Summer.fi, a DeFi yield-optimization protocol also known as Summer Finance, paused its Lazy Summer Protocol vaults early on July 6, 2026, after an attacker drained roughly $6 million in a single transaction. Blockchain security firm Blockaid flagged the breach shortly after 4 a.m. ET, and on-chain analysts at Cyvers and CertiK confirmed the exploiter had gamed the way the protocol counted assets inside its vaults. Using a $65.4 million flash loan, the attacker engineered a $70.9 million redemption and walked away with about $6 million after repaying the loan. The stolen funds, mostly in the DAI stablecoin, moved to an attacker-controlled wallet. Summer.fi’s SUMR token dropped more than 18% as the news spread.
A flash loan is an uncollateralized crypto loan that must be borrowed and repaid inside the same blockchain transaction, which lets an attacker briefly command tens of millions of dollars at almost no upfront cost.
- Summer.fi paused its Lazy Summer vaults on July 6, 2026 after an attacker drained about $6 million, mostly in DAI.
- The exploiter used a $65.4 million flash loan from Morpho to force a $70.9 million redemption by manipulating the vaults’ asset accounting.
- The SUMR token fell more than 18%, and the protocol held roughly $22 million in total value locked before the attack.
- Summer.fi said guardians paused affected vaults to stop further losses; a full post-mortem has not been published.
Published: July 6, 2026 16:30 UTC
How the attack worked
The exploit targeted the accounting logic that Lazy Summer uses to price vault shares. Lazy Summer is an automated yield platform that shuffles deposits across lending markets such as Aave and Morpho in search of higher returns, rebalancing on behalf of users. Its FleetCommander contract tracks the total assets held across those markets, and that number determines how many shares a deposit is worth.
According to CertiK, the attacker first accumulated shares in a specific vault, Silo: Varlamore USDC Growth, then donated assets into the connected contract mid-transaction to inflate the recorded total. That distortion let a roughly $64.8 million deposit be redeemed for $70.9 million. The gap, about $6 million, was the profit. Cyvers said the attacker then swapped the proceeds into DAI and sent them to a wallet under their control.
The entire sequence, from the $65.4 million flash loan to the final withdrawal, ran atomically in one transaction on Ethereum. Guardians paused the affected vaults after the fact, but the funds were already gone by the time alerts reached the protocol’s team.
Why a $22 million protocol matters
Summer.fi is not a top-tier protocol by size, holding around $22 million in total value locked before the attack. The mechanics, though, echo a pattern that keeps hitting yield vaults across DeFi: a pricing or accounting function that trusts a value an attacker can move, combined with cheap flash-loan capital to move it.
These automated vaults appeal to users because they promise hands-off returns, routing money to whichever lending market pays most at a given moment. That same automation widens the attack surface. When a vault’s share price depends on a live measure of assets held elsewhere, anyone who can distort that measure for a single block can mint value out of nothing. June saw crypto projects lose about $75.87 million to exploits, and DeFi platforms remained a favored target.
The incident also feeds a broader worry regulators have started voicing. The IMF recently warned that tokenization can spread financial shocks faster than traditional plumbing, and composable DeFi, where protocols plug into each other’s liquidity, is the clearest example of how one contract’s flaw can pull in capital from several others in seconds.
What happens next
Summer.fi confirmed it was investigating and said the root cause was still unconfirmed. The usual playbook from here involves a public post-mortem, an attempt to contact the attacker with a bounty offer, and a decision on whether the protocol or its backers will reimburse affected depositors. None of those steps had been announced by press time.
For users, the immediate signal is the pause itself: deposits in the affected vaults are frozen while the team assesses damage. For the wider market, the attack is another data point in a rough stretch for on-chain security, and a reminder that yield-optimizing vaults carry smart-contract risk that a headline APY does not price in.
Frequently asked questions
What is Summer.fi?
Summer.fi, also called Summer Finance, is a DeFi protocol that automates yield farming. Its Lazy Summer Protocol moves user deposits across lending markets like Aave and Morpho to chase higher returns, rebalancing positions automatically rather than requiring users to manage them by hand.
How did the attacker steal $6 million?
The attacker took a $65.4 million flash loan and manipulated how Lazy Summer counted the assets backing its vault shares. That let a roughly $64.8 million deposit be redeemed for $70.9 million, leaving about $6 million in profit after repaying the loan, which was swapped into DAI.
Are user funds safe now?
Summer.fi paused the affected vaults to prevent further losses, so remaining deposits in those vaults are frozen while the team investigates. The protocol has not yet published a full post-mortem or said whether affected users will be reimbursed.








