TL;DR
-
Summer.fi has suspended its Lazy Summer vaults after a security exploit resulted in the theft of approximately $6 million.
-
The attacker reportedly used a flash loan to manipulate the protocol's accounting system.
-
Stolen funds were allegedly swapped into DAI before being transferred to the attacker's wallet.
Decentralized finance (DeFi) platform Summer.fi has temporarily suspended its Lazy Summer vaults after a security exploit drained approximately $6 million from the Ethereum-based yield protocol.
The protocol confirmed the incident after blockchain security firms detected suspicious activity, with emergency measures implemented to prevent further losses while an investigation continues.
Flash Loan Attack Targeted Lazy Summer Vaults
Lazy Summer is an automated yield optimization platform that allocates user deposits across lending protocols such as Aave and Morpho, automatically rebalancing positions to maximize returns.
According to preliminary investigations, the attacker exploited the protocol using a large flash loan, reportedly obtained through Morpho.
Security researchers believe the exploit manipulated the accounting logic of Lazy Summer's automated USDC vaults, allowing the attacker to artificially inflate the value of the vault's assets before redeeming them for a profit.
The suspicious activity was initially identified by blockchain security firm Blockaid, with PeckShield and CertiK also reporting the exploit shortly afterward.
🚨Blockaid's exploit detection system has identified an ongoing exploit on @summerfinance_.
— Blockaid (@blockaid_) July 6, 2026
~$6M drained so far.
More details in 🧵
Summer.fi later confirmed the incident, stating that protocol guardians had paused all affected Lazy Summer vaults as a precautionary measure to stop any additional unauthorized withdrawals.
The team said it is actively investigating the attack and working to determine its full impact.
Stolen Funds Converted to DAI
According to DeFi security researcher Bhari, the attacker exploited a vulnerability that allowed the protocol to overstate its total assets.
After extracting the funds, the attacker reportedly swapped the stolen assets into DAI using the decentralized exchange Curve before transferring the funds to a wallet under their control.
The exact identity of the attacker remains unknown. The exploit had an immediate impact on Summer.fi's native governance token.
Following news of the attack, SUMR declined by more than 11% as investors reacted to the security breach.
Before the exploit, Summer.fi held approximately $22 million in total value locked (TVL), according to data from DeFiLlama, meaning the stolen funds accounted for a significant portion of the protocol's assets.
The incident adds to a growing list of DeFi exploits in 2026, highlighting the ongoing security risks facing automated yield protocols and smart contract-based financial applications.
Hassan Maishera