DeFi protocol Summer.fi is investigating a $6 million exploit that compromised one of its so-called low-risk automated vaults. Blockchain security firms Blockaid, PeckShield, and CertiK confirmed that the attacker used a $65.4 million flash loan to manipulate liquidity and pricing inside the vault, then drained DAI stablecoins in a single transaction.
LazyVault_LowerRisk_USDC Pool Targeted
Summer.fi marketed the LazyVault_LowerRisk_USDC pool as a conservative investment product. Instead of attacking user wallets, the attacker tampered with internal liquidity and broke the pricing mechanism. As a result, the protocol briefly displayed an annual percentage yield of about 2,080,000%. That price anomaly created a narrow window to withdraw roughly $6 million in DAI. Although the abnormal reading lasted only briefly, the attacker completed the exploit before the protocol returned to normal operation.
Security firms detected suspicious activity within minutes and alerted the community. However, investigators have not identified the attacker nor confirmed any recovery of stolen assets.
Flash Loan Exploit Exposes Weaknesses in Automated Vaults
Unlike typical crypto thefts, this attack did not rely on stolen keys or compromised wallets. Flash loans allow borrowing large sums without collateral as long as they are repaid within the same transaction. The attacker borrowed about $65.4 million to distort liquidity inside the affected vault, temporarily inflating the displayed APY. The protocol then allowed unauthorized withdrawals based on the manipulated data.
This incident highlights risks inherent in automated yield vaults that depend on real-time pricing. Even products labeled low-risk can become vulnerable when valuation models fail under extreme conditions.
Another Setback for Summer.fi's Multichain Ecosystem
Summer.fi (formerly Oasis.app) operates across Ethereum, Base, and Arbitrum. Over the past year, it has faced several operational and security incidents, including frozen withdrawals after the USDX stablecoin depeg, a close call with an rsETH exploit, and a blocked malicious governance proposal that tried to abuse outdated permissions. Although each incident differed in execution, they all exposed risks within the protocol's infrastructure. The latest attack will likely intensify scrutiny of Summer.fi's security architecture and vault design.
DeFi Security Losses Continue to Climb in 2026
The Summer.fi exploit mirrors a broader trend in decentralized finance. Cybercriminals are increasingly targeting lending platforms, automated vaults, and liquidity protocols with sophisticated methods. Industry analysts estimate that DeFi-related hacks had already caused over $840 million in losses before Q3 2026, with April alone accounting for more than $640 million — making it the costliest month so far this year. Flash loan exploits remain a core challenge despite stronger monitoring, underscoring the need for resilient pricing systems and better safeguards for automated investment products.

