The Summer.fi automated vault under the Taifung Multi-chain Agreement was attacked on Monday and about $6 million DAI was transferred. The chain security companies Blockaid, Peck Shield and CertiK subsequently disclosed anomalies, and the team suspended the affected contracts, but has not yet announced compensation arrangements.

Lightning loan distorts the pool price

At the heart of the attack was the use of large flash money to distort the mobility of the pool in which the vault was located. The attackers used approximately US$ 65.4 million in lightning loans for a vault called LazyVault LowerRisk USDC.

The product was originally identified as a low-risk strategy vault and risk management was managed by Block Analitica. At the time of the attack, there was an anomaly in the pool algorithm, which led to a shorter annualized rate of return at the front end to about 2.08 million per cent. The attackers then quickly removed the user funds by using this price-false window.

Major losses are concentrated in LVUSDC

According to PeckShield, the main impact was on Summer.fi's LVUSDC vault. The link data show that one of the most relevant current addresses is suspected to be related to the UDHC co-founder Torben Jorgensen of Web3.

  • Lightning loans of approximately $65.4 million
  • Transferred assets about $6 million DAI
  • Anomalous annualization rose to about 2.08 million per cent

It was mentioned that the address had been deposited in the pool of approximately 8.6 million USDCs shortly before the attack and had subsequently become one of the most damaged parties in the incident. The transferred DAI was quickly converted through the Uniswap V3 pool.

We've had a lot of wind control problems in the last year.

The incident also brought renewed market attention to Summer.fi ' s multi-chain infrastructure risk. The agreement currently covers Etheleum, Base and Arbitrum. In the past year, the agreement had been frozen because the USDX had broken its anchor, and there had been an attack on rsETH-related incidents.

In addition, the team had previously intercepted a malicious governance proposal. The proposal sought to influence the agreement by using old access rights. The overall security situation in the DeFi sector also remained tense at the time of the new attack.

According to the data cited, by the beginning of the third quarter of 2026 more than $840 million had been lost in the DeFi area during the year as a result of cyberattacks, of which the monthly losses in April exceeded $640 million.