Imagine opening the stablecoin vault app you normally use to park your funds, only to suddenly see an annual yield figure showing 2,080,000 percent. That is precisely what happened on Monday morning, July 6, 2026, to one of the most conservative vaults on Summer.fi (formerly known as Oasis.app) - and within minutes, roughly $6 million in user funds vanished.
Security firm Blockaid first flagged the anomaly, followed by Cyvers and CertiK, who broke down the attack mechanism. According to CertiK, the attacker used a massive $65.4 million flash loan to distort liquidity within the “LazyVault_LowerRisk_USDC” pool operated by Lazy Summer Protocol, a component of Summer.fi.
How the Flash Attack Worked
A flash loan is an uncollateralized, instant loan that must be repaid within the same blockchain transaction - if it fails, the entire transaction is automatically reverted. The attacker exploited this mechanism to manipulate how the FleetCommander smart contract calculates share values in the vault. By distorting this accounting, the attacker managed to trigger a $70.9 million redemption using vastly smaller actual capital, subsequently swapping around $6 million in stolen proceeds to the DAI stablecoin and making off with the funds.
The targeted vault was not just any product - it was specifically marketed to risk-averse users, serving as a DeFi equivalent of a “savings account.” Ironically, an APY spike into the millions should have been an instant red flag rather than a marketing gimmick. Several analysts noted that this incident highlights a new vulnerability: AI-driven automated strategies managing vault allocations now carry their own layer of risk on top of standard smart contract vulnerabilities.
Part of DeFi’s Worst Year
Summer.fi has not yet officially confirmed full details regarding the root cause at the time of writing, and the situation remains developing. What is clear, however, is that this incident adds to the mounting DeFi losses throughout 2026, which aggregate data shows have already surpassed $840 million - largely driven by major attacks last April.
This incident serves as a reminder that a “low-risk” label in DeFi never means risk-free. Automated vaults do offer the convenience of not having to monitor the market constantly, but that convenience relies on code complexity where a single small flaw can be exploited in minutes. For everyday users simply looking to park stablecoins safely, this news serves as a compelling reason to always verify where high yields actually originate before depositing funds.
Via The Block.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




