The Summer.fi team announced the cessation of operations after a hack that resulted in the theft of $6.04 million. The user interface will remain accessible until August 31, and the future of the protocol itself will be decided by the decentralized autonomous organization (DAO) governing it. The developers acknowledged: "We have concluded that there is no viable path forward for us other than ceasing operations."
The project operated for about seven years, two of which were as part of the Maker Foundation, and from June 2021 as an independent platform. During this time, over 50,000 users utilized the Oasis.app and Summer.fi services. At its peak, the total value locked in the Lazy Summer Protocol reached $200 million, but by the time of the attack, this figure had dropped to approximately $22 million, according to DefiLlama data.
Attack Details: Manipulation with Outdated Assets
On July 6, an attacker manipulated the net asset value of two USDC vaults of the Lazy Summer Protocol on the Ethereum network, withdrawing approximately $6.04 million in a single atomic transaction. The low-risk vault lost $5.64 million, and the higher-risk product lost $400,000. The attack was made possible by using Silo Varlamore USDC Growth vault tokens with outdated valuations. These were deposited into the Ark strategy, which was already being decommissioned. The deposit limit for the Ark was set to zero, but the strategy was not removed from the active FleetCommander set, so its assets continued to influence the calculation of the net share value.
A key factor was an incomplete operation: the Ark was already in the process of being disabled but was still accounted for in calculations. The team did not identify a separate error in the smart contract code. The attacker artificially inflated the asset valuation to obtain real liquid funds from other strategies, including Morpho, Spark, and Sky. To do this, they utilized flash loans totaling over $65 million.
Preparation and Consequences
According to the team, preparation for the attack began no later than April 6. Wallets associated with the attacker gradually accumulated Silo tokens, which were then used for the manipulation. After repaying the flash loans, the attacker converted the profit into DAI and directed a portion of the funds through Tornado Cash via an intermediary wallet. The developers noted that a significant portion of their own funds were in the affected vaults, depriving the project of reserves for recovery and continued operations.
Following the attack, all Lazy Summer Protocol vaults were suspended, and deposit limits in DAO-managed products were set to zero. The organization is conducting procedures to resume withdrawals and redeem shares. Once functionality is restored, they will appear in the Summer.fi interface, and the project's support service and Discord will continue operating until the end of August.
Aave founder Stani Kulechov called Summer.fi one of the pioneers of DeFi, noting: "This shows how high the stakes and costs are when creating a quality and secure access point to DeFi." The closure of Summer.fi came shortly after a similar decision by the DeFi service Zapper, whose team attributed their exit to challenging market conditions.
My analysis: This case is a vivid example of how operational shortcomings, not just code vulnerabilities, can lead to catastrophic consequences. The failure to promptly remove an outdated strategy from the active set is a gross risk management error that cost the project. The DeFi market is becoming increasingly mature, but such incidents remind us that even experienced teams are not immune to human error. In the first half of the year, crypto projects lost approximately $972 million across 207 incidents, according to Immunefi, and this hack only underscores the need for rigorous audits of operational processes.