Summer.fi Loses $6 Million in Flash Loan Exploit

DeFi protocol Summer.fi got hit hard Monday morning. Blockaid spotted the exploit first, flagging roughly $6 million drained from what’s called the Lazy Summer Protocol.

The attacker used a $65.4 million flash loan to pull off a $70.9 million redemption on Summer.fi’s vault system. PeckShield identified the main target as the LazyVault_LowerRisk_USDC vault — a risk-managed pool overseen by Block Analitica. At one point the vault’s displayed APY spiked to around 2.08 million percent. That’s not a typo.

Summer.fi, formerly known as Oasis.app, sits on top of the Lazy Summer Protocol. It’s a front-end that automatically routes deposits across yield sources like Aave and Morpho. The exploit contract is live at 0x0514F827C129C16418a0933E03C99A6AF982FC61, with three affected Lazy Summer contracts already on Blockaid’s list.

The protocol’s native token, SUMR, dropped 5.3% to about $0.00193 — a move that cut against a broader market up more than 1% on the day.

This is the second crypto exploit so far in July, following a rough June that saw $75.87 million lost across 40 separate hacks. The Humanity Protocol breach accounted for the biggest chunk of that.

We’ve reached out to Summer.fi for comment. More as this develops.