BTC $64,787.59 +0.82%
ETH $1,920.20 +0.80%
BNB $585.54 +2.90%
XRP $1.08 +0.45%
SOL $74.23 +1.01%
TRX $0.3283 +0.51%
DOGE $0.0700 -0.70%
ADA $0.1654 +1.03%
BCH $211.17 -0.31%
LINK $8.44 +1.23%
HYPE $53.03 -3.38%
AAVE $98.56 +0.32%
SUI $0.6931 +0.92%
XLM $0.1721 -0.96%
ZEC $475.34 +3.24%
BTC $64,787.59 +0.82%
ETH $1,920.20 +0.80%
BNB $585.54 +2.90%
XRP $1.08 +0.45%
SOL $74.23 +1.01%
TRX $0.3283 +0.51%
DOGE $0.0700 -0.70%
ADA $0.1654 +1.03%
BCH $211.17 -0.31%
LINK $8.44 +1.23%
HYPE $53.03 -3.38%
AAVE $98.56 +0.32%
SUI $0.6931 +0.92%
XLM $0.1721 -0.96%
ZEC $475.34 +3.24%

exploit

All
Article
Flash

Summer.fi Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism

Summer.fi released an analysis report on the Lazy Summer Protocol USDC treasury attack incident. The attacker manipulated the prices of two USDC treasury shares in a single atomic transaction, extracting approximately $6.04 million of depositor funds. The core of the attack lies in the calculation method of the treasury's net asset value (NAV).The attacker donated tokens that still retained the old valuation to a Silo Ark that had been suspended after the incident in November 2025 but had not yet been completely removed, resulting in an inflated total asset value of approximately 9.5%, raising the share price, which was then redeemed at an inflated price and withdrawn from the treasury's actual liquidity. The report emphasizes that this attack was not due to a contract code vulnerability, but rather a missing link in the treasury's offline process—the deposit limit for that Ark had been set to zero, yet it was still counted in the NAV of active assets.The attacker premeditatedly accumulated the required tokens three months in advance through multiple wallets and transferred part of the profits via Tornado Cash. After the incident, Guardian Multisig has suspended all on-chain treasuries and set the deposit limit to zero. The Lazy Summer DAO will discuss compensation plans for affected users and the treasury restart plan in the coming days.

AI Agent Security Risk Exposure: Attackers Can Exploit "Memory Pollution" to Induce Misoperation of Funds

The GoPlus Security team has disclosed a new type of attack in its AgentGuard AI project: inducing AI agents to perform unauthorized sensitive operations through "memory poisoning." This attack method does not rely on traditional vulnerabilities or malicious code but exploits the long-term memory mechanism of AI agents. For example, an attacker first induces the agent to "remember preferences," such as "usually prioritizing proactive refunds instead of waiting for chargebacks," and then uses vague expressions like "process as usual" or "execute as before" in subsequent instructions, thereby triggering automated financial operations.GoPlus points out that the key risk in such cases lies in the AI agent mistakenly treating "historical preferences" as a basis for authorization, leading to financial losses or security incidents in operations such as refunds, transfers, and configuration changes. To address this issue, the team has proposed several protective recommendations, including:Operations involving refunds, transfers, deletions, or sensitive configurations must require explicit confirmation in the current session.Memory-related instructions like "habit," "usual way," and "as before" should be regarded as high-risk state changes.Long-term memory must have a traceability mechanism (writer, time, confirmation status).Vague instructions should automatically elevate the risk level and trigger secondary verification.Long-term memory must not replace real-time authorization processes.The team emphasizes that the "AI agent memory system" should be viewed as a potential attack surface and should be constrained and audited through a dedicated security framework.
app_icon
ChainCatcher Building the Web3 world with innovations.