BTC $84,136.55 -1.66%
ETH $2,616.59 -3.35%
BNB $774.47 -0.71%
XRP $1.47 -1.93%
SOL $118.63 -1.31%
TRX $0.3331 -1.02%
DOGE $0.0908 -4.03%
ADA $0.2580 -5.57%
BCH $307.25 -2.65%
LINK $13.72 -1.56%
HYPE $90.77 -2.50%
AAVE $176.38 -2.69%
SUI $1.12 -4.62%
XLM $0.2064 -3.83%
ZEC $1,321.44 -0.71%
AAPL $334.36 +0.34%
AMZN $256.95 +1.64%
GOOGL $347.71 -0.24%
MSFT $530.27 +0.55%
META $740.48 -0.69%
NVDA $240.01 -0.16%
TSLA $378.93 -0.46%
SNDK $1,638.26 -3.49%
INTC $114.71 -1.49%
SPCX $168.87 -2.48%
MU $1,036.56 -2.05%
AMD $648.04 +2.40%
BTC $84,136.55 -1.66%
ETH $2,616.59 -3.35%
BNB $774.47 -0.71%
XRP $1.47 -1.93%
SOL $118.63 -1.31%
TRX $0.3331 -1.02%
DOGE $0.0908 -4.03%
ADA $0.2580 -5.57%
BCH $307.25 -2.65%
LINK $13.72 -1.56%
HYPE $90.77 -2.50%
AAVE $176.38 -2.69%
SUI $1.12 -4.62%
XLM $0.2064 -3.83%
ZEC $1,321.44 -0.71%
AAPL $334.36 +0.34%
AMZN $256.95 +1.64%
GOOGL $347.71 -0.24%
MSFT $530.27 +0.55%
META $740.48 -0.69%
NVDA $240.01 -0.16%
TSLA $378.93 -0.46%
SNDK $1,638.26 -3.49%
INTC $114.71 -1.49%
SPCX $168.87 -2.48%
MU $1,036.56 -2.05%
AMD $648.04 +2.40%

exploitation

All
Article
Flash

Summer.fi Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism

Summer.fi released an analysis report on the Lazy Summer Protocol USDC treasury attack incident. The attacker manipulated the prices of two USDC treasury shares in a single atomic transaction, extracting approximately $6.04 million of depositor funds. The core of the attack lies in the calculation method of the treasury's net asset value (NAV).The attacker donated tokens that still retained the old valuation to a Silo Ark that had been suspended after the incident in November 2025 but had not yet been completely removed, resulting in an inflated total asset value of approximately 9.5%, raising the share price, which was then redeemed at an inflated price and withdrawn from the treasury's actual liquidity. The report emphasizes that this attack was not due to a contract code vulnerability, but rather a missing link in the treasury's offline process—the deposit limit for that Ark had been set to zero, yet it was still counted in the NAV of active assets.The attacker premeditatedly accumulated the required tokens three months in advance through multiple wallets and transferred part of the profits via Tornado Cash. After the incident, Guardian Multisig has suspended all on-chain treasuries and set the deposit limit to zero. The Lazy Summer DAO will discuss compensation plans for affected users and the treasury restart plan in the coming days.

The Ministry of Industry and Information Technology of China issued a risk alert regarding the timely update of specific iOS versions to prevent the exploitation of vulnerabilities

The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology of China has monitored and found that attackers are using exploit tools targeting Apple Inc.'s terminal products to carry out cyber attack activities, which can lead to serious harms such as information theft and system control. The affected range includes Apple terminal products such as iPhone and iPad running iOS 13 to 17.2.1.Attackers induce users to use the Safari browser to visit web pages containing malicious code through methods such as SMS, email, or web poisoning, comprehensively utilizing security vulnerabilities present in the terminal devices to implant remote control Trojans into the victim's terminal products, stealing sensitive user information, gaining maximum privileges, and taking control.It is recommended that users of Apple terminal products conduct risk assessments, and promptly fix vulnerabilities through version upgrades and patch installations (refer to the Apple Security Updates). Pay attention to system update notifications and the latest security update announcements released by Apple, upgrade to the latest secure version in a timely manner, strengthen security awareness, avoid clicking on unknown links, and prevent the risk of cyber attacks.
app_icon
ChainCatcher Building the Web3 world with innovations.