DeFi protocol Summer Finance exploited for $6 million; analysts point to flash loan attack
·2 min read
Compiled by KHAO Editorial
— aggregated from 1 source + 9 references discovered via search.
See llms.txt for citation guidance.
★ Tier-1 Source
Summer Finance, a DeFi yield-optimization protocol also known as Summer.fi, has been exploited for $6 million, according to onchain analysts.
Key facts
Meanwhile, CertiK further explained that the attacker used a $65.4 million flash loan to attain a $70.9 million redemption by manipulating how Summer
Attacker could redeem $70.9M following a $64.8M deposit thanks to manipulation of FleetCommander's accounting of totalAssets on a host of vaults, particularly Silo: Varlamore USDC Growth
Summer Finance, a DeFi yield-optimization protocol also known as Summer.fi, has been exploited for $6 million, according to onchain analysts
Cyvers wrote in an X post that the attacker seemingly targeted a share accounting vulnerability through price manipulation, swapped the stolen $6 million to DAI stablecoins, and moved the funds
Summary
Blockchain security firm Blockaid flagged the security breach early Monday morning, while other analysts followed up with further details. Cyvers wrote in an X post that the attacker seemingly targeted a share accounting vulnerability through price manipulation, swapped the stolen $6 million to DAI stablecoins, and moved the funds to an attacker-controlled address. Meanwhile, CertiK further explained that the attacker used a $65.4 million flash loan to attain a $70.9 million redemption by manipulating how Summer.fi's Lazy Summer Protocol accounted for assets in its vaults. "Attacker could redeem $70.9M following a $64.8M deposit thanks to manipulation of FleetCommander's accounting of totalAssets on a host of vaults, particularly Silo: Varlamore USDC Growth, which the attacker had accumulated beforehand and donated to the Ark in between," CertiK wrote.