The Summer.fi protocol team has announced the cessation of operations following a hacker attack worth $6.04 million. The user interface will remain accessible until August 31, and the future of the protocol itself will be determined by the DAO governing it.

"We have concluded that there is no viable path forward other than ceasing operations," the developers stated. This step resulted from the fact that a significant portion of the team's own funds were in the affected vaults, depriving the project of reserves for recovery.

Summer.fi had been operational for about seven years. The team spent two years as part of the Maker Foundation and spun off into an independent project in June 2021. During this time, over 50,000 people used the Oasis.app and Summer.fi services. The total value locked in the Lazy Summer Protocol reached $200 million in the first nine months of operation but had shrunk to approximately $22 million by the time of the attack, according to DefiLlama data.

On July 6, an attacker manipulated the net asset value of two USDC vaults of the Lazy Summer Protocol on the Ethereum network and withdrew about $6.04 million in a single atomic transaction. The lower-risk vault lost approximately $5.64 million, while the higher-risk product lost about $400,000.

The attack used Silo Varlamore USDC Growth vault tokens with outdated valuations. These were deposited into the Ark strategy, which was already being decommissioned. The deposit limit for Ark was set to zero, but the strategy was not removed from the active FleetCommander set. Therefore, its assets continued to be accounted for when calculating the net value of vault shares.

A key condition for the attack was an incomplete operational process: Ark was already in the shutdown phase but still influenced the asset valuation calculation. The team did not identify a separate error in the smart contract code. The attacker exploited this to artificially inflate asset valuations and obtain real liquid funds from other strategies, including Morpho, Spark, and Sky. To execute the operation, they secured flash loans worth over $65 million.

According to the team, preparations began no later than April 6. Wallets associated with the attacker gradually accumulated Silo tokens, which were later used for manipulation. After repaying the flash loans, the attacker converted the profits into DAI. They later routed part of the funds through Tornado Cash using an intermediary wallet.

Following the attack, all Lazy Summer Protocol vaults were suspended, and deposit limits in DAO-governed products were set to zero. The organization is conducting procedures necessary to resume withdrawals and redeem shares across all vaults, including the two affected ones. After restoring the relevant functions, they will appear in the Summer.fi interface. The project's support service and Discord will continue operating until the end of August.

Aave founder Stani Kulechov called Summer.fi one of the pioneers of DeFi: "This shows how high the stakes and costs are when creating a quality and secure access point to DeFi. A lot has happened over seven years, and it was a good journey for the team."

The closure of Summer.fi came shortly after a similar decision by the DeFi service Zapper. The team explained the decision by citing difficult market conditions and an unsustainable business model. Notably, in the first half of the year, crypto projects lost about $972 million as a result of 207 incidents.

My expert opinion: This incident is a vivid example of how operational shortcomings, rather than code errors, can lead to catastrophic consequences. Projects should implement stricter lifecycle management processes for strategies, especially during decommissioning. Otherwise, even a minor administrative vulnerability can destroy years of work and community trust.