Lazy Summer Protocol

Orange · 45/100

Executive summary

Lazy Summer Protocol is an automated DeFi yield aggregator on Ethereum and Base that routes deposits across external lending markets; it scores 45/100 (orange band) with high data confidence (89/100) and a 10-point penalty for unresolved incident remediation.

  • Security: Audited by ChainSecurity (January 2025, partial remediation with risk-accepted findings and one fix-introduced issue), Prototech Labs (governance package, findings not verifiable), and Sherlock (Governance V2 contest, four medium findings, no critical/high); deployed-code coverage is not independently verified for Base or Ethereum as of September 2026.
  • Incidents: Two major unresolved losses: (1) November 2025 Arbitrum USDC vault Silo/USDX depeg incident (~$1.49M user loss, no reimbursement confirmed); (2) July 2026 Ethereum donation/NAV-inflation exploit (~$6.04M loss from two USDC vaults, ~$4.3M partial recovery distributed, full reimbursement not provided); remediation in progress but status remains unresolved.
  • Governance & custody: Non-custodial; Governance V2 on Base (stSUMR holders vote via Summer Governor V2, 7-day voting period, 30% quorum, 48-hour timelock, Guardian 6-of-8 multisig for emergency pauses); Ethereum is an execution spoke; Summer.fi frontend now deactivated, protocol in withdraw-only mode after July 2026 exploit and announced wind-down.
  • Top risks: Share-price manipulation and stale external-protocol valuation (demonstrated by July 2026 exploit); dependency on external counterparties (Morpho, Aave, Silo, Compound, Euler, Fluid) with compounded smart-contract, oracle, and liquidity risk; operational wind-down and constrained exit liquidity; governance and recovery capacity impaired by company closure.
  • Strengths: Automated yield optimization with risk curation by BlockAnalitica; broad protocol integration across multiple chains; institutional-grade infrastructure with daily NAV and custodian integration docs; active bug-bounty/whitehat safe-harbor framework (SEAL, Immunefi, $100k cap).
  • Unverified: Exact deployed-code coverage for audited commits on Base and Ethereum; full tokenomics (SUMR emissions, revenue-share mechanics, on-chain verification); current TVL by chain and vault; founder identities and team track record; AI keeper claims; total user claims from July 2026 partial recovery.
  • Recommended exposure: No new allocation; existing positions should be exited during the withdraw-only window; the protocol has suffered two material incidents in nine months, the second unresolved with only ~40% partial recovery, and operations are winding down with no active deposit functionality.
  • Open questions: Verify exact recovery amount claimed by users from the July 2026 Merkl distribution; confirm current on-chain TVL and liquidity depth by vault and chain; obtain independent bytecode-match verification for all deployed contracts against audited commits; assess DAO treasury sufficiency for any future reimbursement or wind-down costs; clarify legal entity wind-down timeline and residual liability.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 3 audit(s); continuous security program bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2025-09-01 is older than a year
Incidents 20% 0 0.0 2 open incident(s), $3,230,000 at risk = 277606.3% of TVL (threshold 10%); penalty proportional to assets at risk
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $1,164 = 0% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 17/36 verified facts; 36/36 fresh (180d)

Identification

protocol identification

two sources

Lazy Summer Protocol (also branded Summer.fi) is an automated DeFi yield aggregator that routes user deposits across lending and staking markets on multiple chains, including Ethereum and Base. Identification & basic metadata

  • Name: Lazy Summer Protocol (aka Summer.fi).
  • Category: Yield aggregator / automated yield vaults.
  • Website / app: Summer.fi front-end hosts the Lazy Summer vaults (exact URL not reproducible here).
  • Docs: Summer.fi FAQ serves as protocol documentation, describing vault mechanics, yield components, and supported networks.
  • Chains: Operates on Ethereum Mainnet and Base, plus Arbitrum, Sonic, Hyperliquid; your focus chains are confirmed as active.
  • Launch date: Public launch press coverage in February 2025 describes the protocol as newly live, indicating launch around February 2025.
  • Native / ecosystem token: SUMR (SummerToken) is referenced as the reward token; APY includes “SUMR Token Rewards,” and a SUMR token listing exists on Base. Main contracts & verification status
  • A SummerToken (SUMR) contract is listed on Base; this is associated with Lazy Summer Protocol’s ecosystem token. Explorer verification status and exact vault contract addresses on Ethereum and Base are Not verifiable as of 2026-09-04 given current tool limits.
  • Aggregators (DefiLlama, DIA, Barker) surface vault-level positions for USDC, USDT, EURC, WETH, ETH on Ethereum and Base, but do not consistently expose canonical vault contract addresses; cross-checking against explorers and on-chain analytics is Not verifiable as of 2026-09-04. Protocol design & fork lineage
  • Press materials state the protocol “launches with an AI-powered yield optimizer” and is developed under the OasisDEX / Summer.fi umbrella, with a GitHub repository lazy-summer-protocol referenced. This suggests an in-house design rather than a direct fork, but explicit upstream fork attribution is Not verifiable as of 2026-09-04.
  • The protocol reallocates deposits across Aave, Compound, Euler, Fluid, Gearbox, Morpho, Sky, Spark and similar markets, using AI-powered keepers and risk caps set with Block Analitica and other curators. Audits & fork-related risk history
  • Whether Lazy Summer Protocol is a fork of a prior yield aggregator, and which specific changes were audited, is Not verifiable as of 2026-09-04.
  • In July 2026, Summer.fi halted Lazy Summer vaults after an exploit that drained about $6 million from the Ethereum-based yield platform, indicating a significant security event in the protocol’s history rather than in a separate fork.
  • Any history of malicious modifications in third-party forks of Lazy Summer Protocol is Not verifiable as of 2026-09-04. Contradiction callout > TVL & chain coverage figures differ across aggregators. DefiLlama and DIA show differing TVL numbers and chain counts for Lazy Summer Protocol (e.g., DIA reporting ~$1.1K TVL and 5 chains vs. DefiLlama reporting materially higher TVL on Base). On-chain reconciliation is Not verifiable as of 2026-09-04, so these discrepancies are a material data-quality risk.
Evidence (15)

maturity

two sources

Lazy Summer Protocol appears to be a real product, not just a landing page: the Summer.fi docs describe Lazy Summer Protocol as a hands-free lending/yield product with user-facing Lazy Vaults, deposit/withdraw flows, and strategy components such as ARKs, a Buffer ARK, and a Rebalancer. The current Summer.fi site also says the app is deactivated and that Lazy Summer Protocol is in withdraw-only mode, which indicates live product functionality existed and that the portal now mainly supports exits rather than new activity. The documentation is fairly mature and operationally oriented, with navigation for contract addresses, governance, ARKs, and a documentation query interface, which is stronger than a simple marketing site.

There is also an institutional page offering a daily NAV file and integration docs for custodians, suggesting the project has productized distribution beyond retail UX. Two important caveats stand out. First, the project’s own materials claim the protocol is open-source and provides an SDK/API kit, but that is still an unverified marketing claim from the protocol until independently confirmed.

Second, the current site states the app is deactivated and withdraw-only, so live deposits are not currently supported from the portal; that is a meaningful maturity signal, but also a sign of reduced operational scope. No strong evidence of fake metrics or template-site behavior appeared in the gathered sources. Not verifiable as of 2026-09-04: broken links, exact live deposit/withdrawal status by chain, and whether there is a publicly documented open API beyond the protocol’s own claims.

Evidence (7)

Security

bug bounty

two sources

Lazy Summer Protocol appears to have an active whitehat safe-harbor / bounty-style program rather than a conventional public bug bounty: a forum proposal for SEAL Whitehat Safe Harbor described terms of 10% of recovered funds, capped at $100,000 per incident and $100,000 aggregate, with non-retainable funds, 72-hour return requirement, and pseudonymous identity. Summer.fi’s audits page also states it maintains an active bug bounty program on Immunefi, but the retrieved snippet does not expose the payout tiers, scope, or start date. A later security notice and post-exploit coverage in July 2026 show the protocol used this rescue framework during an active exploit, but no verifiable public record in the retrieved sources confirms bounty payouts or results beyond the incident response itself.

Not verifiable as of 2026-09-04: exact launch date of the Immunefi program, full program parameters, and any completed bounty payouts/results.

Active
Yes
Platform
Immunefi; SEAL Whitehat Safe Harbor
Max payout
$100K
Since
2025-12-22
Evidence (3)

counterparty risks

two sources

Оценка на 6 сентября 2026 г.

  • Ключевая зависимость: Lazy Summer агрегирует внешние lending/yield-рынки через Arks, включая Morpho, Aave, Compound, Silo, Fluid, Sky/Spark, Euler и другие. Следовательно, пользователь принимает совокупный smart-contract, liquidity, oracle/valuation и governance-риск этих протоколов, а не только риск Summer.
  • Подтверждённый failure: 6 июля 2026 г. две USDC-ваультки Ethereum были атакованы примерно на $6.04 млн. Причиной была некомпенсированная/устаревшая оценка Silo Varlamore-актива, который оставался в активном Ark после начала offboarding. Пожертвование переоценённых shares искусственно подняло NAV/share price, после чего атакующий вывел ликвидные активы через redemption. Это подтверждает material NAV-manipulation и stale-mark risk во внешних стратегиях.
  • Контрагентный статус: Summer.fi объявила wind-down операций; интерфейс переведён в withdraw-only режим, а vault deposit caps были установлены в ноль. Это существенно повышает operational, liquidity и recovery risk даже для незатронутых vaults.
  • Оракулы и valuation: основной выявленный риск — не отдельная манипуляция ценовым oracle, а stale external accounting/valuation и circular vault dependencies (например, Yearn-обёртка, связанная с LowerRisk vault). Аналогичные ошибки в underlying protocol могут переноситься в NAV Summer.
  • Мосты: cross-chain архитектура предусматривает LayerZero и межсетевые fleet/proxy-переводы; текущая фактическая сумма bridge exposure по Base и Ethereum — Not verifiable as of 2026-09-06.
  • Custodian/CEX/MM и RWA/SPV: Not verifiable as of 2026-09-06. Прямых подтверждений custodial, CEX/MM или RWA-issuer зависимости в проверенных источниках нет.
  • Stablecoin/LST exposure: USDC — подтверждённый основной collateral/deposit asset; дополнительная концентрация по stablecoin, LST/restaking и каждой стратегии — Not verifiable as of 2026-09-06. Contradiction callout: ранее опубликованные marketing/TVL-данные показывали продолжающийся продукт с несколькими активными vaults, но после инцидента официальный статус — sunsetting/withdraw-only, caps 0. On-chain exposure percentages без Dune не подтверждены; маркетинговые агрегаты не заменяют raw-chain проверку. Сценарии: depeg/insolvency USDC или underlying market, stale NAV, liquidity freeze, bridge failure, либо дальнейший operational shutdown могут вызвать delayed redemptions, haircut или полную потерю стратегии.
Dependency failure active
Yes
Evidence (5)

crypto custody

unverified

Lazy Summer Protocol appears to be organized as a non-custodial DeFi system: the terms state the company does not custody, control, or manage user funds, and does not have access to users’ private keys. Public institutional materials also describe self-managed vaults where funds move only with the customer’s own multisig/MPC and where vaults can be ring-fenced or segregated by mandate, but that is a general product description rather than a protocol-level custody attestation. No public source found here verifies the actual custody architecture for the Base and Ethereum deployments beyond these non-custodial/self-managed descriptions, so the precise handling remains not verifiable as of 2026-09-06.

Evidence (2)

incident

one source

From November 3 to November 6, 2025, Arbitrum USDC Lower-Risk Vault: the Balancer exploit impaired USDX/sUSDX liquidity; USDX depegged, while Silo’s oracle continued reporting stale collateral values and did not liquidate. The Lazy Summer vault therefore continued valuing the position near par until withdrawals exhausted available liquidity. Approximately 250 lenders were affected, with realised user loss reported at about $1.49M USDC.

Response: deposit caps were set to zero, affected users were snapshotted, the Silo market was offboarded through SIP2.39, and recovery-monitoring contracts were deployed. No recovery or reimbursement has been confirmed; the reimbursement RFC remained open but paused as of July 31, 2026. Fixes included removing the impaired market, excluding USDX exposure from the rebuilt strategy, and adding emergency-control/risk-warning measures.

Current status: unresolved.

Date
2025-11-03
Cause
Depeg / collateral
Loss
$1.5M
Status
unresolved
Recovered
$0
Reimbursed
No
Event id
lazy-summer-2025-11-arbitrum-usdc-silo-usdx
Evidence (3)

incident

one source

Lazy Summer Protocol: Token & Share Accounting via Donation Attack on Ethereum; loss $6,040,000 (DeFiLlama hacks registry).

Date
2026-07-05
Cause
Smart-contract exploit
Loss
$6.0M
Status
status unknown
Classification
Token & Share Accounting
Technique
Donation Attack
Evidence (1)

incident

two sources

Immediate response was to pause all Lazy Summer vaults and set deposit caps to zero across networks; the team also said the situation was under active assessment and asked users not to interact with the protocol. Later coverage says the protocol/DAO was working on restoring withdrawals/redemptions and that compensation was not yet finalized.

Date
2026-07-06
Cause
Other
Evidence (3)

incident

two sources

On July 6, 2026, Ethereum mainnet: a donation/NAV-inflation exploit manipulated the share price of the LowerRisk and HigherRisk USDC FleetCommander vaults. A stale-valued Silo Varlamore USDC Ark remained active during offboarding; the attacker used flash loans to donate overvalued shares and redeem against other depositors’ liquid USDC. Affected vaults: LowerRisk USDC (~$5.64M) and HigherRisk USDC (~$0.40M).

Realised loss was approximately $6.04M; independent tracing reports attacker proceeds of approximately $6.016755M DAI plus ~$108K in residual fleet shares. Response: all vaults were paused and deposit caps set to zero; affected Ark assets were swept; governance removed legacy Arks and executed a Merkl distribution. Approximately $4.3M of remaining USDC was made claimable by affected users, representing roughly 40% recovery after socialization.

Full reimbursement was not provided; exact amount claimed by users is Not verifiable as of September 6, 2026. Root-cause fix: complete Ark removal rather than merely setting caps to zero. Current status: remediation_in_progress.

Date
2026-07-06
Cause
Smart-contract exploit
Loss
$6.0M
Attacker proceeds
$6.0M
Status
remediation in progress
Recovered
$4.3M
Reimbursed
No
Event id
lazy-summer-2026-07-06-ethereum-nav-donation
Evidence (4)

key management

unverified

Key management is organized through a multi-contract Fleet structure rather than a single vault. Each Lazy Vault (Fleet) has a Fleet Commander that controls asset allocation, user deposits and withdrawals, and share issuance; multiple ARKs execute the underlying yield strategies; and a Buffer ARK holds tokens for quick withdrawals. Operational risk and parameter settings are managed separately from execution: risk curation is described as being handled by Block Analitica through deposit caps, max-deposit caps per Ark, fleet TVL limits, and rebalance flow limits.

The docs also say advanced ARKs are added only subject to governance approval, and the protocol has SUMR governance that can approve or remove strategies and decide on protocol funds, indicating that strategy-level control is shared between governance and curated risk management rather than being fully autonomous. Some materials describe an AI Keeper Network that continuously monitors markets and rebalances vaults, but that claim appears in marketing or secondary coverage and is Not verifiable as of 2026-09-04 from the provided sources.

Evidence (7)

smart-contract

two sources

As of September 6, 2026 — Dune unavailable. On-chain verification, proxy-admin decoding, role enumeration, and timelock measurement are therefore Not verifiable as of September 6, 2026. Known addresses / architecture

  • Base governance: Governor 0xBE5A4DD68c3526F32B454fE28C9909cA0601e9Fa; SUMR token 0x194f360D130F2393a5E9F3117A6a1B78aBEa1624; Timelock/Treasury 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796 (third-party registry; not independently verified on-chain here).
  • Ethereum: the same Timelock/Treasury address is cited in governance records. A mainnet Higher-Risk WETH FleetCommander is 0x2E6abcbCCeD9Af05bc3B8a4908e0c98c29A88e10, with buffer Ark 0x88e7b6f36Ec5BB35F802f11d5807401E1f0073a2.
  • Exploit-affected Ethereum USDC vaults: LowerRisk FleetCommander 0x98C49e13bf99D7CAd8069faa2A370933EC9EcF17; HigherRisk 0xE9cDA459bED6dcfb8AC61CD8cE08E2D52370cB06. ``text SUMR holders / Governor (Base) │ cross-chain execution / LayerZero ▼ Timelock + ProtocolAccessManager ──► FleetCommander (ERC-4626) │ ├─ Buffer Ark ├─ Strategy Arks / external vaults └─ Oracle / valuation paths Guardian Safe ──► pause, zero deposit caps, cancel proposals `` Admin and exit risk
  • Governance records describe a 48-hour timelock during the April 2026 attack attempt; a later proposal targeted one-day execution delays. Current deployed delay is Not verifiable as of September 6, 2026.
  • Guardians reportedly could pause vaults, set deposit caps to zero, and cancel proposals, but could not move user funds. Pausing creates freeze/withdrawal-access risk.
  • Upgradeability, proxy type, proxy-admin ownership, owner/emergency/fee/oracle/strategy permissions, renounced roles, and whether withdrawals remain possible without governance are Not verifiable as of September 6, 2026.
  • Material incident: on July 6, 2026, two Ethereum USDC vaults lost approximately $6.04 million through NAV/share-price manipulation involving an incompletely offboarded Ark; this was not a key-compromise event.
  • ChainSecurity audited Summer Earn code, including FleetCommander/Ark functionality, but deployment-to-audited-bytecode matching and unresolved finding counts are Not verifiable as of September 6, 2026. Risk conclusion: high operational, governance, valuation, and freeze risk; admin-drain capability and proxy risk remain unconfirmed.
Evidence (5)

audit

one source

ChainSecurity — “Summer Earn Protocol” audit report. Publication date: January 14, 2025. Scope: Fleet/FleetCommander investment infrastructure, Ark contracts, Dutch auctions, rewards distribution, Pendle PT Ark, batching, SUMR vesting, access control and governance assumptions.

Critical/high/medium findings: Not verifiable as of September 5, 2026; the report page states that the most critical issues were addressed after an intermediate report, but also notes risk-accepted issues and a fix-introduced issue (“Wrong Direction for Buffer Adjustment Checks”). Findings include “State Not Updated Before Staking,” “Disembarking AaveV3Ark Can Fail,” “Tip Not Collected,” “Wrong Order Assumption in Withdrawable Arks Caching,” privileged-role issues, MEV issues, and “Removal of Arks Can Be DOSed.” Fix status: Partial remediation; several findings fixed, some risk accepted/acknowledged, and at least one issue introduced by remediation. Deployed-code coverage: Not verifiable as of September 5, 2026; no bytecode-to-audited-commit match was independently established.

Auditor
ChainSecurity
Report date
2025-01-14
Scope
Summer Earn Protocol core fleets, FleetCommander, ARKs, auctions, rewards, vesting, batching, governance/access control and related assumptions.
Findings
Most-critical issues reportedly addressed after the intermediate report; residual risk-accepted findings and a remediation-introduced issue remained. Exact severity breakdown is Not verifiable as of September 5, 2026.
Fix status
Partially fixed; several named findings fixed, some risk accepted/acknowledged; remediation introduced “Wrong Direction for Buffer Adjustment Checks.” Deployed-code coverage is Not verifiable as of September 5, 2026.
Evidence (2)

audit

unverified

Audit report publicly listed by Summer.fi for Lazy Summer Protocol; the public audit index confirms reports are available, but the exact report text was not retrieved here.

Auditor
ChainSecurity
Report date
2025-02-12
Scope
Lazy Summer Protocol (deployed code coverage not verifiable here; bytecode-match note not confirmed)
Findings
Not verifiable as of 2026-09-04
Fix status
Not verifiable as of 2026-09-04
Evidence (1)

audit

unverified

Independent media and protocol-linked materials both state the protocol launched with audits from ChainSecurity and Prototech Labs; one launch item says the protocol was backed by audits from these two firms.

Auditor
ChainSecurity and Prototech Labs
Report date
2025-02-12
Scope
Lazy Summer Protocol on Ethereum and Base (deployed code coverage not verifiable here; bytecode-match note not confirmed)
Findings
Not verifiable as of 2026-09-04
Fix status
Not verifiable as of 2026-09-04
Evidence (2)

audit

one source

Rechecked published audit record: Prototech Labs — Lazy Summer governance-package audit. Publicly available evidence continues to indicate an audit covering governance-package components, including staking, vesting, Governor V2 and staked-token modules. The exact report publication date, report text, severity breakdown and remediation table were not publicly verifiable through the reviewed sources.

No bytecode-match evidence was located.

Auditor
Prototech Labs
Report date
2025
Scope
Governance package reportedly covering SummerStaking.sol, SummerVestingWalletsEscrow.sol, SummerGovernorV2.sol and StakedSummerToken.sol; exact report scope, commit and deployed addresses are Not verifiable as of September 6, 2026.
Findings
Critical/high/medium findings: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026. Deployed-code coverage is also Not verifiable as of September 6, 2026.
Report url
https://docs.summer.fi/summer.fi/audits
Report id
doc:2a8db2aa9fb53f2b
Evidence (3)

audit

two sources

Rechecked published competitive-audit record: Sherlock — “Summer.fi - governance v2” contest/report. Scope covered Governance V2, the new governance token and upgraded staking/lock modules, including SummerStaking.sol, SummerVestingWalletsEscrow.sol, SummerGovernorV2.sol and StakedSummerToken.sol. Public researcher records aggregate four medium findings and no high findings for the contest; the protocol’s November 6, 2025 recap stated that no critical issues remained.

Exact final report publication date and complete remediation status are not verifiable. No bytecode-match evidence was located.

Auditor
Sherlock
Report date
2025-09
Scope
Governance V2, SUMR governance-token migration/transferability components, staking/lock module, vesting escrow and related cross-chain governance contracts.
Findings
0 critical, 0 high and 4 medium findings reported in the publicly indexed contest records. Named medium findings include reward-state failure when a reward token is re-added, reward calculation rounding/precision loss for low-decimal tokens, potentially unbacked staked SUMR minted by escrow, and satellite-chain governance execution restrictions. Exact final severity table is Not verifiable as of September 6, 2026.
Fix status
Partially addressed or remediation planned, but final fix status is Not verifiable as of September 6, 2026. At least one reward-token re-addition issue was publicly described as acknowledged and not fixed at disclosure. Deployed-code coverage is Not verifiable as of September 6, 2026.
Report url
https://audits.sherlock.xyz/contests/1176
Report id
doc:d7788e20b2915949
Unresolved critical
0
Unresolved high
0
Evidence (5)

audit

unverified

Audit report publicly listed by Summer.fi for Lazy Summer Protocol; the public audit index confirms reports are available, but the exact report text was not retrieved here.

Auditor
Prototech Labs
Report date
2025-02-12
Scope
Lazy Summer Protocol (deployed code coverage not verifiable here; bytecode-match note not confirmed)
Findings
Not verifiable as of 2026-09-04
Fix status
Not verifiable as of 2026-09-04
Evidence (1)

Team & Reputation

founders

two sources

Lazy Summer Protocol appears to be a product of the Summer.fi/Oasis ecosystem, not a standalone company with a clearly branded founding team, and is marketed as an institutional‑grade, risk‑managed yield aggregator on Ethereum and Base. Public, independently verifiable information on named founders and legal entity structure is very limited. ### Founders & team

  • The protocol is consistently presented as part of Summer.fi (formerly Oasis), with the GitHub repository under OasisDEX/lazy-summer-protocol, implying development by the Oasis/Summer.fi engineering team rather than a separate founding group.
  • No individual founders or core team members are named in major profiles or press coverage (DefiLlama, DIA Data, Coindesk article on the exploit, Summer.fi blog/docs).
  • Risk management for vaults is repeatedly attributed to BlockAnalitica, a known DeFi risk firm, but as an external risk curator rather than protocol founders.
  • Reality: as of 2026‑09‑04, founder identities, prior projects, and personal track records are Not verifiable as of 2026‑09‑04 from independent sources. ### Public vs. anon; credibility
  • The underlying organization (Summer.fi/Oasis) is long‑standing in DeFi lending/automation and is publicly branded with a history of front‑end and protocol products, which provides organizational credibility, but this attaches to Summer.fi broadly, not specifically to a named Lazy Summer founding team.
  • Multiple institutional integrations (e.g., Utila, references to “250+ institutional clients”) are unverified marketing claims unless backed by independent confirmation; current web data comes from Summer.fi’s own communications. ### Prior incidents / hacks
  • In July 2026, Summer.fi halted Lazy Summer vaults after an exploit that drained about $6 million from the Ethereum‑based yield platform. This is a direct, adverse operational event affecting the protocol’s risk profile.
  • Coverage attributes the exploit to the Lazy Summer vaults, not to base lending protocols like Aave/Morpho, indicating protocol‑level design/implementation risk. ### Office, jurisdiction, real business vs. web front
  • No reliable independent information on registered legal entities, physical offices, or jurisdiction specifically for Lazy Summer Protocol is available; all references route back to Summer.fi media/docs and generic protocol descriptions.
  • DIA Data, DefiLlama, Barker money and Rainbow list Lazy Summer as a real, live yield aggregator across Ethereum, Base and other chains, with concrete vault and TVL data, supporting that this is an operational protocol rather than a pure web front.
  • Legal structure (onshore/offshore; regulated entity) remains Not verifiable as of 2026‑09‑04 from independent, non‑marketing sources.
Evidence (12)

general reputation

two sources

Lazy Summer Protocol currently has a mixed reputation: it is marketed as an institutional‑grade, risk‑managed yield aggregator on Ethereum and Base, but suffered a major exploit and vault pause in July 2026, which is now the main reputational overhang. Protocol & positioning

  • Described as a yield aggregator / automated yield optimizer routing deposits across Aave, Morpho, Compound, Euler, Fluid, Sky (Maker), Spark and others, with AI‑powered keepers and risk parameters designed with BlockAnalitica.
  • Integrated into Summer.fi and institutional platforms like Utila, explicitly targeting institutional treasuries and stablecoin issuers with “lower‑risk” and “higher‑risk” vault tiers on Ethereum and Base. Exploit / security incident
  • In July 2026, a ~$6m exploit hit the Ethereum-based Lazy Summer vaults; Summer.fi paused the Lazy Summer vaults after the incident.
  • Blockchain security firms and the project confirmed funds were drained from the yield platform.
  • On-chain details, attack vector, and recovery status are Not verifiable as of 2026-09-04. Audits, risk management, and investors
  • Multiple materials highlight collaboration with BlockAnalitica for conservative risk caps and vault composition. This is framed as institutional‑grade risk, but these are unverified marketing claims without independent audit reports cited.
  • Public sources do not clearly identify formal smart‑contract audits, audit firms, or major VC investors backing the protocol. Not verifiable as of 2026-09-04. Sentiment & adoption
  • Earlier coverage and community posts were broadly positive, focusing on convenience, multi‑protocol yield, and TVL growth (e.g., ~$18m TVL shortly after launch).
  • Later institutional integrations (e.g., Utila) suggest continued interest from institutional infrastructure providers despite the exploit. Legal / regulatory / sanctions
  • No evidence of fraud, rug pull, sanctions listings, or active regulatory actions specifically targeting Lazy Summer Protocol was found. Not verifiable as of 2026-09-04 beyond open media sources. Unresolved concerns (risk analyst view)
  • Material exploit with limited public post‑mortem detail is a key unresolved risk.
  • Lack of clearly referenced, independent audits and limited transparency on governance/founders are additional concerns. Not verifiable as of 2026-09-04.
Evidence (15)

Economy

TVL: $1K

model

two sources

Economic model (as of September 6, 2026)

  • Strategy / assets in-out: Automated vaults (“Fleets”) accept primarily USDC, ETH/WETH and allocate through ARK adapters to external DeFi lending/yield venues, with keeper-driven rebalancing. Buffer ARKs retain liquidity for withdrawals; standard withdrawals use the buffer, while larger withdrawals may force unwinding from strategy ARKs and cost more gas.
  • Yield source: Underlying lending/strategy yield plus, historically, SUMR incentives; displayed APY was described as net of fees. SUMR rewards are subsidy-dependent and therefore not organic. organic_yield_pct: null.
  • Risk profile: Intended to be non-leveraged and broadly market-neutral for stablecoin vaults, but not risk-free: exposure includes smart-contract, oracle, liquidity, curator and external-protocol risk. ETH/WETH vaults remain directionally exposed to ETH. Governance materials contemplated Morpho, Euler, Fluid, Aave and higher-concentration vaults.
  • Leverage / looping / restaking: No verified protocol-level leverage or recursive looping identified; restaking exposure is not verifiable as of September 6, 2026. leverage_ratio: null.
  • Lock-ups / withdrawals / gates: No ordinary lock-up was identified; withdrawals were designed to be near-immediate when buffer liquidity was sufficient, otherwise strategy unwinds were required. After the July 6, 2026 exploit, deposits were capped/paused; an official July 30 update said unaffected vaults had reopened for withdrawals.
  • Fees / revenue: Documentation states generally 1% AUM for stablecoin vaults and 0.3% for the Ethereum ETH vault; fees are distributed through tip streams. DeFiLlama attributes 30% of tips to the DAO treasury and SUMR stakers, with 20% to SUMR stakers.
  • TVL / APY: Dune is unavailable in this run: Not verifiable as of September 6, 2026 for on-chain TVL, product breakdown, chain split, trend comparison, APY history or volatility. DeFiLlama currently reports Lazy Summer TVL of $1,145.75, 100% on Arbitrum, average APY 0%, and a 91.7% 30-day TVL decline. > Contradiction / critical finding: The supplied scope says Base and Ethereum, but current DeFiLlama reports Lazy Summer on Arbitrum and zero on Base/Ethereum. This discrepancy is unresolved without Dune. Separately, a July 6, 2026 share-accounting exploit extracted approximately $6.04m from two Ethereum USDC vaults; Summer.fi subsequently announced a wind-down, materially impairing APY sustainability and operational continuity.
Evidence (6)

reserves

one source

As of 2026-09-06, reserves/treasury are not fully verifiable. Dune/on-chain verification was unavailable in this run: Not verifiable as of 2026-09-06. Known control and addresses:

  • Base DAO treasury/timelock: 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796, identified in governance materials as the source of treasury assets. A separate Base execution Safe was 0x89b39e0007577e5aE3d9f87CAaeaC4d2A3db5B34; the proposal specified a 2-of-3 configuration.
  • Ethereum treasury: governance states that the Lazy Summer Foundation retains the Governor role and should execute transfers from the Ethereum treasury, but no distinct Ethereum treasury address was provided. Not verifiable as of 2026-09-06.
  • Emergency Guardian multisig: 0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4, 6-of-8, with authority limited to pausing vaults, setting deposit caps to zero, and cancelling risky proposals; it cannot move user funds. Composition / policy: The documented reserve is primarily a token allocation, not a verified liquid treasury balance: 200M SUMR foundation allocation, with 147M SUMR reported as remaining reserve after planned January 2026 usage. This is a protocol disclosure and not an independently verified balance. Governance also authorized approximately $100k stablecoins plus approximately $100k of SUMR for Base protocol-owned liquidity, with surplus required to return to the DAO treasury. Current risk / liabilities: On July 6, 2026, two Ethereum USDC vaults suffered an approximately $6.04M exploit. The July 30 update says remaining USDC was distributed through Merkl after socializing losses, but does not disclose a final treasury balance, reserve-backed reimbursement amount, or remaining liability. Summer.fi subsequently announced a wind-down, leaving future decisions to the DAO. Contradiction / finding: Historical DAO reporting showed approximately $726,440 treasury value in January 2026, while later treasury UI data exposed only small priced balances and many unpriced assets; neither is a current, independently verified reserve figure. Current liquid reserves, chain-by-chain balances, custody composition, attestations, and final post-exploit liabilities: Not verifiable as of 2026-09-06.
Evidence (5)

tokenomics

unverified

Lazy Summer Protocol has a native token, SUMR. The Base contract address surfaced in the search results is 0x194f360d130f2393a5e9f3117a6a1b78abea1624; the search results did not provide a verified Ethereum contract address, and Not verifiable as of 2026-09-04 for a cross-checked Ethereum deployment. The protocol describes SUMR as its governance token, and some sources also say holders can stake it for yield, but the exact mechanics are not fully verifiable from the available sources.

The tokenomics claims in the protocol’s own materials are: 1,000,000,000 max supply, with an initial float around 430M-450M SUMR; allocations are 35% community, 25% strategic partners/investors, 20% core contributors/team, and 20% foundation/treasury. Governance rights are a core utility: SUMR holders vote through the Lazy Summer DAO on protocol direction, treasury use, and strategy decisions. Revenue-share claims are partly conflicting.

One protocol-linked source says stakers receive a share of protocol revenue via “Staking V2,” with 20% of protocol revenue cited in one document, while another forum summary claims holders can receive governance power plus protocol earnings in SUMR emissions and stablecoin rewards; these are unverified marketing/communication claims because I could not confirm them on-chain here. Emissions are described as governance-controlled and “modest/predictable,” with one forum post citing about 5,000 SUMR/day, but Not verifiable as of 2026-09-04. Unlock schedule and whether announced unlocks actually happened on-chain, team/investor vesting, top-holder concentration, insider wallets, mint/blacklist/fee-switch controls, and DEX liquidity depth/main listings are Not verifiable as of 2026-09-04 with the available non-onchain sources.

The only listing/liquidity evidence found indicates SUMR is available on Base and referenced as tradable via common wallets/marketplaces, but depth and holder concentration were not verifiable.

Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 is a tail-risk stress scenario, not a base case. The strongest consistent theme across the sources is that such a drop would likely require multiple shocks at once: a deep liquidity crunch, forced deleveraging, sustained institutional outflows, and a broader macro or regulatory crisis. For Lazy Summer Protocol on Base and Ethereum, the direct protocol-specific impact is Not verifiable as of 2026-09-04 because the provided sources do not contain on-chain data, protocol disclosures, or independent balance-sheet evidence for this protocol.

Operationally, the most plausible stress channels for a DeFi yield protocol in a BTC crash are:

  • Lower collateral values if the protocol has BTC-linked collateral, wrapped BTC exposure, or strategies correlated with crypto beta.
  • User redemptions and TVL outflows as risk appetite falls and users rotate to cash or stables.
  • Strategy impairment if the protocol relies on leverage, basis trades, or external venues that suffer forced liquidations.
  • Counterparty and liquidity stress if underlying venues, bridges, or stablecoin plumbing are simultaneously pressured. What cannot be verified from the available material is whether Lazy Summer Protocol has direct BTC exposure, which chains hold the majority of its TVL, or whether any specific vaults would breach limits in this scenario. Those protocol-specific risk points are Not verifiable as of 2026-09-04. If you want, I can turn this into a chain-by-chain stress checklist for Base and Ethereum, but I would still need independent protocol data to quantify exposures.
Evidence (6)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-09-04. The provided search results do not identify Lazy Summer Protocol’s actual collateral set, chain-by-chain exposures on Base and Ethereum, or its liquidation/oracle parameters, so the impact of a 20% depeg in the largest collateral cannot be calculated from the available evidence. The only directly relevant stablecoin-stress evidence in the results is generic: large depegs have previously triggered broad liquidation and reallocation effects in DeFi, and stablecoin depegs can originate from reserve, liquidity, or exchange-specific stress, but these sources are not protocol-specific and do not support a numeric loss estimate for this protocol.

If you want a defensible stress estimate, the missing inputs are: the largest collateral asset by TVL on each chain, its debt backing, oracle source and heartbeat, liquidation threshold, and whether the protocol uses cross-chain accounting. Without those, any percentage loss figure would be speculative.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

Scope / data limitation — September 5, 2026. Dune was unavailable, so exposure by chain, vault, ARK, and counterparty cannot be measured: Not verifiable as of September 5, 2026. The analysis below is therefore structural, not a quantified top-counterparty ranking. Primary stress: largest external lending/strategy counterparty becomes insolvent

  • Expected loss path: the affected ARK cannot withdraw its position or receives impaired collateral; the Fleet’s total assets fall. The Vault’s share price then declines because it is calculated from Fleet assets divided by shares. If the Buffer ARK is insufficient, withdrawals become forced withdrawals directly from yield ARKs and may fail, delay, or realize additional slippage.
  • Who absorbs it: first, users of the affected Fleet through NAV/share-price impairment. If accounting or withdrawal ordering prevents proportional repricing, later redeemers can absorb disproportionate losses—a failure mode documented in Lazy Summer’s prior Silo-related loss discussion.
  • Compensation: no automatic contractual insurance or guaranteed Summer.fi reimbursement was verified. Any reimbursement would require DAO action; a historical proposal considered partial, proportional, or full SUMR-denominated reimbursement and an insurance fund, while acknowledging treasury limits. These were governance proposals, not a standing promise.
  • Smart-contract impact path: Vault → Fleet Commander → strategy ARK → external protocol; insolvency is reflected only when the ARK’s withdrawable balance/asset valuation is impaired. Governance can offboard/sweep the ARK and alter allocations; Base is the governance hub, with LayerZero transmitting decisions to satellite chains. Variant stresses 1. DEX/LP venue failure: asset becomes non-redeemable or depegs; ARK exits through swaps, crystallizing market impact and slippage. Users bear the loss; compensation remains discretionary. 2. Oracle failure: stale or manipulated valuation delays insolvency recognition, allowing withdrawals at an overstated NAV and transferring loss to remaining users. Oracle risk is expressly identified by Summer.fi. 3. Bridge/messaging failure: cross-chain governance or asset movement is delayed or corrupted; funds may be stranded on the affected chain, while Base governance cannot guarantee recovery. Cross-chain execution depends on LayerZero. Bottom line: absent a verified insurance reserve, the base case is socialized user loss at the Fleet level, with no automatic compensation and potentially path-dependent loss allocation.
Evidence (6)

stress scenario - committed fraud by the DAO or owners

two sources

For a committed fraud by the DAO or owners stress case, the answer is not verifiable as of 2026-09-04 from the available sources. The strongest available evidence points to a third-party exploit, not insider fraud: Summer.fi’s post-mortem says the $6.04M loss was caused by an attacker manipulating share price in two Lazy Summer USDC vaults on Ethereum, and explicitly states it was not a compromised-key or admin-privilege event and that the Guardians could not move user funds. Independent reporting likewise describes a flash-loan/accounting exploit rather than DAO or owner theft.

Because of that, there is no source-backed basis to model a DAO/owner-fraud scenario as an observed event. If you want a stress-case assumption for risk analysis, the prudent framing is:

  • Worst-case governance fraud: DAO or controller misappropriates or misdirects vault assets, causing immediate loss of principal and likely a total run on remaining deposits.
  • Recovery expectation: materially worse than the July exploit, because governance fraud usually implies insiders control remediation, disclosure timing, and asset movement.
  • Verifiability: not verifiable as of 2026-09-04, because the provided materials do not show DAO/owner fraud on Base or Ethereum, only an external exploit on Ethereum. If you need, I can turn this into a concise risk-rating line for an IC memo or diligence template.
Evidence (3)

stress scenario - primary yield source negative 30d,

one source

For a stress scenario with a negative 30-day primary yield source, Lazy Summer Protocol should be treated as yield-fragile: the protocol’s user-facing value proposition depends on continuously routing deposits to positive-yield venues, so a negative 30d primary source would likely compress vault APY and could drive flows out of the affected vault, especially in the currently conservative risk posture. The protocol’s published yield-source updates show it actively rotates across external sources such as Midas Apollo Crypto and Reserve ETH+, which means a weak or negative source can be replaced, but that also confirms yield is path-dependent rather than self-sustaining. The most material risk under this scenario is spread compression into near-zero or negative net returns after fees, keeper costs, and rebalancing friction; on some chains the live APY is already extremely low, with Base vaults near 0.03% and Ethereum USDT at 0.00% in the cited snapshot.

Because the protocol’s strategy is to optimize across external DeFi venues, a negative 30d primary source would not just reduce performance — it could also force a rebalance event that exposes users to execution risk, especially if the replacement source has thinner liquidity or a different asset profile. A prudent institutional read is:

  • Impact on users: lower or potentially negative realized yield after costs.
  • Impact on the protocol: weaker deposit retention and higher rotation pressure across chains and vaults.
  • Risk posture: elevated, because the protocol already describes itself as conservative amid broader DeFi market conditions. If you want, I can turn this into a chain-by-chain stress memo for Base vs. Ethereum with a concise severity rating for each.
Evidence (3)

Governance & Legal

governance

one source

Assessment as of September 13, 2026. Governance V2 on Base is the documented control layer: stSUMR holders propose/vote, approved calls execute through the Timelock, and cross-chain effects are relayed to satellites. Recent executed proposals show governance can change parameters; Ethereum is primarily an execution spoke.

This supports DAO governance = real, not merely symbolic, although current posture is caretaker/wind-down and the frontend is being deactivated. Control map: Labs/operating-company personnel historically built and operated the system, but the Foundation’s V1 co-governor role was reported as removed after the V1→V2 transition. The critical emergency layer is a Guardian Safe.

Current documented configuration is 8 signers with a 6/8 threshold, not the previously recorded 4/8; guardians can pause vaults, set deposit caps to zero, and cancel in-flight proposals, but cannot move funds or tune parameters. The Guardian mandate is time-limited and renewable by governance. Proposal process: proposals are created and voted on Base; the latest documented setting is a 1-day voting delay, 7-day voting period, and 1-day Timelock queue, with satellite execution afterward.

Guardian cancellation bypasses quorum for emergency proposal cancellation. ⚠️ Contradictions/gaps: a risk report describes a 48-hour Timelock delay, while the later executed governance record states 24 hours. Delay is therefore not safely resolvable from web evidence. Voting concentration and top holders: Not verifiable as of September 13, 2026 (Dune unavailable).

Multisig signer independence is also Not verifiable as of September 13, 2026; public identities/affiliations exist, but independence was not independently validated. Company linkage: OAZO APPS LIMITED, UK company no. 13258623, London registered office, SIC 62012.

Active directors: Chris Bradbury, Barron Phillips Jeter, and John Michael Yarwood. Chris Bradbury is the only active person with significant control disclosed. The current Terms page provides no usable contracting details and states the app is deactivated/withdraw-only.

Timelock
Yes
Multisig threshold
6
Multisig owners
8
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
Yes
Evidence (8)

legal & regulatory

two sources

The available evidence points to Oazo Apps Limited as the service entity behind Summer.fi’s user-facing terms: the Terms state the agreement is between the user and Oazo Apps Limited, a company incorporated and registered in England, United Kingdom, and they describe the service as non-custodial software with no custody or control over user assets. The same terms also include prohibited uses, a contact for legal issues, and reference a Privacy Policy/Cookies Policy, which indicates standard data-protection handling for the front end. The protocol appears to be a DeFi product accessed through Summer.fi; an independent writeup also says Oazo Apps Limited is only the front-end provider and that the Lazy Summer Protocol was launched by the Lazy Summer Foundation, but that foundation claim is not independently verified here and should be treated cautiously.

No regulator action, court case, or public sanctions designation against the protocol or Oazo Apps Limited was found in the gathered material, so active enforcement is not verifiable as of 2026-09-04. There is also no evidence here of mandatory KYC/AML at the protocol level; however, institutional-facing materials mention availability only to qualified purchasers in supported jurisdictions and customizable whitelists, which suggests access controls rather than universal KYC. The main legal risk is structural: a noncustodial, front-end-led interface can still face jurisdictional exposure, consumer-protection, sanctions-screening, and data-processing obligations at the entity level even if on-chain contracts are permissionless.

Active enforcement
No
Sanctioned
No
Entity
Oazo Apps Limited
Jurisdiction
England, United Kingdom
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Oazo Apps Limited', 'Lazy Summer Protocol'. OFAC SDN screening of 'Oazo Apps Limited', 'Lazy Summer Protocol': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Oazo Apps Limited
  • Lazy Summer Protocol
Sanctioned
No
Evidence (4)

Stability

stability

one source

Lazy Summer Protocol does not issue its own stablecoin; it is an automated yield platform that accepts existing stablecoins such as USDC, USDT, EURC, and USDC.e. Public web evidence also indicates the protocol has had at least one stablecoin-related depeg incident affecting underlying assets, but the exact depeg count, last depeg date, and maximum depeg percentage are not verifiable here without on-chain checks. As of 2026-09-06, the supportable classification is that the protocol itself is not a stablecoin issuer, and the underlying stablecoin depeg history is not fully verifiable.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

two sources

Lazy Summer Protocol presents a distressed risk profile following the July 6, 2026 Ethereum exploit that extracted approximately $6.04 million from two USDC vaults and the subsequent announcement that Summer.fi would wind down operations. The main residual risks are unrepaired accounting/design weaknesses, dependency on underlying protocols and oracles, impaired governance and operations, and constrained exit liquidity. Chain-level TVL and exposure split: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Share-price manipulation exploitA donation-driven NAV/PPS inflation attack affected the LowerRisk and HigherRisk Ethereum USDC vaults, causing approximately $6.04 million of depositor-value loss. The incident demonstrates that audited, verified contracts can still contain exploitable economic/accounting compositions.HighHighVaults were paused, deposit caps were set to zero, affected strategies were isolated, and post-mortem remediation was initiated.High: the exploit occurred in production and no independently verified redesign or complete compensation outcome was identified.
Underlying protocol and oracle contagionVaults inherit failures from lending markets, collateral assets, oracles, and liquidity venues. Prior incidents showed that stale or incorrect underlying valuations can delay loss recognition and make withdrawals impossible.HighHighThird-party risk curation, DAO-approved strategy selection, caps, monitoring, and proposed emergency controls.High: diversified exposure does not remove correlated oracle, depeg, liquidity, or composability risk.
Operational wind-down riskSummer.fi announced a wind-down after the exploit, weakening ongoing development, monitoring, support, and incident-response capacity.HighHighWithdrawal access was restored for unaffected vaults and final governance/settlement processes were pursued.High: continuity, maintenance, and long-term support are materially impaired.
Governance and curator concentrationRisk parameters and supported markets depend on DAO decisions, guardians, keepers, and external risk curators. BA Labs subsequently stepped down, creating transition and oversight risk.HighHighDAO governance, guardian controls, third-party reviews, and parameter caps.High: governance latency and curator turnover can leave unsafe exposure active.
Liquidity and exit constraintsPauses, zero deposit caps, strategy illiquidity, and underlying-market withdrawal limits can prevent timely exits or crystallize losses during stress. The protocol’s prior Arbitrum event demonstrated this failure mode.HighHighBuffer liquidity, keeper-led rebalancing, withdrawal reopening for unaffected vaults, and emergency pausing.High: liquidity depends on external venues and may disappear precisely when users need it.
Evidence (5)

strengths

one source

Lazy Summer Protocol’s top strengths are: automated yield optimization, risk curation, simple single-deposit access, broad protocol integration, and institutional-grade infrastructure. The protocol is described as continuously rebalancing deposits across top DeFi protocols using AI-powered keepers, with risk limits set by Block Analitica, so users do not need to manually chase yields. It also emphasizes a single interface for diversified exposure to multiple yield sources, which reduces operational friction for users compared with managing many separate positions.

Public materials say it integrates across many protocols and networks, including Ethereum and Base, which supports diversification and strategy flexibility. Finally, Summer.fi positions Lazy Summer as infrastructure suitable not only for retail vault users but also for larger institutional entities seeking onchain yield exposure.

Evidence (7)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 10 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-30.