An automated vault operated by the Ethereum multi-chain protocol Summer.fi was attacked on Monday, resulting in the theft of approximately $6 million in DAI. On-chain security companies Blockaid, PeckShield, and CertiK subsequently disclosed the anomaly, stating that their teams have suspended the affected contracts but have not yet announced compensation arrangements.
Price within the Flash Loan Twisted Pool
The core of this attack was to distort the liquidity of the vault pool by using large flash loans. The attackers used approximately $65.4 million in flash loans to target a vault pool named LazyVault_LowerRisk_USDC.
The product was originally positioned as a low-risk strategy vault, with risk management handled by Block Analitica. During the attack, an algorithm malfunctioned within the pool, causing the displayed annualized yield to briefly surge to approximately 2.08 million. The attackers then exploited this price distortion to quickly withdraw user funds.
The main losses were concentrated in LVUSDC
PeckShield stated that the primary affected entity is Summer.fi's LVUSDC vault. On-chain data shows that one of the largest related addresses appears to be linked to Torben Jorgensen, co-founder of the Web3 company UDHC.
- The flash loan amounted to approximately $65.4 million.
- Approximately $6 million in assets were transferred out of DAI.
- The abnormal annualized rate once rose to approximately 2.08 million%.
The report mentioned that the address deposited approximately 8.6 million USDC into the relevant pool shortly before the attack, subsequently becoming one of the biggest losers in the incident. The transferred DAI was quickly redeemed through the Uniswap V3 pool.
The agreement has encountered risk control issues multiple times in the past year.
This incident has also brought renewed market attention to the risks associated with Summer.fi's multi-chain infrastructure. The protocol currently covers Ethereum, Base, and Arbitrum. Over the past year, the protocol has experienced withdrawal freezes due to USDX de-pegging and narrowly escaped attack related to rsETH.
In addition, the team had previously intercepted a malicious governance proposal that attempted to influence the protocol by exploiting legacy access permissions. This latest wave of attacks comes at a time when the overall security situation in the DeFi industry remains tense.
According to data cited in the article, by the beginning of the third quarter of 2026, the DeFi sector had suffered losses of more than $840 million due to cyberattacks, with losses exceeding $640 million in April alone.











