The team behind the DeFi protocol Summer.fi has announced a complete cessation of operations. The reason was a $6.04 million hack that deprived the project of the financial reserves needed for recovery. The user interface will remain accessible until August 31, and the future fate of the protocol itself will be decided by the decentralized autonomous organization (DAO) governing it.

The developers stated that after seven years of work in DeFi, they see no viable path forward other than a complete shutdown. The project began its journey as part of the Maker Foundation and became independent in June 2021. During this time, over 50,000 users utilized the Oasis.app and Summer.fi services.

How the Hack Occurred

The attack was carried out on July 6. The attacker manipulated the net asset value of two USDC vaults of the Lazy Summer Protocol on the Ethereum network and withdrew funds within a single atomic transaction. The low-risk vault lost approximately $5.64 million, while the higher-risk product lost about $400,000.

The key vulnerability was an incomplete operational process. The attack used Silo Varlamore USDC Growth vault tokens with outdated valuations. These were deposited into the Ark strategy, which was already being decommissioned. The deposit limit for Ark was set to zero, but the strategy was not removed from the active FleetCommander set. As a result, its assets continued to be factored into the calculation of the vault's net asset value. The team did not identify a separate error in the smart contract code.

The attacker exploited this to artificially inflate asset valuations and obtain real liquid funds from other strategies, including Morpho, Spark, and Sky. To execute the operation, they secured flash loans totaling over $65 million. Preparation for the attack began no later than April 6 — wallets linked to the attacker gradually accumulated Silo tokens. After repaying the flash loans, the attacker converted the profits into DAI and partially routed the funds through Tornado Cash.

Consequences and Context

The total value locked in the Lazy Summer Protocol reached $200 million in its early months but had dropped to $22 million by the time of the attack. The developers emphasized that a significant portion of the team's own funds was held in the affected vaults, leaving the project without reserves for recovery.

Following the attack, all protocol vaults were suspended, and deposit limits in DAO-managed products were set to zero. The organization is conducting procedures to resume withdrawals and redeem shares. Aave founder Stani Kulechov described Summer.fi as one of the pioneers of DeFi, noting the high stakes and costs involved in creating a quality access point to the sector.

The closure of Summer.fi came shortly after a similar decision by the DeFi service Zapper, which attributed its exit to challenging market conditions and an unsustainable business model. For context, in the first half of the year, crypto projects lost approximately $972 million across 207 incidents, according to Immunefi.

My comment as an analyst: This case is a stark example of how operational shortcomings in protocol management can lead to fatal consequences. The lack of clear procedures for decommissioning outdated strategies and reliance on centralized decisions within a supposedly decentralized system undermine trust in DeFi. A project losing $6 million from team reserves simply could not withstand the blow — this is the harsh reality for protocols with low liquidity and weak risk diversification.