Summer.fi announced shutdown, resulting in more than US$6 million in losses from lightning attacks.
Summer.fi announced plans to phase out operations. Previously, a lightning attack on Lazy Summer Vaults extracted approximately $6.04 million from two USDC vaults on Ethereum by manipulating the protocol's asset valuation process. The interface, customer support and Discord channel of Summer.fi will remain open until August 31, 2026. The underlying Lazy Summer Protocol will not automatically close on this date because it is governed separately by the Lazy Summer DAO. In an official shutdown announcement, Summer.fi said the loss left the team without enough funds to support recovery efforts, infrastructure and continued operations.
Attack occurred on an already declining protocol
Summer.fi has been in operation for about seven years and became independent from the Maker Foundation in June 2021. According to reports, more than 50,000 people have used Oasis.app and Summer.fi during this period. Lazy Summer Protocol has expanded rapidly since its launch, with a total locked position value (TVL) of nearly US$200 million in the first nine months. However, before the closure announcement, its asset base had fallen significantly.
DefiLlama data from Lazy Summer Protocol shows that the TVL in the latest snapshot is approximately US$12.8 million. The tracker also recorded that total quarterly negotiated revenue fell from approximately $218,300 in the third quarter of 2025 to $47,420 in the second quarter of 2026. A decline in TVL should not be equated with user attrition, and this indicator may change due to withdrawals, token price fluctuations, treasury suspensions, and changes in asset valuation methods. Summer.fi said that a significant portion of the team's own capital was stored in the affected vaults, so the attack not only damaged user deposits, but also eroded the reserves needed to maintain project operations.
Outdated Ark valuations make attacks possible
The attacker targeted the way Lazy Summer Vaults calculates net asset value (NAV), not the intrusion management key. Lazy Summer Vaults allocates funds into policy adapters called Arks. One strategy holds Silo Varlamore USDC Growth Vault tokens, which carry outdated valuations. The Ark was originally being phased out and its deposit limit had been reduced to zero, but was not removed from the active FleetCommander collection, which means its reported assets are still affecting the vault's NAV. The attacker donated Silo tokens with outdated valuations to the Ark, artificially increasing the reported value of the vault. The inflated share price then allowed attackers to redeem true USDC liquidity from other strategies, including Morpho, Spark, and Sky. According to the official attack review report from Summer.fi, the attacker used more than $65 million in lightning loans in an atomic transaction to complete the attack. Low-risk USDC Vault lost approximately $5.64 million, and high-risk Vault lost approximately $400,000. Summer.fi said that it did not find the newly introduced smart contract coding error. The incident originated from an incomplete strategic shutdown process, which resulted in the Ark still existing in the active valuation system. The team's investigation also showed that wallets associated with the attackers began accumulating relevant Silo tokens several months before the attack. After repaying the lightning loan, the attacker exchanged the remaining proceeds for DAI, and some of the funds were then transferred via Tornado Cash.
Agreement will be taken over by DAO in the future
Summer.fi Labs is shutting down, but the Lazy Summer Protocol will still be controlled by the DAO. After the attack, the treasury was suspended and the deposit limit was set to zero. The DAO is currently completing the procedures needed to resume withdrawals and share redemptions, and these features will appear on the Summer.fi interface when ready. The team has not yet committed to fully compensating affected depositors. Any recovery plan and the long-term future of the agreement will require DAO governance decisions. DefiLlama classified the incident as a protocol logic donation attack on Ethereum. It also reported cumulative protocol revenue of approximately $232,050, which means that the $6.04 million attack size is approximately 26 times the protocol's reported lifetime revenue. This comparison does not represent the complete balance sheet of Summer.fi, but illustrates the scale of the loss relative to the revenue generated by the agreement. The incident occurred in the context of a broader loss of cryptographic security. A May 2026 crypto hacker report recorded 41 incidents totaling $84.2 million in losses. The interface and support channels of Summer.fi will remain open until August 31. After that, withdrawals, remedies and future responsibilities for the Lazy Summer Protocol will be entrusted to the DAO.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following