Summer turned out to be short for the DeFi sector: the Summer.fi protocol officially announced the cessation of its operational activities. The reason is a $6.04 million hack that deprived the team of its financial cushion and the ability to recover. The user interface will be available until August 31, and the future fate of the protocol itself is now in the hands of the DAO governing it.

Seven years of history and $200 million under management

The project operated for about seven years, two of which were as part of the Maker Foundation. In June 2021, Summer.fi spun off into an independent entity, first launching Oasis.app and then its own brand. During this time, over 50,000 people used the services. The peak total value locked (TVL) of the Lazy Summer Protocol reached $200 million, but by the time of the attack, this figure had dropped to $22 million.

Anatomy of the attack: outdated valuation and incomplete process

The incident occurred on July 6. The attacker manipulated the net asset value of two USDC vaults on the Ethereum network. The key vulnerability lay not in the smart contract code, but in an incomplete operational process: the Ark strategy, which was already being decommissioned, continued to influence the calculation of share values. The deposit limit was set to zero, but Ark was not removed from the active FleetCommander set.

The attacker used Silo Varlamore USDC Growth vault tokens with an outdated valuation. By depositing them into the "dormant" strategy, they artificially inflated the asset value and withdrew real liquid funds from other strategies — Morpho, Spark, and Sky. The operation required flash loans totaling over $65 million. Preparation for the attack began no later than April 6: associated wallets gradually accumulated Silo tokens. After repaying the loans, the profit was converted into DAI and partially laundered through Tornado Cash.

Financial blow and inevitable closure

The developers acknowledged that a significant portion of the team's own funds were in the affected vaults. The loss of reserves made it impossible to restore infrastructure and continue operations. After the attack, all Lazy Summer Protocol vaults were suspended, and deposit limits were reset to zero. The DAO is currently conducting procedures to resume withdrawals and redeem shares. The project's support and Discord channel will continue operating until the end of August.

Aave founder Stani Kulechov called Summer.fi one of the pioneers of DeFi, noting the high stakes and costs involved in creating a secure entry point to the sector. Notably, Summer.fi's closure came shortly after a similar decision by the DeFi service Zapper, which cited challenging market conditions and an unsustainable business model.

Analytical commentary: This incident is a stark example of how, even in the absence of code errors, operational miscalculations and insufficient process automation can lead to catastrophic consequences. In an environment where protocol TVL is declining and hackers are becoming increasingly sophisticated, every incomplete process is a ticking time bomb. For investors, this is a signal: DeFi security is not just about code audits, but also about flawless operational discipline.