Summer.fi attackers exchanged 1.35 million DAIs for ETH and transferred to Tornado Cash
The hackers in the Summer.fi attack have exchanged 1.35 million DAIs for Ethereum (ETH) and transferred funds to Tornado Cash, a sanctioned cryptocurrency mixing platform. The move could seriously hinder the recovery of funds under the DeFi loan agreement.
Summer.fi is an Ethereum-based DeFi front-end that provides users with a loan protocol interface. The attack resulted in the loss of user funds. The attacker then exchanged the stolen DAI stablecoin for ETH, which was then transferred to the well-known mixing-currency service Tornado Cash.
This series of operations follows a common pattern in DeFi attacks, from attack occurrence to asset conversion to deposit into a mixed-currency platform. On-chain activity related to the attacker can be tracked on Etherscan through the corresponding Ethereum wallet address.
Summer.fi had previously confirmed that it was under attack and suspended all Lazy Summer protocol vaults as an immediate response.
Why exchanging DAI for ETH is crucial to tracking attacks
DAI is a decentralized stablecoin pegged to the U.S. dollar and its value is relatively stable. As a native asset of Ethereum, although the price of ETH fluctuates, it is necessary to interact with mixed currency protocols and other on-chain concealment tools.
The attacker exchanged 1.35 million DAI for ETH, thereby converting traceable stablecoin positions into more liquid native assets. Analysts monitoring the flow of funds after an attack often view such swaps as a precursor to money laundering.
The act of redemption itself is a deliberate step. Stablecoins like DAI could theoretically be frozen or blacklisted by issuers or governance mechanisms, while ETH transactions cannot be reviewed at the protocol level. Rapid redemption reduces the window of time for any intervention.
What does it mean to switch to Tornado Cash
Tornado Cash is a decentralized mixed currency protocol on Ethereum that can cut off the chain association between sender and recipient addresses. The U.S. Treasury Department\'s Office of Foreign Assets Control (OFAC) added Tornado Cash to its sanctions list in 2022, citing the platform being used to launder billions of dollars in cryptocurrency, including funds stolen by North Korea-linked hackers.
Attackers transferred stolen funds through Tornado Cash, which could make it difficult for investigators and blockchain analysis companies to track the ultimate destination of stolen assets. The mixed-currency platform collects deposits from multiple users and allows withdrawals to new addresses that have no visible connection to the original source.
The use of sanctioned mixed-currency platforms also raises legal complexities. Any entity or individual that knowingly facilitates transactions involving Tornado Cash could face regulatory review under U.S. sanctions law, adding another layer of difficulty to potential fund recovery.
What Summer.fi users should pay attention to
In addition to the 1.35 million DAIs visible in the attacker\'s financial flow, the specific scope of this attack\'s impact on users has not been independently confirmed. Users who deposit assets through Summer.fi vault should pay attention to the official announcement of the agreement team.
The Summer.fi team has confirmed the incident through its official X account. At the time of writing, details about whether more funds were damaged, what loopholes were exploited, and whether recovery plans were being developed remained limited.
This incident is another example on the DeFi security incident list in 2026, testing the protocol\'s risk resistance and user trust. Although the attacker transferred funds to Tornado Cash, whether his identity can be revealed will depend on the depth of on-chain forensic analysis and whether the attacker made any operational security mistakes before mixing the coins.
Frequently asked questions about Summer.fi attackers and the flow of funds
What happened in the Summer.fi attack?
An attacker used a Summer.fi (DeFi lending front-end on Ethereum) vulnerability to obtain at least 1.35 million DAIs. The stolen funds are then exchanged for ETH and sent to Tornado Cash.
How much was the stolen amount?
The confirmed on-chain capital flows involve 1.35 million DAI. Whether more funds were damaged has not been independently confirmed.
Why would an attacker exchange DAI for ETH?
ETH is a native asset of Ethereum and is necessary to interact with mixed currency protocols such as Tornado Cash. At the same time, converting stablecoins into native assets also reduces the risk of freezing funds through governance actions.
Why is switching to Tornado Cash important?
Tornado Cash is a sanctioned mixed-currency protocol that hides the connection between sender and recipient. Using the platform may make tracking and recovering stolen funds more complex.
What unknown information is there?
The identity of the attacker, the specific vulnerability exploited, the total amount of user funds affected, and whether there is a possibility of recovery have not been confirmed. Users should follow the official Summer.fi channels for the latest news.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH