Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation
On July 6, 2026, the Lazy Summer Protocol suffered an exploit on Ethereum mainnet that resulted in approximately $6.04 million in losses across two USDC vaults. The attacker used flash-loan liquidity,
On July 6, 2026, the Lazy Summer Protocol suffered an exploit on Ethereum mainnet that resulted in approximately $6.04 million in losses across two USDC vaults. The attacker used flash-loan liquidity, but the flash loan was only the amplifier. The underlying vulnerability was an incomplete strategy-offboarding process that left an impaired Silo Ark active in the vault’s net asset value calculation.
The attacker accumulated Silo “Varlamore USDC Growth” vault tokens whose onchain valuation had not reflected their economic impairment following the November 2025 Stream Finance collapse. By transferring those tokens directly into the still-active Ark, the attacker increased the Lower Risk vault’s reported totalAssets() without adding an equivalent amount of realizable USDC. They then redeemed shares at the inflated price and received genuine liquid assets belonging to the vault.
Overview
Date: July 6, 2026
Network: Ethereum mainnet
Total Loss: ~6.04M
Attack Transaction: 0x0db528c44f23fc7fa4544684a2fab81096450a14aae8bc89f42cd0592d43da12
Attacker Beneficiary:
Executor Contract: 0x0514F827C129C16418a0933E03C99A6AF982FC61
This was not a compromised-key or malicious-admin incident. The affected contracts were verified and behaved as implemented. The failure emerged from the interaction between the vault’s intended accounting rules, an external asset carrying a stale valuation, and an Ark that had been capped but not fully removed.
Technical Analysis of the Exploit
Protocol Architecture
Lazy Summer vaults use an ERC-4626-style share model. Users deposit an underlying asset into a FleetCommander, which allocates capital among strategy adapters known as Arks. Each Ark connects the vault to a particular yield source or strategy.
The value of a vault share is derived from the vault’s total reported assets:
share price = totalAssets() / totalSupply()
The FleetCommander calculates totalAssets() by summing the assets reported by every Ark in its active set. Consequently, any change in an active Ark’s reported value can affect the value of every vault share.

_sumTotalAssets() function iterates over the supplied Arks and adds each Ark’s reported totalAssets() to the FleetCommander’s aggregate asset value.The relevant Silo Ark was undergoing offboarding. Its depositCap had been set to zero, preventing the protocol’s normal rebalancing flow from depositing additional capital. However, that action did not remove the Ark from getActiveArks() and did not stop arbitrary token transfers to the Ark address. Its token balance therefore continued to contribute to totalAssets() and the vault share price.
Root Cause
The root cause was an impaired Silo Ark that had been capped but not fully removed from the FleetCommander’s active set:
Setting
depositCapto zero blocked normal allocations but did not exclude the Ark fromtotalAssets().Tokens transferred directly to the Ark were included in its reported value without minting new FleetCommander shares.
The donated Silo Varlamore tokens were credited above their realizable economic value.
The donation therefore increased the vault’s reported assets and share price without adding comparable liquid USDC. The attacker monetized that accounting increase by redeeming against the buffer and other liquid Arks.

The Silo position inflated the accounting value; it did not fund the payout.
Attack Flow
The exploit transaction began with the executor already holding the Silo Varlamore shares later donated to the affected Ark. How those shares were acquired is outside the scope of this analysis.
Exploit Transaction
The following steps are reconstructed directly from the successful exploit transaction and its call trace.
1. Flash Loans from Morpho

The executor borrowed:
65,419,171.88 USDC
1,000,000 USDT
The loans were obtained from Morpho with no flash-loan fee and were repaid within the same transaction.
2. Pre-staging the Higher Risk Vault
The sequence began with the Higher Risk vault. The attacker deposited approximately 398,172.24 USDC and immediately withdrew almost the same amount.
Although the round trip cost essentially nothing, the withdrawal was sourced from the Higher Risk vault’s liquid Sky and Morpho positions rather than its buffer. The original deposit consequently remained in the buffer, increasing immediately accessible liquidity from approximately 1,000 USDC to 399,172 USDC.
This step prepared the buffer to satisfy the attacker’s later Higher Risk redemption without forcing the vault to withdraw from illiquid Arks.
3. Minting the Term Shares
The attacker deposited approximately 490,636.89 USDC into the Term “Summer USDC” Yearn v3 strategy and received approximately 439,778.13 Term shares.
This operation served two purposes:
The Term shares became the donation asset used to manipulate the Higher Risk vault.
The underlying USDC was deposited into the Lower Risk FleetCommander, adding liquidity to its buffer.
That reciprocal vault wiring made the step unusually efficient. The capital used to mint the Higher Risk donation asset was later recovered when the attacker drained the Lower Risk vault’s liquid positions.
4. Manipulating the Lower Risk Vault
The attacker deposited 64.83 million USDC into the Lower Risk vault at approximately 1.0665 USDC per share, receiving 60.79 million shares.
They then donated Silo Varlamore tokens directly to the capped-but-active Silo Ark. The donation increased totalAssets() without minting new FleetCommander shares, raising the share price by approximately 9.5%, from 1.0665 to 1.1677 USDC.
The attacker subsequently redeemed 60.77 million shares for 70.96 million USDC. The payout came from the vault’s buffer and liquid Sky, Morpho, and Spark Arks—not from the manipulated Silo position.
5. Manipulating the Higher Risk Vault
The attacker next deposited approximately 29.52 million USDC into the Higher Risk vault at a share price near 1.0583.
They then donated the previously minted 439,778.13 Term shares to the Higher Risk Term Ark. The Ark credited those shares at approximately 490,636.89 USDC. This increased the Higher Risk share price from approximately 1.0583 to 1.0756.
Unlike the Silo donation, the Term shares were not themselves acquired at a steep discount. The profit came from their dual use: minting them routed the underlying USDC into the Lower Risk buffer, where that capital had already been recovered in the preceding drain. The donation was therefore effectively funded by assets extracted during the Lower Risk leg.
The attacker redeemed approximately 27.81 million Higher Risk shares for 29.92 million USDC, draining nearly the entire prepared buffer and producing approximately $399,000 of additional value.
6. Settlement
After manipulating both vaults, the attacker repaid the Morpho flash loans and transferred approximately 6.017 million DAI, along with the remaining vault shares, to the beneficiary address.
The total extracted value was approximately $6.04 million—about $5.64 million from the Lower Risk vault and $0.40 million from the Higher Risk vault. Because the entire exploit occurred atomically, monitoring and emergency pause mechanisms could not intervene between the NAV manipulation and withdrawals.
Post-Exploit Fund Movement
The exploit transaction transferred approximately 6.017 million DAI and the remaining vault shares to the beneficiary address. Subsequent onchain tracing indicates that part of the proceeds was converted to ETH and routed through intermediary addresses before reaching Tornado Cash.
Conclusion
The attacker donated overvalued Silo tokens to inflate the vault's reported NAV, then converted that accounting increase into liquid USDC held by the buffer and other Arks. The flash loans amplified the attack, but the capped Silo Ark remaining active in vault accounting was the decisive condition.
For vault aggregators, capping a strategy is not equivalent to removing it. A strategy remains security-critical for as long as it can influence the vault's accounting.




