BlocktoBlockto
Summer Finance Loses $6 Million in Flash Loan Exploit
BLOCKCHAIN NEWS

Photo: Illustrative

Summer Finance Loses $6 Million in Flash Loan Exploit

DeFi yield-optimization protocol Summer Finance, also known as Summer.fi, was exploited for $6 million on Monday, according to multiple blockchain security firms tracking the incident. Security platform Blockaid flag the breach early Monday morning, with additional details following from other analysts.

Laurisa
By Laurisa

Junior Author · July 6, 2026

2 min
Key takeaways
DeFi yield-optimization protocol Summer Finance, also known as Summer.fi, was exploited for $6 million on Monday, according to multiple blockchain security firms tracking the incident.
Security platform Blockaid flag the breach early Monday morning, with additional details following from other analysts.
How the Attack Unfolded According to security firm Cyvers, the attacker exploited a vulnerability in how the protocol accounted for user shares, using price manipulation before converting the stolen funds into DAI stablecoin and moving them to a separate wallet.

DeFi yield-optimization protocol Summer Finance, also known as Summer.fi, was exploited for $6 million on Monday, according to multiple blockchain security firms tracking the incident. Security platform Blockaid flag the breach early Monday morning, with additional details following from other analysts.

How the Attack Unfolded

According to security firm Cyvers, the attacker exploited a vulnerability in how the protocol accounted for user shares, using price manipulation before converting the stolen funds into DAI stablecoin and moving them to a separate wallet.

attacker appears to have exploited a share accounting vulnerability through price manipulation

Security firm CertiK offered a more detailed breakdown, saying the attacker took out a $65.4 million flash loan to secure a $70.9 million redemption. The exploit centered on how Summer.fi’s Lazy Summer Protocol calculated total assets across its vaults. The protocol relies on automated systems, described as AI keepers, that shift user deposits across various lending platforms to optimize yield.

CertiK explained that the attacker deposited close to $64.8 million and was able to withdraw $70.9 million by manipulating asset calculations tied to FleetCommander, the smart contract that oversees the vaults. The attacker reportedly built up a position in one specific vault, tied to Silo’s Varlamore USDC Growth strategy, and donated those funds to a connecting contract known as the Ark shortly before the exploit.

Protocol Yet to Confirm Breach

Summer.fi has not officially acknowledged the exploit, and the precise root cause has not been confirmed. The incident adds to a growing list of flash loan attacks targeting DeFi protocols that rely on automated vault accounting systems.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.

Summer Finance Loses $6 Million in Flash Loan Exploit — Blockto - Blockto