Summer.fi Loses About $6 Million in Flash Loan Exploit as Funds Move Through Tornado Cash

Summer.fi Loses About $6 Million in Flash Loan Exploit as Funds Move Through Tornado Cash

N
News Editor 01
2026-07-22 12:35:13
Summer.fi was hit by a July 6 exploit that used a flash loan of more than $65 million USDC to manipulate vault accounting and drain about 6.017 million DAI. On-chain tracking shows part of the funds has already been swapped to ETH and sent to Tornado Cash.
Summer.fiDeFi securityflash loan exploitTornado Cashon-chain tracking

Summer.fi suffered a major security breach on July 6, 2026, with attackers stealing roughly $6 million from the DeFi platform’s automated asset management system. Security firm Blockaid identified the incident early in the day, and the affected component was the platform’s Lazy Summer Protocol.

Vault accounting was manipulated through an ERC-4626 exploit path

According to the source material, the attacker used a flash loan of more than $65 million in USDC to distort vault accounting inside special ERC-4626 contracts. That temporary capital injection created an artificial balance inside the system, which then allowed the exploiter to redeem extra shares and extract profit.

The funds taken amounted to about 6 million DAI from automated yield vaults. The report says the incident highlights how flash loans can abuse vault logic when protocols interact with systems such as Morpho, Curve, and Uniswap.

Summer.fi paused Lazy Summer vaults across all networks

After the exploit became clear, the team halted all Lazy Summer vaults on every network and set deposit limits to zero to prevent additional losses. Users were also told to stop interacting with the protocol while the investigation continues.

The market reaction was immediate. Summer.fi’s native token SUMR fell by more than 18% shortly after news of the breach spread.

On-chain data shows DAI being split, swapped, and mixed

Tracking data cited from Onchain Lens shows the attacker actively moving the stolen assets. The stolen 6.017 million DAI has been broken into smaller transactions and routed through a single intermediate wallet, a step that makes the transfer path less transparent.

Inside that wallet, the DAI is swapped for ETH on Uniswap. The ETH is then sent into Tornado Cash in batches of 10 ETH each. Once funds enter a mixer, following the trail becomes much harder.

At the time described in the material, 40 ETH had already been deposited into Tornado Cash, valued there at about $71,800, while another 26 ETH remained in the intermediate wallet. The rest of the illicit funds was still moving on-chain, complicating efforts to trace, freeze, or recover the assets.

No compensation plan yet as recovery options remain open

No official reimbursement plan has been announced for affected users. The report says the remaining stolen funds are still sitting in the attacker’s main wallet. It also notes that firms including CertiK, PeckShield, and Blockaid are expected to carry out forensic analysis that may support the Summer.fi team.

The source says the team may consider offering a whitehat bounty to the attacker in exchange for returning the funds. It also mentions the possibility of using on-chain tools to freeze assets that have not yet entered Tornado Cash. Whether a governance vote will be proposed to repay victims through treasury reserves or a new token structure remains unresolved in the report.

A full financial audit from a major accounting firm is presented as the next key step. That review is expected to shape both the handling of user losses and the protocol’s future security upgrades.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.