Summer fi: The Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism.
Related
Summer.fi An attack has been officially confirmed; all vaults in the Lazy Summer Protocol have been suspended.
According to Foresight News , Lazy Summer Protocol has officially confirmed an attack and has suspended all vaults under its umbrella. The cause is currently under investigation, and updates will be provided as they become available.
Aptos blockchain was found to have a critical vulnerability, with an attack cost of only a few hundred dollars; the team has promptly fixed it.
PANews reported on July 5th that, according to Coindesk, white-hat hackers at security firm Hexens discovered a vulnerability in the Aptos blockchain, which has since been patched. If maliciously exploited, this vulnerability could have put up to $70 billion in digital assets at systemic risk, including stablecoins and cross-chain bridges. In late February, Hexens researchers reported a critical vulnerability in the Move virtual machine (the execution environment for handling on-chain smart contracts) to the Aptos development team. They described it as an "expiration cache vulnerability" that could lead to type confusion, meaning the software could be tricked into mistaking one on-chain resource for another. Researchers simulated the attack in a real network environment with a success rate exceeding 90%.
DeFi protocol Summer Finance suffers $6 million loss after attack.
According to BlockBeats, on July 6, BlockAid reported that the DeFi protocol Summer Finance is under continuous attack, with approximately $6 million in assets stolen so far.
Gnosis Pay Security Incident Recap: Vulnerability stemmed from a flaw in signature verification logic; fix completed.
According to Foresight News , Gnosis Pay released a post-incident report on June 1st, disclosing that the root cause of the vulnerability was a flaw in the ERC-1271 signature verification logic within the Zodiac module: the system only reads the contract's return result and does not check whether the call was actually executed successfully. Attackers exploited this flaw to deploy a contract that intentionally failed but still returned a "valid" status, forged authorization, and then withdrew funds from accounts not owned by them. This vulnerability was introduced with Zodiac code version 3.4.0 in October 2023 and was patched on June 5th. The report shows that attackers withdrew approximately $1.5 million from 5,281 wallets, including approximately $641,000 in GNO, approximately $453,000 in EURE, and approximately $399,000 in USDC.e; another approximately $300,000 is locked in inaccessible accounts, and the team is exploring recovery methods. Gnosis Pay stated that it will expand its security team, introduce external audits, broaden the scope of smart contract audits, and has completed a complete product rebuild (v2) to improve its security response capabilities.
SlowMist: Eldel Finance lost approximately $350,000 in the attack.
PANews reported on July 1st that, according to SlowMist alerts, Eldel Finance suffered an attack resulting in a loss of approximately $350,000. The vulnerability stemmed from the `latestAnswer()` function in the price source, which reads the `convertToAssets()` method of the ERC4626 vault. The vault's `totalAssets()` method directly uses the underlying asset balance, allowing attackers to manipulate prices by directly transferring donated assets. The attackers used flash loan in conjunction with a donation attack to manipulate oracle prices, stealing approximately $350,000 and some reserves from the Aave Pool. The attacker's address is 0x58428161bb55c14a413945f06cbdec157f411c76, and the affected contracts included the price source and the ERC4626 vault.
Naver's $9.9 billion stock swap deal with Dunamu has been delayed again until the end of the year, while South Korea's digital asset law remains unresolved.
According to BlockBeats, on July 7, Naver Financial and Dunamu postponed the completion date of their full share swap transaction to December 31, marking the second delay in the deal. The deal to merge Dunamu, the operator of South Korea's largest crypto exchage Upbit, into Naver's financial sector was originally scheduled to close on September 30. Dunamu disclosed a new timeline on the 6th through corrections to its initial filing last November, but incomplete digital asset legislation and pending antitrust reviews remain major uncertainties. The company has postponed its extraordinary general meeting of shareholders from August 18 to November 19, and the shareholder confirmation date has been reset to October 22. Several government approvals are still required before the transaction can be completed, including approval from the Korea Fair Trade Commission (FTC) for the merger, approval for the change of Naver Financial's largest shareholder under credit information regulations, and acceptance of the filing for the change of Dunamu's largest shareholder under specific financial transaction information laws. Dunamu stated that progress at any of these stages could further extend the timeline or even cause the transaction to change. Dunamu also pointed out that the Digital Assets Basic Law, currently under consideration in Congress, is a real variable affecting the progress and outcome of transactions. As this bill is being enacted, regulators are also simultaneously considering implementing bank-style no-fault liability rules for exchanges, requiring platforms to compensate users for losses caused by hacker attacks.