Summer.fi·Crypto / Web3·
Depositor value was extracted.
The report cites Summer.fi's technical report describing a flash-loan attack exploiting vault share-pricing logic and a roughly $6.04 million loss. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: capped but still-active ARKs remained included in FleetCommander share-price accounting
- Consequence
- Confirmed: Depositor value was extracted.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Summer.fi
- Industry
- Crypto / Web3
- Disclosed
- Event date
- Affected asset
- two vaults
- Data involved
- Crypto Assets
- Documented impact
- Asset theft
- Attached evidence
- 4 independent domains · 5 sources
2)Evidence-backed incident path
- 01
Reported cause
capped but still-active ARKs remained included in FleetCommander share-price accounting
ConfidencePrimaryExact excerpt
E1“capped but still-active (not delisted) ARKs remained included in FleetCommander share-price accounting”
forum.summer.fi · Jul 08 - 02
Reached
two vaults
ConfidencePrimaryExact excerpt
E2“Our own tracing puts the figure at approximately $6.04M across two vaults”
blog.summer.fi · Jul 07 - 03
Observed
Depositor value was extracted.
ConfidenceConfirmedExact excerpt
E3“extracted approximately $6.04 million of depositor value”
blog.summer.fi · Jul 15
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Not publicly established
No qualifying public evidence in the attached record.
- That a Defence review would have prevented this incident
4)Relevance to your product
A single protocol invariant can carry the weight of the complete asset path.
This pattern applies when…
- Products that calculate vault shares, prices, or asset balances using smart-contract logic.
Diagnostic questions
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 98 Protocol exploit
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
Context-only control area
Protocol and contract control area
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
5 attached sources across 4 independent domains. At least one primary source is attached.
- E3blog.summer.fiSunsetting Summer.fi and the Labs CompanyOrganization statement · Jul 15 · PrimaryOrganization statementPrimary
Exact excerpt
“extracted approximately $6.04 million of depositor value”
- E1forum.summer.fiLazy Summer Protocol Exploit, July 6 2026: BA Labs Risk Curator Retrospective - Risk - Summer CommunityOrganization statement · Jul 08 · PrimaryOrganization statementPrimary
Exact excerpt
“capped but still-active (not delisted) ARKs remained included in FleetCommander share-price accounting”
- E2blog.summer.fiLazy Summer USDC Vault Exploit Post-MortemOrganization statement · Jul 07 · PrimaryOrganization statementPrimary
Exact excerpt
“Our own tracing puts the figure”