DEFENCE / RADAR

Public snapshot

Summer.fi·Crypto / Web3·

Depositor value was extracted.

The report cites Summer.fi's technical report describing a flash-loan attack exploiting vault share-pricing logic and a roughly $6.04 million loss. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: capped but still-active ARKs remained included in FleetCommander share-price accounting
Consequence
Confirmed: Depositor value was extracted.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Summer.fi
Industry
Crypto / Web3
Disclosed
Event date
Affected asset
two vaults
Data involved
Crypto Assets
Documented impact
Asset theft
Attached evidence
4 independent domains · 5 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    capped but still-active ARKs remained included in FleetCommander share-price accounting

    ConfidencePrimary
    Exact excerpt

    capped but still-active (not delisted) ARKs remained included in FleetCommander share-price accounting

    forum.summer.fi · Jul 08
    E1
  2. 02

    Reached

    two vaults

    ConfidencePrimary
    Exact excerpt

    Our own tracing puts the figure at approximately $6.04M across two vaults

    blog.summer.fi · Jul 07
    E2
  3. 03

    Observed

    Depositor value was extracted.

    ConfidenceConfirmed
    Exact excerpt

    extracted approximately $6.04 million of depositor value

    blog.summer.fi · Jul 15
    E3

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • That a Defence review would have prevented this incident

4)Relevance to your product

A single protocol invariant can carry the weight of the complete asset path.

This pattern applies when…

  • Products that calculate vault shares, prices, or asset balances using smart-contract logic.

Diagnostic questions

  1. Do value and authorization invariants hold across every contract path?
  2. Can one actor manipulate pricing, accounting or bridge state out of sequence?
  3. Are privileged operations bounded under adversarial composition?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
98
Protocol exploit
Confirmed share
14%
18 confirmed · 108 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

Context-only control area

Protocol and contract control area

  • Do value and authorization invariants hold across every contract path?
  • Can one actor manipulate pricing, accounting or bridge state out of sequence?
  • Are privileged operations bounded under adversarial composition?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

5 attached sources across 4 independent domains. At least one primary source is attached.

  1. E3
    blog.summer.fiSunsetting Summer.fi and the Labs CompanyOrganization statement · Jul 15 · Primary
    Organization statementPrimary
    Exact excerpt
    extracted approximately $6.04 million of depositor value
  2. E1
    forum.summer.fiLazy Summer Protocol Exploit, July 6 2026: BA Labs Risk Curator Retrospective - Risk - Summer CommunityOrganization statement · Jul 08 · Primary
    Organization statementPrimary
    Exact excerpt
    capped but still-active (not delisted) ARKs remained included in FleetCommander share-price accounting
  3. E2
    blog.summer.fiLazy Summer USDC Vault Exploit Post-MortemOrganization statement · Jul 07 · Primary
    Organization statementPrimary
    Exact excerpt
    Our own tracing puts the figure
  4. S4
    hokanews.comSummer.fi Hacked: $6M Stolen as Funds Vanish Into Tornado Cash - HOKANEWS.COMOther public report · Jul 07 · Attached
    Other public reportAttached
  5. S5
    defi-bible.comA $65.4 Million Flash Loan for a $6 Million Profit: A Complete Recap of the Summer.fi Lazy Summer Vault Exploit | DeFi BibleOther public report · Jul 31 · Attached
    Other public reportAttached

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →