Notice: analysis for informational purposes, does not constitute financial advice. Figures verified against the official Summer.fi post-mortem and the risk curator's retrospective, both from July 2026; the exact magnitude of the position and the final distribution may vary depending on the execution of already approved governance proposals. CleanSky does not receive commissions or referral payments from any of the cited protocols.

On July 6, 2026, an attacker extracted $6.04 million from two Lazy Summer Protocol (Summer.fi) vaults without touching a single line of code. What they exploited was accounting: a collateral token that died in the Stream Finance collapse in November 2025 was still valued at 100% within the vault eight months later. The attacker bought that asset cheaply, donated it to the vault to inflate its Net Asset Value (NAV—the net equity that determines the value of each share) by 9.5%, and redeemed overvalued shares against the actual liquidity of the depositors. This article reconstructs the two timelines that made the attack possible—the market price of the collateral and its accounting valuation within the vault—and why that gap, which no TVL (Total Value Locked) dashboard shows, is a form of debt already identified in our analysis on curator risk in DeFi. Here, that abstract risk plays out in real-time.

What exactly happened on July 6 at Summer.fi?

In a single atomic transaction on Ethereum, an attacker manipulated the share price of two Lazy Summer Protocol USDC vaults and walked away with $6.04 million of depositor capital. An aggregator vault functions like an automated fund: it pools deposits from many users and distributes them across various yield strategies, each managed by a component Summer.fi calls an "Ark." The value of your share depends on the sum of what all those strategies are worth together. Breaking that sum breaks the vault.

The loss was not distributed equally. The bulk—approximately $5.64 million—came from the lower-risk vault, precisely the one many depositors choose for its conservative profile; the higher-risk vault lost around $400,000. After the attack was detected, protocol guardians paused all Lazy Summer vaults and set deposit caps to zero while the cause was being confirmed. The SUMR governance token fell by more than 18% in the immediate hours (CoinDesk); the following day's post-mortem placed the drop at ~5.3% after a partial recovery.

Affected VaultEstimated LossStated Profile
Lower Risk USDC Vault$5,640,000Conservative
Higher Risk USDC Vault$400,000Aggressive
Total Extracted$6,040,000

What is "valuation technical debt" and why doesn't TVL show it?

In software engineering, technical debt is the shortcut that saves time today and charges interest tomorrow: code that works until someone stresses it. Valuation technical debt is its accounting equivalent: it is the persistent lag between the value an on-chain contract assigns to an asset and its actual market price. That lag carries over transaction after transaction until someone converts it into cash—in Summer.fi's case, eight months and 9.5% of the NAV.

The problem is that the indicator everyone watches—TVL—does not distinguish between real value and accounting value. A DeFiLlama dashboard sums up what each contract claims to hold, not what the market would pay for it. If a vault reports holding collateral worth 100 and that collateral is worth 0, the dashboard shows 100. The figure is technically true and economically false at the same time. That distance between the two series—market price and on-chain valuation—is the debt: it doesn't appear in any aggregate indicator and only materializes when someone decides to collect it. In Summer.fi, the risk was flagged—the deposit cap for the affected Ark was set to zero on October 30, 2025—and yet its valuation continued to show 100% for the following eight months.

How did collateral that died in November still value at 100% in July?

The asset in question was a token from Silo's "Varlamore USDC Growth" vault, a lending protocol. That token was linked to the ecosystem that crumbled during the Stream Finance collapse in November 2025. When Stream Finance imploded, certain associated Silo markets were frozen: users' USDC became trapped, unable to be withdrawn. But the on-chain value of those tokens was never adjusted downward to reflect this. Worse: the contract continued to accrue interest on capital that no longer existed in liquid form. The accounting showed a living, growing asset where the market saw a corpse.

The Stream Finance collapse of November 2025 was one of the most cited contagion episodes of the cycle: a yield protocol whose leveraged strategy unwound, dragging down the lending markets that had provided it with liquidity, Silo among them. The tokens representing those deposits were trapped, and their theoretical value—the one appearing on-chain—disconnected from the real value, which became practically zero due to a lack of buyers.

Within Lazy Summer, that token belonged to an Ark that was already flagged for decommissioning. Its deposit cap was set to zero and it was listed as being in the withdrawal process following the 2025 incidents. The problem is that the cleanup had not been completed: the Ark was still part of the NAV calculation using the legacy valuation from before the collapse. Eight months of valuation debt accumulating silently within a strategy that was officially "exiting" but technically still counting. And because the contract continued to accrue interest on that phantom capital, the gap didn't just persist: it grew every day.

To see the gap clearly, it is useful to place the two timelines side by side: what the market said about the collateral versus what the vault's accounting said.

MomentReal Market Price of CollateralOn-chain Valuation in Vault
Oct 30, 2025 (pre-collapse)≈ $1.00, liquid≈ $1.00; curator sets Ark deposit cap to zero
Nov 2025 (Stream Finance)Collapse: market frozen, real value ≈ 0No change: 100%
Apr 2026Illiquid, no buyer except the attacker, who begins accumulating the token via multiple wallets (Apr 6)100% + accrued interest
July 6, 2026 (attack)Bought cheaply by the attacker100%, used to inflate NAV +9.5%

How is the NAV of an aggregator vault manipulated?

The attack was not a stroke of luck, but an operation built over months. On-chain evidence indicates that the attacker funded several wallets on April 6, 2026, about three months before the incident, and accumulated the "zombie" Silo tokens through multiple addresses. Buying them was cheap: nobody else wanted them. But inside the vault, those same tokens were worth, on paper, much more than they cost.

On the day of the attack, the mechanics followed three steps. First, a flash loan—an instantaneous loan requested and repaid within the same transaction—moved about $65.4 million in stablecoins to provide muscle for the operation. Second, the attacker donated their overvalued Silo token position to the Ark in the process of withdrawal. That donation raised the totalAssets() reported by the vault by around 9.5%, without minting any new shares and—the decisive detail—without adding a single dollar of withdrawable liquidity. The vault now "believed" it was wealthier. Third, the attacker redeemed their shares at that inflated price, cashing out against the real USDC that users had actually deposited.

The result was written on the dashboards: during the transaction, the reported APY of one of the vaults reached absurd figures, in the range of 2,080,000%. No asset on the planet yields that. It was the mathematical signature of broken accounting showing up on screen in real-time, a number so impossible it functioned as a confession.

Was it negligence by Summer.fi or an accepted risk?

It is important to be precise, because the difference matters. According to the post-mortem itself, the root cause was an operational issue during the decommissioning of an old strategy; the analysis explicitly rules out a failure in the protocol's smart contracts. The Ark was correctly marked for exit—cap at zero, flagged for withdrawal—but the execution of that exit was left halfway, and in the meantime, its obsolete valuation continued to weigh on the NAV.

This places it in the middle ground between an error and a conscious decision. There is, for now, no public evidence that Summer.fi knew the asset was overvalued and decided to let it count: the most likely scenario is a process failure, a cleanup task that was assumed finished without being closed. But the lesson is identical regardless of intent. An offboarding process—the orderly withdrawal of a strategy—that marks an asset as "exiting" without simultaneously marking it "to market" leaves a gap open for as long as the exit lasts. And that exit, in this case, lasted eight months.

What known risks of aggregator vaults does the Summer.fi case confirm?

Yes, and therein lies the value of looking at the case with perspective. In our July 20 analysis on whether DeFi yields more than the bank, we argued that the extra yield from aggregator vaults isn't free: it is paid for with two specific risks. One is that the loss is lumpy, not spread out—when something fails, you don't lose a diluted fraction, you lose the entire vault that chose poorly. The other is curator risk: your money rests on the decisions of whoever configures and maintains the strategies, not on an immutable contract.

Summer.fi is the empirical confirmation of both. The loss was lumpy: $5.64 million concentrated in the conservative vault, not a scratch shared among thousands. And it was curator risk in its purest form: the defective asset wasn't introduced by the attacker; it was carried over by the vault's own management process. The risk curator—BA Labs—documents this failure in its retrospective and emphasizes that its own control layer worked: it had set the Silo Ark deposit cap to zero on October 30, 2025, eight months before the attack. The root cause it points to is one level higher, in the NAV accounting and protocol-level offboarding: the risk was identified, and yet the valuation was never re-marked. The attacker only found the door that the process had left ajar. For the full map of these risks, our vault risk taxonomy organizes them by category.

How many vaults today have zombie assets valued at 100%?

There is no public answer. Stream Finance didn't just affect Summer.fi: it left frozen tokens scattered across various protocols that used them as collateral or as a strategy. Each of those protocols had to decide, in November 2025, how to mark down those assets. Those that did it right closed their valuation debt immediately. Those that left it "for offboarding" are dragging it along, exactly like Lazy Summer, and they won't know it until someone builds the position to collect it.

The pattern repeats beyond Stream Finance. We already saw it with opaque collateral stablecoins in our analysis of the msUSD attestation crisis: whenever an asset can report a value that the market does not validate, an exploitable gap exists. DeFi's global TVL—hundreds of billions of dollars—includes an unknown amount of this latent debt. Nobody accounts for it because, by definition, it doesn't appear until it materializes. The Summer.fi attack didn't create the risk; it revealed it.

The discomfort is compounded by the calendar. Between the November collapse and the July attack, nearly eight months passed in which the asset was visible on-chain, auditable by anyone with a block explorer, and yet it continued to count at 100%. The attacker did not have insider information: they had time and the discipline to accumulate an asset for three months that the rest of the market had already given up for dead. The magnitude of the damage is summarized by a single figure: out of a pre-attack TVL of about $22 million (CoinDesk/DefiLlama), the extraction of $6.04 million took away nearly 27% of the protocol's capital.

What to ask before depositing in an aggregator vault?

The practical lesson is not to flee from vaults, but to know how to interrogate them. Before depositing capital in a yield aggregator, these questions separate an audited vault from a black box:

  1. How is collateral in the withdrawal process marked to market? An asset "in offboarding" must be valued at market price, not the last good price. If the protocol doesn't explain how it does this, assume it doesn't.
  2. Are there assets with pending haircuts—valuation cuts—that still count at 100% in the NAV? Ask explicitly about residual exposure to previous collapses—Stream Finance or any other—that still appear in the strategies.
  3. Who is the curator and what is their track record? A specific name, not "the team." Check if they have published honest retrospectives of previous incidents.
  4. Can the NAV be inflated by donation? A well-designed vault ignores or discounts direct transfers of assets that do not pass through the normal deposit flow.
  5. What real liquidity is withdrawable today? The reported totalAssets() and the effectively available liquidity can diverge. Ask for the second figure.

None of these questions require knowing how to code. They require treating the advertised yield as a hypothesis, not a guarantee, and asking those who safeguard it to defend it with data.

What remains for the trapped depositors?

As of July 21, 2026, governance has already quantified the damage. The Lazy Summer DAO approved proposals SIP1.7 and SIP1.8, which withdraw the remaining funds from the two affected vaults —approximately 4.3 million dollars allocated to Syrup, Term Finance, and Origin—, already executed on Base with cross-chain execution on Ethereum scheduled for July 21 itself. According to the team, affected depositors will be able to recover around 40% of their deposited value —the rest of the loss is socialized following the incident— through a claim campaign on Merkl, with a snapshot taken at the block immediately following the attack. The proposal to move the recovered funds to Merkl is still pending, so the final distribution schedule remains open. And there is a major epilogue: on July 15, Summer.fi announced the orderly closure of the company; the application will remain accessible until August 31, 2026, and the future of the protocol remains in the hands of the DAO.

That limbo is the final layer of valuation debt: first, accounting failed to mark the asset down, then the attacker cashed out the difference, and now a vote has already decided how much of that loss falls on them: they recover around 40% of what was deposited, and the rest is socialized. The figure of 6,04 million is the price of a single poorly closed Ark. The question it leaves open —how many other vaults are dragging their own 100% zombie asset today— will remain unanswered until the next patient attacker decides to ask it.

Sources and links: Official Summer.fi post-mortem · BA Labs risk curator retrospective (Summer forum) · Post-incident update (Summer forum, July 20) · Summer.fi sunsetting announcement · CoinDesk · CryptoTimes · The Block · AMBCrypto · Blockchain Reporter