CertiK says the attacker used a $65.4M flash loan to inflate the vault's accounting and manipulate share prices in one atomic transaction.
The contract ran as written. The flaw was share-price logic that a briefly borrowed balance could distort — a known DeFi attack class.
Summer.fi said it will wind down. The app is expected to stay reachable through Aug 31 while a DAO takes over affected vaults.
H1 2026 crypto hack losses topped $1B. Automated yield vaults stack extra failure points on top of base smart-contract risk.
Read More →