, specifically within the Lazy Summer Protocol and related vaults, to redeem assets on favorable terms. Funds were routed through Morpho vaults, Curve pools, and various vault functions before being converted to DAI and sent to an address controlled by the attacker. Importantly, the exploit did not involve compromised private keys or admin privileges. Instead, it targeted vulnerabilities in the platform’s automated vault management and accounting mechanisms. As of reporting, Summer.fi had not released a full public response, and the root cause was still under investigation. This incident underscores the persistent risks in complex DeFi automation and vault logic.

Related Tokens

Related News