On-Chain Read: Summer.fi Vault Drains $6M, APY Corrupts to 2.08M%, SUMR Sheds 5.3%
LazyVault_LowerRisk_USDC bleeds ~$6M as displayed APY spikes to 2.08M%; SUMR falls 5.3% against a market up 1%.

A displayed APY of roughly 2.08 million percent is the tell here, not the yield. On-chain monitors flagged the reading inside Summer.fi’s LazyVault_LowerRisk_USDC pool Monday morning, and since APY on these vaults is derived directly from balance ratios, a number that far outside reality points to one thing: the share-to-asset accounting that prices each depositor’s stake had been broken.
The Drain
Roughly $6 million left the vault in what was still an active exploit at first detection, meaning the figure was a floor, not a final tally. Trackers followed the outflow along Aave-linked deposit routes, leaving open whether the total climbs as forensics continues mapping the fund path.
LazyVault_LowerRisk_USDC is marketed as a conservative product and run by an external risk manager, which sharpens the irony: the vault positioned as lowest-risk in the Lazy Summer lineup is the one that got hit. On-chain data shows the largest depositor in the compromised pool held approximately 8.6 million USDC and appears tied to an entity connected to the protocol’s own ecosystem — a detail that matters for anyone modeling insider exposure versus pure external attack.
Researchers have already published the identifier set: an attacker address beginning 0x7BF716, a dedicated attack contract, and three affected Lazy Summer contracts. Publishing wallet and contract addresses this early is standard triage — it gives exchanges and analytics desks a window to blacklist the address before funds route through a mixer or a 0x Protocol swap, and gives white-hat responders a defined surface to attempt a freeze.
SUMR Decouples From the Tape
SUMR is trading near $0.00193, down approximately 5.3% on the day, against a broader market that gained more than 1% over the same window. That divergence is the cleanest signal available: a token falling while the wider tape rises is pricing in protocol-specific risk, not macro flow.
Thin liquidity in a small governance token amplifies moves like this, and SUMR has no peg-defense mechanism the way an algorithmic stablecoin might — once exploit headlines circulate, there’s nothing structural to arrest a confidence-driven drawdown.
Structural Exposure and the Monthly Baseline
Summer.fi, rebranded from Oasis.app after pivoting to automated yield aggregation, is the front-end for Lazy Summer Protocol, which auto-routes deposits across sources including Aave and Morpho. That routing concentrates capital in a small number of strategy contracts — efficient for yield, but it widens the blast radius the moment one vault’s logic is compromised, which is exactly what this incident is now stress-testing.
This is the second recorded DeFi exploit of July, following a June in which on-chain data logged approximately $75.87 million lost across 40 separate incidents, the largest being the Humanity Protocol breach. Vault and yield-routing protocols — pooled deposits behind composable contract logic — continue to register as the most frequently targeted layer in the aggregate exploit data, and this drain reads as continuation, not outlier.
Backdrop for positioning: the Fear & Greed Index sits at 24, Extreme Fear territory, while Bitcoin dominance holds at 69.3%. Neither figure is exploit-specific, but both frame the risk appetite context into which this SUMR selloff is landing.
Read more: Polymarket’s $2.9M Frontend Breach Lands as Q2 Hits 89 Exploits, Sector’s Worst
Leave a Reply