The Summer.fi team has decided to completely cease operations following a hacker attack that resulted in the theft of $6.04 million. The user interface will remain accessible until August 31, and the future of the protocol will be decided by the decentralized autonomous organization (DAO) that governs it.

The project, which operated for about seven years, encountered a fatal vulnerability not directly related to smart contract code. On July 6, an attacker manipulated the net asset value of two USDC vaults of the Lazy Summer Protocol on the Ethereum network. Using a single atomic transaction, they withdrew funds: the low-risk vault lost $5.64 million, and the higher-risk product lost $400,000.

Timeline of the Attack: An Error in the Operational Process

The attack used Silo Varlamore USDC Growth vault tokens with outdated valuations. These tokens were contributed to the Ark strategy, which was already in the process of being decommissioned. A key factor was that the strategy was not removed from the active FleetCommander set, although its deposit limit was set to zero. As a result, the Ark assets continued to be accounted for in the calculation of net share value, allowing the hacker to artificially inflate the valuation and obtain real liquid funds from other strategies, including Morpho, Spark, and Sky.

The attacker attracted flash loans totaling over $65 million. Preparations for the attack began no later than April 6 — wallets associated with the hacker gradually accumulated Silo tokens. After repaying the loans, the profits were converted into DAI and partially laundered through Tornado Cash.

Consequences: Loss of Reserves and Protocol Suspension

The developers acknowledged that a significant portion of the team's own funds were in the affected vaults. The financial losses deprived the project of the reserves needed to restore infrastructure and continue operations. "We have concluded that there is no viable path forward other than ceasing operations," project representatives stated.

After the attack, all Lazy Summer Protocol vaults were suspended, and deposit limits in DAO-governed products were reset to zero. The organization is conducting procedures to resume withdrawals and redeem shares across all vaults, including the two affected ones. The project's support service and Discord channel will continue operating until the end of August.

The closure of Summer.fi came shortly after a similar decision by the DeFi service Zapper, which cited challenging market conditions and an unsustainable business model. This highlights the vulnerability of even mature protocols to operational errors and shortcomings in risk management.

My analysis: This incident is a stark example of how incomplete operational processes can prove fatal for a protocol. The absence of a separate error in the smart contract code did not protect the project from losing $6 million. For the DeFi industry, this is a signal: security is not only about code audits but also about strict control over the lifecycle of all components. In the first half of the year, crypto projects lost approximately $972 million as a result of 207 incidents, and the Summer.fi story is another reminder that the cost of negligence can be the complete shutdown of a business.