Lazy Summer USDC Vault Exploit
What happened
On July 6, 2026, an attacker manipulated the share prices of two Lazy Summer Protocol USDC vaults on Ethereum and extracted approximately $6.04 million of depositor value in one atomic transaction.
An impaired Ark remained in the active set used by totalAssets and NAV calculations after its deposit cap was set to zero. Its stale, overvalued donated tokens could therefore inflate the vault share price without adding withdrawable liquidity.
How it happened
The attacker donated overvalued Silo Varlamore vault tokens into an Ark that was capped for offboarding but still included in the vault's NAV. That inflated the share price, letting the attacker redeem against real USDC held in other liquid positions.
Protocol details
Evidence
Proof of concept
1 availableSources
- report Lazy Summer USDC Vault Exploit Post-Mortem blog.summer.fi
- report Post-mortem rekt.news
- report @CertiKAlert incident report x.com
- report @summerfinance_ incident report x.com
- report @blockaid_ incident report x.com
- transaction Transaction etherscan.io
- analysis DeFiLlama defillama.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.