1. Overview:
Following on from SIP1.7 and SIP1.8 this SIP sweeps the USDC from the two buffer arks and transfers the USDC to a MERKL Campaign to allow users to claim the outstanding USDC from the two exploited Vaults, as per the snapshot agreed to in the RFC
2. Motivation:
After the exploited, there remains over $4.1M deposited in the Lower and Higher Risk USDC Vaults on Ethereum. These assets should be distributed to the users who had assets in the vault at the time of the Exploit. Because the attacker still had shares in the Vault, it was decided by the DAO to use MERKL.xyz to distribute the assets so the attackers shares could be removed, and affected users get back as much as possible.
It should be noted that merkl.xyz have very kindly waived their fees from this distribution, so every last unit of USDC is going to affected users.
3. Specification:
Created on the base hub and relayed via LayerZero to the mainnet timelock 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796 for execution.
Sweeps the buffer arks of 2 fleet(s) into the timelock:
LazyVault_LowerRisk_USDC buffer 0x106CBB1F445F0bFFa7894F4199EE940BF7f6dD2B: 4048374.307577 USDC
and creates ONE Merkl campaign (type 4) distributing 4132125.591039 USDC to users per the off-chain allocation JSON (per-fleet entitlements are encoded in the airdrop reasons). The fleets remain paused throughout.
Actions
PAM.grantCuratorRole(LazyVault_HigherRisk_USDC, timelock) — temporary, for setSweepableToken
DistributionCreator.createCampaign(type 4, 4132125.591039 USDC, start 2026-07-27T11:00:00.000Z, duration 3600s) — pulls the amount via transferFrom
4. Risk Assessment:
This is deemed a slightly higher risk governance proposal than most because it is using governance to 'sweep' USDC from the buffer ark, which is an action not commonly used, and then transferring a large amount of USDC to an external, third party contract.
In mitigation of this risk, the Summer DAO has regularly used Merkl for incentive and reward distributions, and the labs company requested Merkl team to review the Merkl calldata used in this proposal, which they happily did and had no issues.
It is still requested though that delegates give a thorough review of this proposal before voting on it, and raise any questions or concerns they may have.
5. Voting:
Voting YES will execute the proposal will sweep all the USDC (approx 4.13M) from the two buffer arks on the Lower Risk and Higher Risk USDC Vaults which were exploited on July 6th, and transfer them to a Merkl Campaign where users who had a balance at the time of the exploit will be able to claim their proportional share. Voting NO will not execute any code, the Vault will remain paused and no funds will swept or transferred to Merkl campaign.