Deposit $64.8M. Donate some shares. Redeem $70.9M. One transaction. That's how
Summer.fi lost $6M on yesterday. It's at least the fifth time this exact scenario has drained a live vault.
How it happened:
- FleetCommander, the contract managing Summer's vaults, prices the vault with totalAssets().
- That function reads a balance the attacker could move.
- Flash-borrow $65.4M → deposit $64.8M at the honest share price → donate pre-accumulated Silo: Varlamore USDC Growth shares into the Ark, the adapter holding the vault's underlying position.
- totalAssets() re-reads the inflated position → share price spikes → the LowerRisk USDC vault momentarily prints a 2,080,000% APY.
- Redeem the shares minted by the deposit (now repriced against the inflated position) for $70.9M.
All this in one transaction.
The part most coverage will misfile: no price feed was falsified. Every underlying asset was priced correctly the whole time.
This isn't novel. Sonne (2024), Curve's sDOLA market, Venus THE, Silo, same root every time: a share price computed off a number a single-block donation can push. And audits don't save you: each contract is individually correct. Venus's own Code4rena review caught this exact vector; the team waved it through as "supported behavior with no negative side effects."
Everyone competes on APY. The category gets won by vault infra that makes share price impossible to lie about: NAV as an on-chain invariant no donation, in any single block, can move. That's the moat.