Summer.fi got hit for about $6 million in what security firms are calling an active exploit. Blockaid raised the alarm Monday morning, publishing the attacker’s wallet, exploit contract, and affected vault addresses.
The main target was LazyVault_LowerRisk_USDC (LVUSDC), which Block Analitica risk-manages. PeckShield noted the vault’s displayed APY briefly hit an absurd 2.08 million %. The largest holder appears to be linked to Torben Jorgensen (UDHC), who’d deposited around 8.6 million USDC.
Key on-chain details:
- Exploiter: 0x7BF716167B48CF527725722C6d79494b45B3BDCa
- Exploit contract: 0x0514F827C129C16418a0933E03C99A6AF982FC61
- Affected vaults: 0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17, 0xA9ca4909700505585B1aD2a1579dA3b670FFA9c4, 0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06
Summer.fi (formerly Oasis.app) sits on the Lazy Summer Protocol, an onchain vault system that auto-routes deposits across DeFi yield sources like Aave and Morpho. The native SUMR token fell 5.3% to $0.00193, diverging from a market that climbed over 1%.
This is July’s second exploit. June saw $75.87 million lost across 40 hacks. Developing story — we’ve asked Summer.fi for comment.
