FujitaChain

The $6M Accounting Blindspot: How Summer Finance's Vault Logic Failed the Transactional Stress Test

Directory | HasuWhale |

Hook

Over the past 72 hours, a protocol lost 40% of its LPs — not to a market crash, but to a single transaction. The data shows a flash loan of 65 million USDC entered the curve DAI/USDC pool, sending the spot price of DAI to a distorted ratio. Within the same block, another contract borrowed 8 million DAI from Morpho's lending market, deposited it into Summer Finance's vault, and extracted 6 million in stablecoins. The attacker then repaid the flash loan, leaving a hole in the vault's balance sheet. The core insight: this was not a price oracle attack. It was a failure in vault accounting logic — a flaw that, in my 2017 ICO audit experience, would have been caught with a simple sanity check on net liquidity changes.

Context

Summer Finance is a yield-optimization protocol that aggregates deposits into strategy vaults, similar to Yearn but with a focus on Morpho's lending efficiency. The protocol launched in late 2025 and had a total value locked (TVL) of approximately $50 million before the incident. It integrated with Curve's stablecoin pools for liquidity adjustments and Morpho for borrowing yield. The attack, discovered on June 23, 2026, exploited a subtle gap in how the vault computed user share values during multi-step flash loan operations. This event is the latest addition to a grim Q2: 2026 has already seen nearly $1 billion in DeFi losses, according to Rekt.news.

To understand the flaw, we need to look at the protocol’s accounting model. The vault used a dynamic share price derived from total assets divided by total shares. But it failed to update the asset balance correctly when a user interacted with both the vault and an external lending market in the same transaction. The attacker recognized this as a window to artificially inflate the share price and drain the surplus.

Core

Let me trace the on-chain evidence chain step by step. I queried the transaction hash 0x8f3c…a2ee on Dune. The sequence is clear:

  1. Flash Loan Initiation: The attacker borrowed 65 million USDC from Aave, swapped it to DAI, and used 40 million DAI to buy USDC in the Curve DAICrvUSD pool. This shifted the pool balance, creating a price discrepancy where DAI was temporarily overvalued relative to USDC.
  1. Borrowing from Morpho: Using the cheap DAI as collateral (acquired at a discount due to the pool imbalance), the attacker borrowed 8 million DAI from Morpho’s lending market. The crucial point: this borrowing inflated the attacker’s balance in Morpho, but the vault accounting in Summer Finance did not isolate this external liability.
  1. Deposit to Summer Finance Vault: The attacker deposited the 8 million borrowed DAI into Summer Finance’s vault. The vault’s share price algorithm, because it only checked the net asset balance of the vault itself (not the external debt position), registered an increase in assets without accounting for the liability. The share price shot up.
  1. Withdrawal: The attacker then withdrew a portion of their shares, claiming 6 million USDC from the vault’s reserve. Because the share price was artificially high, they received more than their initial deposit.
  1. Repayment: The attacker repaid the flash loan and the Morpho loan, closing the loop. The net result: 6 million USDC siphoned from the vault’s real capital.

This is a classic “accounting mismatch” vulnerability. In the 2020 DeFi Summer, I built a Yield Efficiency Index to track such anomalies. The standard metric of a vault’s “total value” must include external debt positions in the same transaction—something Aave and Compound enforce through their isolate accounting systems, but Summer Finance overlooked.

The data further reveals that the attacker deployed a custom smart contract (unverified) to orchestrate these steps. The Summer Finance vault itself was verified, but the logical assumption that “verified means secure” proved flawed. The contract allowed an external call to deposit after a flash loan, but did not re-check the net asset position after the external interaction. As I wrote in my 2020 report, “The Cost of Liquidity,” the most dangerous assumptions are those we fail to audit.

Contrarian

The prevailing narrative in DeFi security is that flash loan attacks are caused by price oracle manipulation. Industry analysts immediately pointed to the Curve pool manipulation as the primary cause. But the data shows a different root cause. The price manipulation was merely a tool to create temporary asset cheapness. The real vulnerability was the vault accounting logic: it did not enforce that the sum of all user share values must equal the vault’s net assets minus external liabilities at every step of a transaction.

Correlation is not causation. The attacker used price manipulation, but even without it, a similar exploit could have been executed by depositing genuinely borrowed funds and then withdrawing them after artificially inflating the share price through a series of self-transactions. The core bug is a failure in accounting invariant checks.

Furthermore, the community often blames “flash loans” as a vector, but flash loans are merely a capital efficiency tool. The true issue is that protocols do not treat complex transactions as atomic units that require state re-verification. In my 2024 ETF compliance work, we built a data bridge that rechecked every on-chain event against a settlement ledger. Summer Finance lacked that bridge.

Takeaway

Looking ahead to next week, I will be monitoring other vault protocols that integrate with Morpho or Curve for liquidity. My Dune queries will scan for any transactions where a deposit and withdrawal happen in the same block with an external borrow. This attack pattern is likely to be repeated against other projects with similar accounting models. The market will correct through another round of security upgrades, but the data endures: the next victim may already be live on mainnet, awaiting a trigger.

We trace the hash to find the human error. The $6 million hole in Summer Finance is a reminder that the most dangerous code is the code we assume is safe.

The market corrects; the data endures.

Market Prices

Coin Price 24h
BTC Bitcoin
$77,670.1 -2.08%
ETH Ethereum
$2,436.4 -2.29%
SOL Solana
$103.4 -2.25%
BNB BNB Chain
$689.1 -2.37%
XRP XRP Ledger
$1.38 -2.08%
DOGE Dogecoin
$0.0846 -2.25%
ADA Cardano
$0.2004 -3.61%
AVAX Avalanche
$7.27 -1.57%
DOT Polkadot
$0.8403 -3.59%
LINK Chainlink
$11.34 -3.13%

Fear & Greed

68

Greed

Market Sentiment

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Tools

All →

Altseason Index

40

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,670.1
1
Ethereum ETH
$2,436.4
1
Solana SOL
$103.4
1
BNB Chain BNB
$689.1
1
XRP Ledger XRP
$1.38
1
Dogecoin DOGE
$0.0846
1
Cardano ADA
$0.2004
1
Avalanche AVAX
$7.27
1
Polkadot DOT
$0.8403
1
Chainlink LINK
$11.34

🐋 Whale Tracker

🔴
0x5ac2...7175
1h ago
Out
7,704,594 DOGE
🔵
0xe0d9...b742
1d ago
Stake
2,005.75 BTC
🔵
0xd9b7...5705
1d ago
Stake
1,588.82 BTC

💡 Smart Money

0xb4df...9e2b
Arbitrage Bot
+$3.0M
88%
0x9b64...ceff
Arbitrage Bot
+$1.9M
82%
0x2466...3109
Experienced On-chain Trader
+$0.5M
88%