EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Summer.fi is gradually shutting down after being attacked by a $6 million Lazy Summer Vault vulnerab

2026-07-17 00:11:40
Bookmark

Summer.fi phases down after a $6 million attack

Summer.fi is gradually disbanding its Labs company and stopping its user interface services. This follows a July 6 vulnerability attack that left the company lacking enough funds to rebuild its business.

The closure of Summer.fi marks the end of its five-year independent operation. The company separated from the Maker Foundation in June 2021, after another two years of construction within Maker. Initially operated independently under the Oasis.app brand, it was later renamed Summer.fi.

The platform has served more than 50,000 users, covering leveraged Maker positions, automated treasury management, and DeFi revenue products. In the first nine months of operation of the Lazy Summer agreement, the total value of locked positions reached approximately US$200 million. However, starting in October 2025, losses related to the collapse of Stream Finance began to put pressure on its treasury system.

A large amount of the team's own funds were also stored in vaults affected by the attack. The loss left the company lacking the funds needed to continue operations after evaluating various possible recovery paths.

Vulnerability steals US$6.04 million from two USDC vaults

The Lazy Summer vulnerability attack on July 6 stole approximately $6.04 million from two Ethereum USDC vaults in an atomic transaction. The attacker manipulated the net asset value of the vault by donating overvalued Silo Varlamore vault tokens to the policy adapter. These strategic adapters were originally restricted from exiting, but were still included in the stock price calculation. inflated valuations allow attackers to deposit funds at real prices and then redeem assets in liquidity vaults at artificially inflated prices.

The lower-risk treasury lost approximately $5.64 million, while the higher-risk treasury lost approximately $400,000. More than $65 million in flash loan stablecoins funded the deal, and the stolen assets were subsequently converted into DAI. All Lazy Summer vaults have been suspended and the deposit limit has been reduced to zero. The attacker later diverted some of the proceeds through Tornado Cash, making it less likely that all funds would be recovered through public transaction tracking.

Lazy Summer DAO retains control of the protocol

The underlying Lazy Summer protocol will not be automatically closed together with Summer.fi Its smart contracts and governance rights remain controlled by the Lazy Summer DAO, which must decide what to do with the affected treasury, remaining liquidity, and future operations. Governance agencies are working to restore withdrawal and redemption capabilities across the entire vault system, including the two attacked Ethereum products. After the attack, approximately $4 million remained in the affected pool, most of which was in an illiquid state and required a DAO-approved allocation process to process.

The closure follows the dissolution of Radiant Capital, which also began liquidation procedures after the loan agreement failed to recover from a $50 million security breach. The interface of Summer.fi will continue to run until August 31. Its support mailbox and Discord channel will also be open until the end of August, allowing users to wait for the vault's withdrawal and redemption functions to be restored.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP