Summer.fi's flash-loan vault exploit.
Today, an attacker drained about $6 million from Summer.fi, the front end for Lazy Summer Protocol, a system that spreads deposits across DeFi lenders like Aave and Morpho to earn yield.
The vault issues shares that track each depositor's stake. A share is worth the vault's total assets divided by the shares outstanding, so its price rests on one number, what the vault believes it holds. The attacker took a flash loan of about $65 million, borrowed and repaid inside one transaction, and used it to distort the pools the vault routes through. Its accounting briefly read the vault's holdings as far larger than they were, and the displayed yield spiked past two million percent.
With the share price inflated, the attacker redeemed for more than was deposited and kept the difference. The contracts ran as written. What failed was the function pricing the shares, which trusted a total it read during a manipulated instant.
Source: https://beincrypto.com/summer-fi-exploit-6-million-sumr/
Related
SciPHR