Blockchain Security

A Share Donation to a Zero-Cap Ark Awaiting Removal Raised Lazy Summer's Global Redemption Price

A zero-cap Silo Ark stayed in Fleet pricing, so wrapper-share transfers enlarged claims against peer cash; by July 27, 2026, LowerRisk's target was removed, HigherRisk's Term Ark remained active, the Fleets were paused, and SIP1.9 had entered the timelock without execution receipts, while no reusable accounting fix was public, so unsafe entry and exit stay closed until HigherRisk disposition and user recovery close.

At a dockside vault, a hand drops tokens beside a rising gauge while a waterfall of coins pours past a locked gate toward a waiting boat, with other boats offshore.
In this article

Research basisSOSEC blockchain security research · deployment-exact source pinned at 0f3353093223 and 15c43a911674 ; deployment records pinned at f7ea3655e8ea ; transaction ledger fixed at Ethereum block 25,471,348; latest response state fixed at block 25,623,214

SourceSummer.fi post-mortem / public technical reconstruction / Summer Earn Protocol source and response commits / Ethereum transaction and events / SOSEC source and accounting review

1 One retired-in-practice Ark still priced the Fleet and turned a local balance into a pooled obligation

At 05:17:59 UTC on July 6, 2026, Ethereum block 25,471,348 included transaction 0x0db528c44f23fc7fa4544684a2fab81096450a14aae8bc89f42cd0592d43da12. One Morpho callback joined two Fleet deposits, two wrapper-share transfers, two redemptions, swaps, and full repayment. Summer.fi reported approximately $6.04 million in loss: about $5.64 million in LowerRisk USDC Fleet 0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17 and about $0.40 million in HigherRisk USDC Fleet 0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06.

The decisive state predated the transaction. LowerRisk's Silo Ark had a zero deposit cap, yet getActiveArks() still returned it and Fleet totalAssets() still summed its report. The actor first acquired a large Fleet-share position at the earlier price, then directly transferred externally acquired Silo wrapper shares into the Ark. The adapter converted the larger balance into assets while Fleet supply stayed unchanged. The next redemption assigned more assets to the existing shares, and BufferArk plus withdrawable peer Arks supplied the cash.

1.2 The architecture separates value reporting, share pricing, and cash payment

The user-facing FleetCommander is an upper ERC-4626 vault. It accepts USDC, mints transferable Fleet shares, and allocates capital among Arks; each Ark connects one strategy, while BufferArk holds immediately available underlying assets. Fleet adds active-Ark and buffer reports to form global NAV, then collects USDC from whichever components are currently withdrawable. Every user owns a homogeneous claim on the Fleet, with no exclusive ownership of one Ark.

FleetCommander combines asset reports from several Arks into one share price, while BufferArk and withdrawable Arks form pooled redemption liquidity.
Figure 1: Reporting, pricing, and payment are connected paths. Once a local report enters the global numerator, the settlement perimeter becomes the entire Fleet.

SiloManagedVaultArk converts wrapper-share balance into assets; FleetCommanderCache aggregates the reports; redeemFromArks() turns share entitlement into USDC. Each component followed its interface. The composition lacked one shared policy: how much instant settlement credit an unconfirmed balance increase may draw from other Arks.

1.3 One transaction ledger fixes every decision-relevant amount

This five-step ledger is the report's sole account of the atomic transaction. Base assets, wrapper shares, and both Fleet-share classes retain their own units; flash liquidity appears as both an asset and a repayment liability. Summer.fi's approximate $6.04 million is an incident-loss measure, the final DAI and residual shares are a settlement inventory, and preparation cost is a third evidence class. Combining them would create a false-precision profit number.

  1. Funding and old-price positions. Morpho sends 65,419,171.879990 USDC and 1,000,000 USDT. LowerRisk mints 60,787,156.805949 shares for 64,828,534.992005 USDC, while HigherRisk mints 27,891,852.787610 shares for 29,517,258.144045 USDC. HigherRisk also deposits 398,172.237752 USDC, raising its buffer from 1,000.000000 to 399,172.237752 USDC, then collects 114,808.834350 and 283,363.402402 USDC from Sky and MorphoV2, totaling 398,172.236752 USDC. Both claim positions exist before either report changes, and the peer withdrawals leave the newly stocked buffer intact at a round-trip net cost of 0.001000 USDC. Flash principal explains the scale and creates an equal liability.
  2. Two reporting inputs. LowerRisk receives Silo tranches of 19,075,252,173.684501 and 476,265,053.026626 shares, for 19,551,517,226.711127 in total; the supplement came from 20,000 USDT through 68,421.198930 xUSD. HigherRisk receives 439,778.128542 Term shares valued at 490,636.886985 USDC, corresponding to 460,050.830821 LowerRisk shares, after the 490,636.886986 USDC purchase cash had routed into LowerRisk. Both Ark reports rise without a Fleet-supply increase. The trace contains no report() call writing LowerRisk's new price into Term: LowerRisk is a quantity-based balance change, while HigherRisk combines fair stored value with a cross-vault cash loop.
  3. LowerRisk settlement. The actor redeems 60,766,209.130494 shares for 70,959,584.459769 USDC. Payment comes from Buffer 65,320,171.878978, Sky 25,835.626746, Morpho Avantgarde 34,465.252249, Gauntlet 284,184.162322, API3 969,759.251134, Spark 1,294,220.796797, and KPK 3,030,947.491543, leaving 20,947.675455 LowerRisk shares. Seven healthy sources cover the redemption; the Silo Ark that enlarged the report supplies none of that payment.
  4. HigherRisk settlement. The actor redeems 27,814,155.738915 shares for 29,916,430.381787 USDC. The buffer retains 0.000010 USDC, and the actor keeps 77,697.049639 HigherRisk shares. The pre-positioned buffer supplies all immediate cash; the Term Ark supplies none.
  5. Repayment and settlement. All flash assets are repaid, and the surplus plus both residual claims move to the controlling EOA: 6,016,754.998120906520734632 DAI, 20,947.675455 LowerRisk shares, and 77,697.049639 HigherRisk shares. The executor contract retains none of those three assets. A net-profit calculation still needs preparation cost, gas, swaps, and residual valuation.

1.4 One causal chain runs from external balance to peer cash

A Silo wrapper-share transfer raises the LowerRisk Ark report and Fleet-share entitlement, after which BufferArk and healthy peer Arks provide the redemption USDC.
Figure 2: Wrapper balance → Ark conversion → Fleet numerator → larger redemption entitlement → buffer and peer-Ark payment.

Figure 2 is the report's sole LowerRisk causal graph. The transaction first mints Fleet shares at the old ratio; an ERC-20 Transfer changes Ark balanceOf; convertToAssets() turns the balance into reported assets; Fleet aggregation adds no matching shares; previewRedeem() assigns more assets to the existing shares; and the withdrawal cache only knows which components can supply USDC. Later source, impact, and repair sections refer to this chain without recomputing its amounts.

HigherRisk is a separate branch. Term shares entered at their fair stored conversion, and the trace contains no report() call that wrote LowerRisk's new share price into Term. The Term purchase first sent cash into LowerRisk, the lower redemption recovered that cash, and the pre-positioned HigherRisk buffer then paid the upper claim. Repair must therefore bound exceptional-report credit and identify reciprocal cash routes across vaults.

2 Source separates balance, valuation, and payment while the composition grants all three the same credit

2.1 The adapter sees the balance accurately and carries no state for its origin

Deployment-exact SiloManagedVaultArk.totalAssets():68–73 reads the complete managed-vault share balance held by the Ark and calls convertToAssets(shares). _withdrawableTotalAssets():83–93 and _board()/_disembark():100–120 answer current withdrawal capacity and the normal custody path. The code stores no origin class for shares arriving through strategy deployment, yield, governance migration, reward, external transfer, or recovery.

This design credits accidentally delivered real assets to all shareholders and avoids stranded value. The risk appears in the upper settlement promise. convertToAssets expresses an idealized accounting conversion; maxWithdraw expresses a current account limit. Fleet uses the former to price every share while allowing settlement to draw the latter from the entire Ark set. No source-specific credit ceiling connects those two quantities.

Wrapper tokens can also rebase, mint rewards, charge transfer fees, suffer slashing, or change exchange rate while balance remains constant. Counting only shares acquired through board() would discard legitimate transitions. A correction needs an adapter-specific state model: preserve observed balance and conversion, record which increments become accepted, keep the rest pending, and apply realization or loss to the corresponding component.

2.2 Fleet summation and withdrawal sorting are locally correct; the missing rule lies between them

FleetCommander.totalAssets():342–349 delegates valuation to the cache. Deployment-exact FleetCommanderCache._totalAssets():80–181 obtains active Arks, appends BufferArk, calls each totalAssets(), and adds the results. It has no per-Ark growth ceiling, source label, pending bucket, or total-versus-withdrawable gate. A later library refactor does not alter the rule executed by the incident deployment.

deposit():245–269 fixes an operation-local total, calculates shares, transfers USDC, and boards assets into the buffer. The wrapper transfer occurs after that call returns. Later, redeemFromArks():223–242 opens a new operation-local view that includes the changed Ark balance. _forceDisembarkFromSortedArks():647–659 receives an amount due and a withdrawable list, without the identity of the Ark that enlarged the entitlement.

The cache boundary is therefore precise. Deposit and redemption each observed coherent state, with no stale read or half-written Fleet state. Extending cache lifetime would obstruct one ordering and could misprice legitimate later yield or loss. Persistent memory belongs in value classification and remaining peer credit, not in an incidental earlier transaction price.

2.3 Cap zero left an accounting member, and Term separated the value graph from the cash graph

On October 30, 2025, the curator Safe set the target Ark's deposit cap, maximum deposit percentage of TVL, and maximum rebalance inflow to zero. setArkDepositCap():144–149 changes routing capacity. _removeArk():286–296 and _validateArkRemoval():311–319 require both cap and reported assets to reach zero before active membership changes. “Stop new routing” and “leave global pricing” are separate governance states.

The HigherRisk Term leg requires both a value graph and a cash graph. The Etherscan-verified Strategy constructor binds _yearnVault to LowerRisk. In Term Finance commit 10e9c8e5254c5a5ab601cd6faa0b9ac34c2b27f2, constructor lines 1265–1281 set that address, and _redeemRepoTokens():848–868 with _deployFunds():1312–1318 places loose USDC into LowerRisk.

Yearn Tokenized Strategy keeps Term totalAssets in storage. Ordinary deposits and withdrawals update it directly; a price change in already-held LowerRisk shares reaches storage when report():1058–1075 invokes the harvest path and lines 1222–1224 write the result. The incident trace contains no such call between the two legs, so HigherRisk accepted Term's fair stored value. Its gain came from purchase cash already recovered downstairs and a different buffer paying upstairs. That distinction makes an adapter-rate-only repair incomplete.

2.4 The formula allocates claims; numerator credit quality determines the economic result

Ignoring fees and rounding, ERC-4626 deposit shares approximate assets × totalSupply / totalAssets, and redemption assets approximate shares × totalAssets / totalSupply. An ordinary deposit increases assets and supply together, leaving price nearly unchanged. A wrapper transfer increases reported assets alone, so existing shares receive the increment. The actor held a large supply fraction before the transfer and could capture that fraction of the later report through redemption.

Let q be the supply fraction controlled after deposit, V the new reported value, C the acquisition cost of the wrapper, and F financing, gas, and swap cost. A rough condition is q × V − C − F > 0, bounded by withdrawable liquidity. The expression does not turn reported value into measured profit. It identifies why temporary capital, discounted acquisition, and pooled payment all had to align.

The security invariant divides the asset numerator by settlement quality. Realized cash, strategy value with established source and exit, an unconfirmed external increment, and an impaired position can all belong to the Fleet without receiving identical payment rights. A user interface can still disclose defensible long-term NAV. Redemption preview must use the portion the protocol will settle immediately or state the queue, discount, and release condition clearly.

Peer credit also belongs to the value increment and the whole Fleet. Limits attached to a caller, transaction, or one redemption reset through share transfers, several accounts, and repeated calls. A ceiling attached to the originating Ark and pending value is consumed by every holder together. When source assets realize, governance confirms them, or a loss is recognized, the allowance and value classes update under one conservation rule.

The invariant explains both legs. LowerRisk V came from old Silo wrapper shares acquired below the value assigned by Fleet. HigherRisk received Term shares at fair stored value, while the cash used to obtain them had already been recovered through LowerRisk. The first needs provenance and realizability classification; the second needs cash-graph analysis of circular funding. Both graphs belong in acceptance because an honest adapter can still form unlimited credit through composition.

3 Pinned source, call trace, and the payment equality close the evidence chain

3.1 Deployment-exact source explains mechanism; fixed blocks establish production state

The source anchors have separate jobs. Verified FleetCommander, FleetCommanderCache, FleetCommanderConfigProvider, and HigherRisk ERC4626Ark match lazy-summer-protocol@0f3353093223704060cccd187fd0e0403f69d59f byte for byte. The deployed LowerRisk SiloManagedVaultArk exact-matches summer-earn-protocol@15c43a911674ef971a4dba7cd7ab7398b38e409a. Pre-incident active-repository commit f7ea3655e8ea83a3cb0b7773b49cbc8b91ae2f18 fixes the deployment records and dated public state. A moving main branch can show later changes; it cannot replace deployment line numbers.

The trace shows which code actually ran. The Silo wrapper Transfer sits between deposit return and redemption entry; the seven USDC sources in the LowerRisk ledger row equal the redemption; Term deployment routes purchase cash into LowerRisk; Yearn report() is absent; and loan repayment plus EOA transfers close the executor ledger. Together these states support Figure 2. A screenshot, extreme APY, or successful transaction status alone cannot establish the complete causal path.

Integer replay begins at the parent block and preserves token decimals, the supply and asset totals observed by each call, rounding direction, and withdrawable ceiling. The LowerRisk residual follows the liquidity limit; the HigherRisk residual follows the actor's chosen redemption amount. Rounding allocates smallest units. Operation-level snapshots prevent the final transaction state from being projected backward into entry pricing.

3.2 Only competing explanations that change the repair target remain

Spot-oracle path. The reviewed LowerRisk call chain moves from wrapper balance into Silo-vault conversion, and FleetCommander reads no spot quote that determines this jump. Upstream markets and the Stream Finance collapse explain cheap acquisition and stale accounting value. The repair target remains adapter admission and peer credit; adding a Fleet spot-oracle check would still leave balance origin undefined.

Operation-local cache path. Deposit and redemption each receive a coherent snapshot, with the ERC-20 transfer between operations. Cache invalidation changes refresh timing and cannot decide whether a fresh, mathematically correct conversion deserves instant pooled settlement. Accepted, pending, and consumed-credit state must persist across calls.

Classic empty-vault rounding path. The Fleet already held substantial assets and supply. The actor used an ordinary deposit to acquire a large position and then changed an existing multi-strategy numerator. Virtual assets, virtual shares, and minimum liquidity address first-depositor rounding; they provide no provenance ledger or peer-payment boundary. Regression should retain classic ERC-4626 cases while classifying this event as adapter-balance donation with cross-Ark settlement.

HigherRisk live-propagation path. A Yearn report() call would add lower-price quality propagation to the repair scope. The incident trace contains no such call. The verified cash route explains the upper economics, so review must ask whether the backing cash for a wrapper can be recovered from another vault and where final settlement liquidity resides.

3.3 Preparation evidence explains cost and technical control without establishing identity or exact profit

Public reconstruction identifies five preparation wallets. Over roughly ten days they bought Stream xUSD, converted it through Balancer into Silo Varlamore USDC Growth shares, and held the position for nearly three months. Permit-based consolidation moved the main tranche to the executor three blocks before the incident. The transaction then added a smaller tranche funded by flash-borrowed USDT. The ledger fixes both exact quantities; this section adds time and source without recomputing the transfer.

The transfer graph supports a common technical-control assessment: wallets accumulated the same target asset, held it, converged on one executor immediately before use, and that executor performed the atomic sequence. The chain graph does not identify a natural person, organization, or jurisdiction. Address labels, funding origin, and real-world attribution require separate evidence.

Cost evidence has different precision. Public reconstruction estimates approximately $40,000 for the prepared majority. The in-transaction supplement is exactly traceable from flash input through xUSD output to wrapper result. A complete main-tranche cost would still require every earlier swap, fee, funding transfer, and holding-period state. The estimate label remains, and the two evidence classes are not merged into one exact dollar cost.

Actor profit also needs an observation time and realizability rule for both residual Fleet-share balances, followed by deductions for gas, swap impact, financing, and preparation. Protocol loss follows net healthy-asset depletion and the realizable value of impaired positions. User restoration follows a governed eligibility and funding rule. The three ledgers reconcile, but they answer different questions. The final DAI balance proves only what the executor transferred to the controlling EOA at settlement.

Preparation creates a pre-incident detection window. Concentrated acquisition of a wrapper used by an Ark awaiting removal, or consolidation into a fresh contract shortly before use, becomes significant when joined with that Ark's direct-transfer exposure and the Fleet's peer settlement capacity. Market purchase alone has legitimate uses; confidence rises from the combined lifecycle, concentration, timing, and liquidity evidence.

Historical hunting begins at the block where the Ark entered the active set or reached cap zero. It searches direct wrapper transfers, report growth without corresponding Fleet-supply change, same-transaction deposit and redemption, and share concentration. Each result keeps block, log index, runtime, and parser version so later repository refactors or label changes cannot rewrite the historical exposure finding.

4 Shared withdrawable assets define the loss ceiling; one Ark's book balance understates exposure

4.1 Fleet liquidity sharing is credit, and the incident exposed an unlimited line

A multi-strategy vault lets a liquid Ark smooth redemptions for a duration strategy. That product feature is also credit: value reported by one Ark may receive cash advanced by another. Figure 2 and the transaction ledger show that this credit had no source, realizability, or amount boundary. Exposure therefore covered the entire buffer and every withdrawable strategy in the Fleet.

A wrapper share also carried three values at once: ideal conversion under the lower vault, cost along the actor's acquisition route, and cash immediately realizable from the position. Fleet formed entitlement from the first and settled it from peers at near-cash value. Replacing all totalAssets with maxWithdraw would undervalue healthy duration strategies and cause NAV jumps. A stronger model keeps long-term NAV, instant-settlement value, and peer-credit allowance as distinct quantities.

Protocol loss, actor profit, and user restoration remain separate. Protocol loss follows real asset depletion and realizable residual value. Actor profit also subtracts preparation, financing, gas, and swaps while valuing residual claims. User restoration follows the governance-chosen eligibility snapshot, inventory, and funding rule. The official loss estimate and the atomic settlement ledger answer different questions.

4.2 Exposure follows value and cash graphs; detection closes from unexplained balance to redemption

Each Fleet exposure record fixes chain, runtime, underlying asset, total assets, supply, buffer, pause, cap, and active set. Each Ark record fixes adapter, wrapper, balance, totalAssets, withdrawableTotalAssets, conversion method, cap, lifecycle, and direct-transfer ability. Nested wrappers continue to the ultimate base asset and mark conversion as live or stored.

The highest-value signal is an active zero-cap Ark receiving wrapper shares that cannot be reconciled to keeper, governance, migration, or a reviewed yield mechanism. The detector converts that delta into reported value, checks whether Fleet supply changed with it, and computes how much the buffer and peers can settle. A one-block share-price jump, extreme APY, and a large deposit—balance transfer—redemption sequence provide downstream confirmation.

Numerical thresholds are locally calibrated operating policy. Historical legitimate yield, direct-transfer baselines, strategy-liquidity distribution, fixed-block fork replay, business pause cost, and human response capacity should set alerting, automatic limits, and release windows. Shadow mode first records hits and misses before automated blocking. This report has no incident distribution or production risk budget and therefore supplies no copy-ready days, basis points, NAV percentages, or minute values.

4.3 Maximum-loss simulation follows payment capacity; historical hunting follows state change

TVL measures asset scale and cannot show how much cash an abnormal Ark report can obtain. A fixed-block simulation injects a controlled report increment into each Ark, recomputes Fleet share price, buffer and strategy withdrawal capacity, deposit limits, and operation constraints, then increases the increment until peer credit, liquidity, or a pause guard becomes binding. The result measures healthy assets mobilized by one unit of abnormal reported value.

A large fresh deposit raises both the actor's share fraction and buffer liquidity, so pre-event balances alone understate exposure. Simulation varies deposit capacity, existing-holder share, transferred shares, several accounts, and cross-block financing. If a control only lowers one address or one call, the model shows how the same aggregate entitlement continues through other holders.

Nested strategies expand to the ultimate base asset. Every edge records lower runtime, live or stored conversion, pause, loss treatment, withdrawal capacity, and where purchase cash is deployed. Cycles receive an explicit failure state. When lower value becomes pending, quarantined, or impaired, upper risk views must preserve that quality; one convertToAssets call cannot flatten it back into ordinary cash-equivalent value.

Alert actions follow evidence maturity. An unknown direct transfer first creates an observation or pending bucket. Share-price growth without supply change plus ample peer liquidity limits large redemption. A single trace that also contains large entry, abnormal balance, and exit invokes the verified pause path. Every level has a withdrawal condition so legitimate migration or recovery can release value after provenance is established.

False-positive review covers ordinary yield, rewards, governed recovery, keeper migration, mistaken transfer, rebase, fee, and underlying-vault upgrade. Detection explains balance and conversion factors separately, then reconciles them to governance and keeper records. Treating every external balance as hostile strands legitimate value; trusting every configured token recreates the incident condition.

5 The minimum repair closes one invariant; deployment intent selects the implementation

5.1 The repair decision path separates fact, invariant, implementation, and local policy

  1. Start from the verified fact. External wrapper growth entered an active Ark report, Fleet turned that report into a global entitlement, and peer liquidity paid it. Keep the affected directions closed while custody, membership, accounting, and restoration remain separate workstreams. Pinned source, Figure 2, the transaction ledger, and fixed-block membership and balance reads are the acceptance evidence for this layer.
  2. Enforce one economic invariant. An Ark-value increase with unconfirmed source or realizability cannot create positive net assets funded by peer Arks. Cumulative peer payment is Fleet-scoped, so account splitting and repeated calls cannot reset it. Historical reproduction and candidate runs must cover multiple holders, transfers, partial redemption, nesting, and timing.
  3. Use removal for a deployment retiring the named targets. Empty or quarantine residual assets, execute removeArk(), prove the new active set, and make cap-zero lifecycle progress only toward draining, quarantine, or removal. Acceptance requires the successful governance transaction, a same-block post-state read, target-balance and user-claim reconciliation, and evidence that the dangerous state cannot recur.
  4. Use value admission and settlement credit for a Fleet that continues operating. Record observed, accepted, pending, impaired, and realized value; share one per-Ark credit ceiling between pricing and settlement; release allowance only as source value becomes cash. Acceptance requires a pinned corrected commit, storage semantics, the upgrade or migration transaction, installed artifact, positive and negative controls, and the economic-invariant result.
  5. Calibrate operations locally. Alert thresholds, automatic pause, exceptional-value release, drain deadline, exercise frequency, and the risk window come from normal history, liquidity stress, false positives, and pause cost. Run shadow rules and human confirmation before calibration. Keep the recorded samples, negative controls, replay results, business impact, owner, exception approval, and withdrawal condition.

5.2 One economic acceptance program proves safety, liveness, and migration correctness

The historical baseline starts from the block immediately before the exploit and records chain ID, block hash, deployed code, active-Ark array, buffer, caps, pause state, roles, token decimals, balances, supply, and wrapper conversions. Replay reproduces the ledger's two mints, two wrapper-balance changes, two burns, loan and repayment, final settlement, and residual claims. A successful call or unrelated revert message is not a valid baseline.

The candidate changes one named repair state in the same apparatus. Negative controls cover direct transfer, conversion-rate change, flash funding, pre-existing holdings, share transfer, several addresses, partial redemption, buffer replenishment, failed peer withdrawal, and nested wrappers. Positive controls cover ordinary yield, keeper board and disembark, approved migration, reward, fee, recognized loss, governed recovery, and legitimate donation. Value classes conserve, user claims reconcile, and pending value cannot obtain peer cash beyond its allowance.

Lifecycle after cap zero is monotonic. Realized proceeds may move to the buffer, while external quantity or conversion growth enters pending or quarantine. After balance and report clear, removal executes; dust and late transfers cannot restore global pricing authority. An upgrade also checks storage slots, initialization snapshot, proxy implementation, roles, and front-end previews so migration does not silently redistribute user claims.

A repair workbench separates value admission, settlement credit, Ark lifecycle, pause, and restoration under one acceptance process.
Figure 3: Deployment removal and protocol accounting are distinct permanent routes, and both pass through the same economic acceptance and production-state review.

5.3 Each candidate design has one job and the same invariant judges the composition

Provenance accounting. The adapter maintains observed and accepted shares. Fleet-directed board(), approved migration, and reviewed yield rules can update the accepted baseline; unexplained surplus remains pending. This is direct for fixed-supply wrappers. Rebases, rewards, transfer fees, slashing, and conversion-rate changes need adapter-specific transitions that a universal counter cannot model safely.

Delayed confirmation. Exceptional positive change is recorded and released through exit probes, provenance evidence, governance confirmation, or time-weighted recognition. Delay moves the increment outside a flash-loan window and gives operators time to assess it. Elapsed time alone does not establish realizability, and an actor can hold longer, so release also needs economic evidence and an Ark-level ceiling.

Long-term NAV and instant settlement. A duration or impaired strategy may retain defensible long-term value while immediate exit uses realized and risk-eligible amounts. The model introduces a queue, discount, or two quantities that ERC-4626 previews, front ends, and integrators must explain. Healthy Arks then stop providing an unlimited guarantee for another Ark's ideal conversion.

Source-first settlement and peer credit. An Ark realizes its exceptional increment first; peers advance only a governed allowance. The allowance is bound to Fleet and increment and is consumed across all holders. Partial fulfillment, repeated redemption, share transfer, and new buffer deposits cannot restore spent credit. Ordinary principal and routine yield can continue to share liquidity under the normal policy.

Lifecycle quarantine. Cap zero automatically enters draining, and new risk eligible for instant peer settlement can only decline. Realized assets may move to buffer; external balance or abnormal conversion remains pending. Removal executes at the documented cleared state, with explicit dust and late-transfer treatment. Reactivation repeats admission review and cannot consist solely of raising the cap.

Global price guard. Deposit and redemption compare accepted share price with a checkpoint and decompose unusual movement by Ark. This can pause or narrow settlement when an adapter classifier fails. It is a last defense because legitimate yield and slow movement complicate thresholds; it cannot replace provenance or peer-credit state.

The upgrade route determines implementation risk. Adding value buckets to a proxy requires storage-slot review, fixed-snapshot initialization, and a governed split of current observed value. A new Fleet avoids storage collision and introduces migration of claims, integrations, approvals, and residual assets. Both routes publish semantic differences, initial values, transactions, post-state, and regression results. Source merge alone is not a production repair.

The matrix supplies the order: decide whether the named deployment will continue service, choose removal or accounting upgrade, then apply the same historical replay, positive controls, and peer-funded-gain invariant. Several heuristic mitigations may reduce exposure, yet they cannot combine into a pass while the economic result remains open.

5.4 A candidate value ledger closes the economic path through explicit state transitions

This section specifies a candidate design for implementation and review; it is not evidence that Lazy Summer has adopted it. Each Ark keeps observed value O, accepted value A, pending value P, and impaired value I on one valuation basis, with a reproducible O = A + P + I relationship. Base assets actually recovered are recorded as realization events so the same exit cannot remain inside the Ark and appear again in the buffer. Fleet may disclose these components in long-term NAV under a documented policy. Instant settlement rights arise only from accepted, realizable value and unconsumed peer credit. An implementation proposal must fix storage, rounding, fee, and negative-value semantics; the model here fixes the economic meaning that those choices must preserve.

Every operation first reconciles the wrapper's actual token balance with its prior observation, then separates quantity movement from conversion-rate movement. A completed Fleet-directed board(), an approved migration, or a documented recovery may enter accepted value under its rule. Positive quantity without a matching protocol action enters pending. Conversion growth follows an adapter-specific yield model: the portion inside reviewed sources and risk bounds can be accepted progressively, while the remainder waits for an exit probe or governance evidence. Conversion loss reduces settlement rights immediately and enters the documented loss or impairment path; it does not wait for a later report to affect payment capacity.

Provenance cannot rest on msg.sender or one Transfer log. A third party can alter an ERC-20 balance directly, a rebase can change it without a transfer, and fee tokens can make sent and received quantities differ. Proxy upgrades and underlying-vault reports can also change conversion behavior. The adapter therefore begins with state deltas and uses governance transactions, maintainer actions, underlying events, and implementation identity as explanatory evidence. An unexplained increment remains pending. An explained increment receives only the authority justified by realizability. Similar-looking events, address rotation, and transaction splitting then fail to obtain full settlement eligibility automatically.

Peer credit is a Fleet-level ledger separate from NAV. A candidate redemption first calculates base assets the source Ark can deliver and reserves that Ark's credit for the remainder. Reservation is written atomically before any external call; reentrancy, share transfer, multiple recipients, and repeated small redemptions all consume one balance. Reservation is released only when the source Ark later delivers cash, a redemption cancels without peer payment, or governance applies a published loss-allocation rule. A new deposit may increase buffer assets, yet it does not replenish credit already consumed by an exceptional Ark.

Preview and execution read the same state semantics. previewRedeem exposes the amount payable now, the amount queued or discounted, and the Ark that creates the limit. Execution rechecks reservation and actual withdrawal after state changes and exits safely against the user's declared minimum output. Partial redemption follows a documented order across source liquidity, ordinary shared liquidity, and exceptional-increment credit. That order keeps ordinary principal from being frozen with pending value and keeps pending value from inheriting a normal-principal label. A deployment whose integrations accept only one synchronous ERC-4626 amount must choose a conservative instant-settlement measure or migrate to an interface that can express a queue.

Ark lifecycle can be modeled as active, draining, quarantined, and removed governance states. Cap zero closes new active allocation and supplies a candidate trigger for draining. Asset recovery, pending increments, impairment treatment, and membership removal then produce distinct state evidence. Draining and quarantine prevent risk authority from increasing while allowing verified recovery to reduce balances. Once the documented clear conditions hold, the membership transaction and a post-transaction read together establish removal. A late transfer to a removed address enters a separate recovery path and never restores Fleet pricing authority. Reactivation repeats admission, parameters, roles, and emergency rehearsal.

Nested strategies propagate quality labels upward. When an upper adapter reads lower-layer shares, it also needs the portions realized, pending, impaired, or queue-constrained. Without such an interface, the upper layer applies conservative settlement eligibility and updates it through exit probes. The cash route is stored as a risk property too: when purchase funding for one layer enters a related Fleet, the risk engine marks a cycle and constrains mutual instant credit. The HigherRisk Term leg shows why this matters: fair stored value can still combine with circular cash and a separate buffer to create risk, so quality propagation cannot activate only after a bad price appears.

Migration initialization is the design's most consequential classification event. The upgrade block fixes each Ark's balance, conversion, withdrawability, membership, buffer, and user supply, and an independent script recomputes O from the same block. Existing principal and evidence-supported yield enter A; positive value with incomplete provenance enters P; publicly confirmed impairment enters I. Any unexplained difference blocks reopening. The governance package includes the classification manifest, rounding rule, storage slots, initialization calldata, and rollback destination. Post-operation reads reconcile all buckets with user claims; supply or asset non-conservation keeps the deployment paused.

Dependency failure also needs accounting meaning. If a wrapper read reverts, conversion returns an anomalous value, an exit probe fails, or a lower queue becomes unavailable, the candidate implementation freezes new instant-settlement eligibility for that Ark, preserves the last provable state and block, and keeps risk-reducing control actions available. Once reads recover, it reconciles the entire gap and places unexplained change in pending; monitor recovery does not accept all accumulated movement. Whether ordinary users can still exit against realized value belongs to the deployment's service policy. That policy can trade availability against caution, while the invariant that exceptional value receives no unlimited peer credit remains fixed.

Configuration and hard constraints occupy different layers. Yield-recognition speed, probe cadence, manual-approval roles, alert levels, and draining deadlines are locally calibrated policy; a governance change carries rationale, samples, expected effect, and withdrawal condition. Conservation of observed value, shared credit consumption across accounts, no return of pricing authority after removal, and no excess peer payment from pending increments are implementation invariants that ordinary parameters cannot disable. Review therefore tests bypasses before judging whether a threshold suits operations. A permissive setting can enlarge a risk budget, but it cannot reset the counter or rename pending state as accepted.

Rollback is a state transition too. Before returning to old code, the system maps consumed credit, pending value, impairment, queued requests, and operation nonces into a safe representation; merely restoring an old storage interpretation can issue already-spent payment rights again. A release package includes forward migration, emergency stop, state export, rollback conversion, and post-operation reconciliation. Fork tests cover interrupted migration, partial multisig execution, and cross-block retry. After a production rollback, independent reads still reconcile user supply, base assets, each value bucket, and outstanding requests.

Observability follows transitions directly. The protocol emits events for observed deltas, value acceptance, pending classification, impairment, cash realization, credit reservation, consumption, and release, each carrying Ark, reason identifier, and operation identifier. Monitoring reconciles those events with balances and call results instead of treating emitted text as final truth. The operator view shows long-term NAV, instant-settlement value, pending value, impaired value, remaining peer credit, and lifecycle state together. Every alert resolves to the block and rule that caused it, while a manual acceptance records its approver, evidence, and withdrawal path.

The matrix invariant remains the candidate's acceptance authority. Negative controls combine external balance movement, conversion change, nested pricing, circular funding, share transfer, reentrancy, and multi-address splitting to show that one exceptional increment cannot obtain peer-funded net payment above its allowance. Positive controls preserve ordinary deposit, yield, fee, loss, migration, partial exit, and recovery. State-machine properties then assert component conservation, non-negative credit, no restoration of pricing authority after removal, and previews bounded by executable output. Only a pinned implementation, deployment transaction, and production post-state can move the matrix entry from “candidate design” to “installed control.”

6 Response advances custody, membership, accounting, service, and user claims independently

6.1 Four state anchors are fixed before any asset movement

The recovery record fixes the block before the exploit, the exploit block, the first confirmed containment block, and the latest public-state block. Each anchor stores Fleet supply, holder balances, buffer, every Ark token balance, conversion, withdrawable amount, membership, cap, pause, role, implementation, and block hash. The pre-attack book describes protocol state before this transaction. Any earlier impairment in the old Silo position still requires a realizability range and a governed adjustment.

Cash, wrapper shares, Term shares, both residual Fleet claims, cross-chain positions, and governed-custody assets remain separate. Every movement records origin, destination, native integer, ownership, valuation rule, confidence, and next state-changing event. The user eligibility rule then addresses mints, burns, transfers, wrapping, identified actor balances, disputed ownership, and rounding. Any exclusion based on a nontechnical judgment should be calculated both included and excluded so its distributional effect is visible.

The recovery ledger closes both asset conservation and claim conservation. Every distributable base asset occupies exactly one state among custody, pending settlement, user claim, and dispute reserve. Every user right occupies exactly one state among the old Fleet, migration receipt, recovery vehicle, completed payment, and documented exclusion. Governance support is recorded with its own source and conditions; it never backfills protocol assets in the historical ledger. Each transition preserves prior and new roots, native-integer totals, transaction, and approval basis so another team can regenerate allocation from the fixed block. If both conservation relationships cannot close, recovery remains in reconciliation; service status and user notices must state that boundary.

Disputes need deterministic handling. When shares transfer around the snapshot, enter a wrapper, map across chains, land at actor-controlled addresses, or become subject to a legal hold, observable events drive inclusion, exclusion, and appeal. A manual exception creates a reasoned supplemental state instead of editing the primary ledger. A user proof connects eligibility snapshot, valuation rule, claimable assets, unresolved recovery rights, and prior claims. The protocol can distribute settled value while preserving unresolved rights in an auditable vehicle. Early service must continue to disclose the unreconciled liability.

Retaining the old Fleet requires a sequence across actual pause guards, roles, migration, membership change, and any implementation upgrade without an unsafe reopening interval. Moving to a new Fleet separates immediately realizable value from pending recovery claims and cannot manufacture a clean share price by discarding an old position. Both routes need fixed-block fork rehearsal and stepwise confirmation through production transactions and post-state reads.

6.2 Emergency authority is proved through actual roles and executable transactions on every chain

The incident Guardian multisig had eight signers and a six-of-eight threshold. Its deployed powers were limited to pausing vaults, setting deposit caps to zero, and cancelling risky in-flight governance proposals; it could not transfer user assets or add and remove Arks. Ethereum, Base, Arbitrum, and Sonic pauses were confirmed separately. HyperEVM reverted for a missing expected role and moved to the Foundation path. Mainnet success cannot establish authority on another chain.

Each production instance stores current members, threshold, roles, selectors, proxy implementation, nonce, gas asset, target, expected events, and fallback path, then validates them through a state-preserving simulation or a governed low-risk action. Exercise frequency, tolerated signer unavailability, and response timing are local operating policy calibrated from organizational distribution, device availability, chain finality, and exercise history.

Public status is per deployment: submitted, confirmed, failed, pending, or not applicable. A global paused label follows automated reads across the complete inventory. Reopening first verifies runtime, Ark state, and an unexpected-share-transfer canary, then enables only the needed surface in cohorts while a proven emergency stop remains available.

6.3 Cleanup changes custody; membership and accounting require their own production evidence

LowerRisk response commit 124733c076d946406411d6625d472de7a1af5692 separates two phases. Production transaction 0x7bead580…fd4 first moved donated vgUSDC through Raft.socializeLosses to the Foundation Safe on July 6. The SIP1.7 cross-chain satellite proposal then executed on July 21, removed 18 zero-balance Arks including the target Silo Ark, and requested the Syrup exit. Membership and balance reads at block 25,623,214 confirm that the target left the active set and reports zero.

HigherRisk SIP1.8 executed the same day, removed 31 zero-balance Arks, requested the Origin exit, and repaused the Fleet. The funded target Term Ark was not in that removal batch. Block 25,623,214 still returns it as a member with both totalAssets() and withdrawableTotalAssets() equal to 194,770.592290 USDC. Pull requests #888 and #890 merged governance batches, distribution configuration, and withdrawal tooling on July 22. Public evidence shows no installed protocol-accounting repair. SIP1.9 passed voting and entered the timelock, proposing to move 4,132,125.591039 USDC from both buffers to Merkl while keeping both Fleets paused; at 10:32 UTC on July 27, the public interface showed no mainnet execution receipt or campaign root.

removeArk() interacts with pause state and the cleared-balance condition, while custody and membership change under different authorities. The production sequence states which calls are available in every intermediate block, how Ark balance affects the report, when removal becomes valid, how signer threshold and timelock apply, and how failure keeps public entry closed. If the current implementation cannot cross that sequence safely, realizable assets and user claims move to a clean deployment while the old Fleet stays closed.

User restoration begins from fixed snapshots and the asset inventory. Immediate cash, healthy-strategy claims, the impaired Silo position, Term shares, both residual Fleet-share classes, and governed-custody assets receive separate valuation. Eligibility states the attack-preceding or containment time, transfers, wrappers, cross-chain positions, disputed ownership, and sanctions treatment. When assets are insufficient, a recovery claim or separate vehicle represents pending value explicitly instead of silently removing it from a new share price.

The Summer.fi and Labs wind-down announcement changes organizational capacity and product outlook. DAO-controlled contract state still changes through chain actions. After an operating entity changes, the owner field becomes more important: every open item names the authority able to sign, deploy, custody, value, or publish state, and the default remains closed when no owner accepts it.

Reopening proceeds per deployment. Install and confirm a permanent route, run historical replay and ordinary-function controls, then verify roles and emergency stop. Open the minimum required surface, observe the locally calibrated risk window, and enable the remainder last. Unknown runtime, membership drift, unreconciled balance, peer cash issued against exceptional value, or unreachable pause returns the deployment to closed state.

7 By July 27, LowerRisk had removed its target; HigherRisk and user restoration remained open

The six entries below are the report's response-state ledger and closure boundary. Dates identify when public evidence first or last established a state. Pending contains actions whose absence is established by chain or governance state. Unknown contains matters that current evidence cannot answer and that would change the restoration decision.

  1. Executed · Jul 6, 2026. Affected vault caps went to zero; Ethereum, Base, Arbitrum, and Sonic entered pause response; LowerRisk phase one moved donated vgUSDC to the Foundation Safe. Block Analitica, the Guardian, and the Foundation Safe / Raft operator own this step. The Summer.fi response timeline, successful cleanup transaction 0x7bead580…fd4, and destination balance establish completion.
  2. Executed · Jul 21, 2026. SIP1.7 removed 18 zero-balance LowerRisk Arks and requested the Syrup exit. SIP1.8 removed 31 zero-balance HigherRisk Arks and requested the Origin exit. Both Fleets were repaused. The Lazy Summer DAO, Base Governor, Ethereum Timelock, and deployment operators own the batch. Both governance detail pages show the satellite proposals as Executed, and block 25,623,214 confirms that the LowerRisk target is absent and reports zero.
  3. Pending · observed Jul 27, 2026 09:21:23 UTC. The HigherRisk target Term Ark still needs authorized custody or recovery treatment, a cleared report, and removal from active membership. DAO governance, Foundation custody, and named-deployment operators own the action. At block 25,623,214, membership remains true and both reported and withdrawable value equal 194,770.592290 USDC. Exit requires a successful governance transaction plus same-block membership and balance reads.
  4. Queued · governance refreshed Jul 27, 2026 10:32 UTC. SIP1.9 passed voting and entered the timelock; the official interface displayed an executable time of Jul 28, 2026 08:06 UTC. It proposes moving 4,132,125.591039 USDC from both buffers into Merkl for snapshot-based user distribution. The Lazy Summer DAO, Ethereum Timelock, Merkl, and recovery-ledger owner own the sequence. Exit requires Executed status, mainnet receipts, the campaign root, the claim surface, and asset-conservation reconciliation.
  5. Pending · as of Jul 27, 2026. Any deployment continuing Fleet service still needs reusable protocol accounting and peer-credit correction, followed by economic acceptance against installed state. Protocol governance, implementation maintainers, security reviewers, and the deployment owner own this route. Acceptance requires a pinned fix and artifact, upgrade or migration transaction, initialized state, regression result, and production post-state reads. The merged public artifacts cover governance and distribution tooling.
  6. Unknown · requires evidence after Jul 27, 2026. Final realizable value of impaired positions, post-Merkl reconciliation of user and residual rights, restored service scope, and any later installed public accounting correction remain open. The DAO, recovery-ledger owner, legal and compliance teams, and each chain's deployment owner own these records. Closure requires pinned valuation and exit evidence, a public eligibility rule, funding transactions, per-deployment service state, and post-fix negative replay.

The reusable invariant is one sentence: value newly reported by one module cannot obtain unlimited cash rights against other modules before source and realizability are confirmed. LowerRisk has closed its named dangerous path through emptying and removal. Incident closure still requires the HigherRisk target disposition and on-chain reconciliation of user distribution. Any deployment resuming Fleet service also needs installed, tested accounting and credit logic that closes peer-funded gain in historical replay while preserving ordinary operation.

Research record

8Evidence, objects, and sources

The material below preserves the identifiers and references used in this report.

8.1Research objects

Products, actors, techniques, affected objects, and control points discussed in the report.

Exploit transaction0x0db528c44f23fc7fa4544684a2fab81096450a14aae8bc89f42cd0592d43da12

Atomic exploit in Ethereum block 25,471,348

Attacker EOA0x7BF716167B48CF527725722C6d79494b45B3BDCa

Originated the transaction and retained final control

Executor0x0514F827C129C16418a0933E03C99A6AF982FC61

Executed flash loans, donations, and nested redemptions

Lower Fleet0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17

Principal USDC impact of about $5.64 million

Upper Fleet0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06

Fair-valued Term-donation impact of about $0.40 million

Deployment-exact Fleet source0f3353093223704060cccd187fd0e0403f69d59f

Fleet, cache, configuration, and HigherRisk adapter source corresponding byte-for-byte to verified deployments

Deployment-exact LowerRisk adapter source15c43a911674ef971a4dba7cd7ab7398b38e409a

Exact-matching SiloManagedVaultArk source

Pre-incident repository snapshotf7ea3655e8ea83a3cb0b7773b49cbc8b91ae2f18

Dated active-repository and deployment-record anchor

LowerRisk cleanup transaction0x7bead580b8d610e56949fb4162384e6e31dec24ad3b4668d8f4bddc345f14fd4

Executed phase-one transfer of donated vgUSDC to the Foundation Safe

Current-state observation block0xe7ebbbc3a892b47ee621a6637624a2ae6cfa685af18f727ebf3f152036b9dd2a

Ethereum block 25,623,214 used for Ark membership, pause-state, and withdrawable-asset reads

Affected patternzero-cap active Ark → direct share donation → global totalAssets → cross-Ark redemption

Zero-cap Ark awaiting removal settled immediately by pooled liquidity

8.2Event chronology

  1. Curator Safe set target Ark parameters to zero

    Curator Safe 0xa16f07b4…6096d3d stopped new routing while the Ark remained in active accounting.

  2. Guardian Module established

    SIP0.2 established the Guardian Module before the incident.

  3. Atomic exploit executed

    Morpho flash borrowing, Fleet and Term deposits, Silo- and Term-share donations, two Fleet redemptions, swaps, and repayment completed in one transaction.

  4. Alert received

    Summer.fi response began.

  5. Affected Vault caps set to zero

    Block Analitica set the affected Vault caps to zero, disabling new user deposits.

  6. First incident Guardian transaction prepared

    Responders set up the transaction, alerted all Guardian signers, and queued DAO-managed-vault cap-zero and pause actions.

  7. DAO vault caps zeroed and four chains paused

    At 10:25, two DAO-managed vault deposit caps were set to zero and Ethereum and Base paused; Arbitrum and Sonic followed at 11:38.

  8. LowerRisk phase one executed

    Transaction 0x7bead580…fd4 moved raw 19,551,517,226,711,127 vgUSDC from the LowerRisk Silo Ark through the Raft to the Foundation Safe.

  9. SOSEC source and accounting review completed

    Ark balances, Fleet pricing, sorted withdrawals, and final settlement transfers were reconciled.

  10. Historical pre-cleanup anchor recorded

    At block 25,573,400, both target Arks remained active and non-buffer; the HigherRisk Ark still held 439,778.128542 Term shares.

  11. SIP1.7 and SIP1.8 recorded as Executed

    The governance detail pages later record both satellite batches as Executed. The LowerRisk batch removed 18 zero-balance Arks including the target Silo Ark and requested the Syrup exit. The HigherRisk batch removed 31 zero-balance Arks, requested the Origin exit, and retained the funded target Term Ark. Both Fleets were repaused at the end.

  12. Cleanup and distribution tooling merged

    Pull requests #888 and #890 merged governance batches, distribution configuration, and withdrawal tooling; those changes did not install a reusable protocol-accounting repair.

  13. Latest on-chain disposition rechecked

    Block 25,623,214 confirmed the LowerRisk target removed from the active set and zero. The HigherRisk target remained active with reported and withdrawable value of 194,770.592290 USDC. Both Fleets were paused.

  14. SIP1.9 entered the timelock

    The official governance interface marked SIP1.9 Queued after a 100% For result and 105% quorum progress, and displayed an executable time of Jul 28, 2026 08:06 UTC. It proposes moving 4,132,125.591039 USDC from both buffers into Merkl and had no mainnet execution receipt.

8.3Sources and material

  1. Summer.fi official post-mortemhttps://blog.summer.fi/lazy-summer-usdc-vault-exploit-post-mortem-what-happened-and-what-comes-next/
  2. Public technical reconstructionhttps://gist.github.com/halaprix/52bd5e32b35be100dc40ba30539e4169
  3. Ethereum exploit transactionhttps://etherscan.io/tx/0x0db528c44f23fc7fa4544684a2fab81096450a14aae8bc89f42cd0592d43da12
  4. Attacker EOA historyhttps://etherscan.io/address/0x7BF716167B48CF527725722C6d79494b45B3BDCa
  5. Exploit executor historyhttps://etherscan.io/address/0x0514F827C129C16418a0933E03C99A6AF982FC61
  6. Lower USDC Fleet contracthttps://etherscan.io/address/0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17
  7. Upper USDC Fleet contracthttps://etherscan.io/address/0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06
  8. Summer Earn Protocol active repositoryhttps://github.com/OasisDEX/summer-earn-protocol
  9. Deployment-exact FleetCommander deposit, redeem, total-assets, and sorted-withdrawal sourcehttps://github.com/OasisDEX/lazy-summer-protocol/blob/0f3353093223704060cccd187fd0e0403f69d59f/packages/core-contracts/src/contracts/FleetCommander.sol
  10. Deployment-exact FleetCommanderCache active-plus-buffer summation sourcehttps://github.com/OasisDEX/lazy-summer-protocol/blob/0f3353093223704060cccd187fd0e0403f69d59f/packages/core-contracts/src/contracts/FleetCommanderCache.sol
  11. Deployment-exact LowerRisk SiloManagedVaultArk balance and conversion sourcehttps://github.com/OasisDEX/summer-earn-protocol/blob/15c43a911674ef971a4dba7cd7ab7398b38e409a/packages/core-contracts/src/contracts/arks/SiloManagedVaultArk.sol
  12. Deployment-exact HigherRisk Term ERC4626Ark balance and conversion sourcehttps://github.com/OasisDEX/lazy-summer-protocol/blob/0f3353093223704060cccd187fd0e0403f69d59f/packages/core-contracts/src/contracts/arks/ERC4626Ark.sol
  13. Exact-match verified Term Summer.fi USDC strategy and decoded LowerRisk constructor bindinghttps://etherscan.io/address/0xA9ca4909700505585B1aD2a1579dA3b670FFA9c4#code
  14. Deployment-exact Term Strategy cash-routing and harvest sourcehttps://github.com/term-finance/yearn-v3-term-vault/blob/10e9c8e5254c5a5ab601cd6faa0b9ac34c2b27f2/src/Strategy.sol
  15. Term-pinned Yearn TokenizedStrategy stored-total-assets and report sourcehttps://github.com/yearn/tokenized-strategy/blob/7bf187015f5f7159276f80cd52204431ab1b3b8b/src/TokenizedStrategy.sol
  16. Exact-match verified Yearn TokenizedStrategy v3.0.2 implementationhttps://etherscan.io/address/0xBB51273D6c746910C7C06fe718f30c936170feD0#code
  17. Deployment-exact Ark cap, active set, and removal-condition sourcehttps://github.com/OasisDEX/lazy-summer-protocol/blob/0f3353093223704060cccd187fd0e0403f69d59f/packages/core-contracts/src/contracts/FleetCommanderConfigProvider.sol
  18. Pinned LowerRisk USDC mainnet deployment recordhttps://github.com/OasisDEX/summer-earn-protocol/blob/f7ea3655e8ea83a3cb0b7773b49cbc8b91ae2f18/packages/deployment/deployments/fleets/LazyVault_LowerRisk_USDC_mainnet_deployment.json
  19. Pinned HigherRisk USDC mainnet deployment recordhttps://github.com/OasisDEX/summer-earn-protocol/blob/f7ea3655e8ea83a3cb0b7773b49cbc8b91ae2f18/packages/deployment/deployments/fleets/LazyVault_HigherRisk_USDC_mainnet_deployment.json
  20. LowerRisk cleanup batch and governance-tool commithttps://github.com/OasisDEX/summer-earn-protocol/commit/124733c076d946406411d6625d472de7a1af5692
  21. HigherRisk Term-Ark cleanup batch commithttps://github.com/OasisDEX/summer-earn-protocol/commit/b77fe629cce928efb08ce86722af40a629fa314e
  22. Executed LowerRisk phase-one cleanup transactionhttps://etherscan.io/tx/0x7bead580b8d610e56949fb4162384e6e31dec24ad3b4668d8f4bddc345f14fd4
  23. July 27 current-state Ethereum block 25,623,214https://etherscan.io/block/25623214
  24. Merged governance, distribution, and Fleet-cleanup batch pull request #888https://github.com/OasisDEX/summer-earn-protocol/pull/888
  25. Merged withdrawal and disposition tooling pull request #890https://github.com/OasisDEX/summer-earn-protocol/pull/890
  26. SIP1.7 LowerRisk satellite execution recordhttps://summer-earn-gov-validator.vercel.app/proposal/113308499862445396638913366510244443366332974733899784453561614539764834303240
  27. SIP1.8 HigherRisk satellite execution recordhttps://summer-earn-gov-validator.vercel.app/proposal/71502614029582003376036239616238578321854490543824431096904656935150123249272
  28. SIP1.9 user-distribution proposal and current timelock statehttps://summer-earn-gov-validator.vercel.app/proposal/54191659210043765627673008203795673868092947581324612664017412778647440568059
  29. Official Lazy Summer contract-address registryhttps://docs.summer.fi/lazy-summer-protocol/lazy-summer-protocol/contracts-addresses
  30. LowerRisk SiloManagedVaultArk verified sourcehttps://etherscan.io/address/0x61d7063041d83C8ca3E42c39181dFd14B3Bc76c2#code
  31. HigherRisk Term ERC4626Ark verified sourcehttps://etherscan.io/address/0xfD899321B1FD8d75e255119766D9097C98568519#code
  32. Summer.fi July 15 wind-down and protocol-status noticehttps://blog.summer.fi/sunsetting-summer-fi-and-the-labs-company/
  33. EIP-4626 Tokenized Vault Standardhttps://eips.ethereum.org/EIPS/eip-4626
  34. OpenZeppelin ERC-4626 implementation and security guidancehttps://docs.openzeppelin.com/contracts/5.x/erc4626
  35. Morpho flash-loan documentationhttps://docs.morpho.org/learn/concepts/flashloans
  36. 2025 curator-Safe batch setting the target Ark parameters to zerohttps://etherscan.io/tx/0x1143847e4a297f630788503f06da8a68c168e1e7d3c4301cfd3d49d4f46649f7