Summer.fi Loses $6M as Flash Loan Exploit Inflates APY to 2,080,000%

Summer.fi Loses $6M as Flash Loan Exploit Inflates APY to 2,080,000%

N
News Editor 01
2026-07-24 03:05:17
DeFi protocol Summer.fi lost $6 million in DAI after a flash loan attack manipulated vault pricing. The attacker borrowed $65.4 million to inflate APY briefly, triggering unauthorized withdrawals. Security firms are investigating but the attacker remains unidentified.

DeFi protocol Summer.fi is investigating a $6 million exploit that compromised one of its so-called low-risk automated vaults. Blockchain security firms Blockaid, PeckShield, and CertiK confirmed that the attacker used a $65.4 million flash loan to manipulate liquidity and pricing inside the vault, then drained DAI stablecoins in a single transaction.

LazyVault_LowerRisk_USDC Pool Targeted

Summer.fi marketed the LazyVault_LowerRisk_USDC pool as a conservative investment product. Instead of attacking user wallets, the attacker tampered with internal liquidity and broke the pricing mechanism. As a result, the protocol briefly displayed an annual percentage yield of about 2,080,000%. That price anomaly created a narrow window to withdraw roughly $6 million in DAI. Although the abnormal reading lasted only briefly, the attacker completed the exploit before the protocol returned to normal operation.

Security firms detected suspicious activity within minutes and alerted the community. However, investigators have not identified the attacker nor confirmed any recovery of stolen assets.

Flash Loan Exploit Exposes Weaknesses in Automated Vaults

Unlike typical crypto thefts, this attack did not rely on stolen keys or compromised wallets. Flash loans allow borrowing large sums without collateral as long as they are repaid within the same transaction. The attacker borrowed about $65.4 million to distort liquidity inside the affected vault, temporarily inflating the displayed APY. The protocol then allowed unauthorized withdrawals based on the manipulated data.

This incident highlights risks inherent in automated yield vaults that depend on real-time pricing. Even products labeled low-risk can become vulnerable when valuation models fail under extreme conditions.

Another Setback for Summer.fi's Multichain Ecosystem

Summer.fi (formerly Oasis.app) operates across Ethereum, Base, and Arbitrum. Over the past year, it has faced several operational and security incidents, including frozen withdrawals after the USDX stablecoin depeg, a close call with an rsETH exploit, and a blocked malicious governance proposal that tried to abuse outdated permissions. Although each incident differed in execution, they all exposed risks within the protocol's infrastructure. The latest attack will likely intensify scrutiny of Summer.fi's security architecture and vault design.

DeFi Security Losses Continue to Climb in 2026

The Summer.fi exploit mirrors a broader trend in decentralized finance. Cybercriminals are increasingly targeting lending platforms, automated vaults, and liquidity protocols with sophisticated methods. Industry analysts estimate that DeFi-related hacks had already caused over $840 million in losses before Q3 2026, with April alone accounting for more than $640 million — making it the costliest month so far this year. Flash loan exploits remain a core challenge despite stronger monitoring, underscoring the need for resilient pricing systems and better safeguards for automated investment products.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.