Lazy Summer USDC Vault Exploit

Estimated assets extracted $6.0M
Ethereum
NAV

What happened

On July 6, 2026, an attacker manipulated the share prices of two Lazy Summer Protocol USDC vaults on Ethereum and extracted approximately $6.04 million of depositor value in one atomic transaction.

Technical root cause

An impaired Ark remained in the active set used by totalAssets and NAV calculations after its deposit cap was set to zero. Its stale, overvalued donated tokens could therefore inflate the vault share price without adding withdrawable liquidity.

How it happened

The attacker donated overvalued Silo Varlamore vault tokens into an Ark that was capped for offboarding but still included in the vault's NAV. That inflated the share price, letting the attacker redeem against real USDC held in other liquid positions.

Protocol details

Classification Token & Share Accounting
Protocol Type Yield Aggregator
Implementation language Solidity
Protocol links Website @summerfinance_

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.