← Radar

Incident case file

Sign in to watch

Summer.fi Lazy Summer Protocol — Flash Loan NAV Manipulation

Incident date July 6, 2026

0 views

ContainedEthereumFlash Loan / NAV ManipulationCluster: SUMMERFI-NAVMANIP-2026-07

Estimated loss

$6.0M

Victims identified

258
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0x7BF716167B48CF527725722C6d79494b45B3BDCa (labeled 'Summer.fi Exploiter 1' by Etherscan). Exploit contract: 0x0514F827C129C16418a0933E03C99A6AF982FC61 (labeled 'Summer.fi Exploiter 2' by Etherscan).

Funds moved to: Approximately $6.04M drained via a single atomic transaction (0x0db528c44f23fc7fa4544684a2fab81096450a14aae8bc89f42cd0592d43da12, block 25471348, 05:17:59 UTC July 6), converted to DAI on Curve. Attacker funded initially via FixedFloat (early April 2026); proceeds exited via Tornado Cash through intermediary 0x46e09c4d4d20c0474598b4d2ffdd08bdf416eba7. Attacker retains 20,947.68 residual LVUSDC vault shares (0.22%), likely frozen by the Guardian Module.
Vault LVUSDC (LazyVault_LowerRisk_USDC): 0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17 — 258 on-chain holders, extreme concentration (top 5 holders = 97.03% of supply). Vault HigherRisk_USDC: 0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06. Guardian multisig (8 signers, 6-of-8 threshold, first used in April 2026 to block a separate governance attack): 0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4. Largest holder: 0x8741e8ff675accb88be2886415292fc9f4984130, linked to Torben Jorgensen (UDHC), holding 77.65

Timeline: July 6, 2026, 05:17:59 UTC: attacker executes a single atomic transaction — donates stale-valued Silo 'Varlamore USDC Growth' vault tokens (mispriced on-chain since the November 2025 Stream Finance collapse) into a deposit-capped Ark still counted in NAV calculations, inflating vault NAV by ~9.5%; borrows a ~$65.4M flash loan via Morpho; redeems shares at the inflated price of ~1.1678 USDC/share versus the true ~1.0665 USDC/share, netting ~$6.04M ($5.64M from the lower-risk vault, $0.40M from the higher-risk vault). 05:36 UTC: Blockaid detects and flags the live exploit. 06:42 UTC: Block Analitica freezes deposits on affected vaults. 07:39 UTC: SEAL 911 engaged. 07:52 UTC: first Guardian Safe multisig transaction. 09:48 UTC: on-chain message sent to the attacker's address from the Lazy Summer deployer. 10:25 UTC: deposit caps set to zero on DAO-managed vaults, Ethereum and Base vaults paused. 11:38 UTC: Arbitrum and Sonic vaults paused as a precaution. 16:39 UTC: Foundation Multisig sweeps remaining Silo Varlamore shares out of the affected vault. 17:16 UTC: Summer.fi contacts FixedFloat regarding the attacker's initial funding. July 7, 2026: full official post-mortem published, confirming contracts behaved as coded and the root cause was a process failure (incomplete Ark offboarding), not a smart contract bug. July 8, 2026: further reporting traces the root cause directly to the November 2025 Stream Finance collapse. Compensation for affected depositors remains an open Lazy Summer DAO governance decision as of this report; no final per-depositor reconciliation has been published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)