DeFi Protocol Summer.fi Loses $6M in Suspected Flash Loan Attack

iconKuCoinFlash
Share
AI summary iconSummary
On July 6, 2026, a DeFi exploit targeted Summer.fi, with estimated losses of $6 million. Blockaid reported that the attacker exploited a flaw in the protocol update’s share accounting mechanism to manipulate prices. Cyvers noted that the stolen assets were converted to DAI and transferred to the attacker’s address. CertiK found that the exploit utilized $65.4 million in flash loans to manipulate the Lazy Summer Protocol’s valuation logic. The attacker redeemed $70.9 million after depositing $64.8 million. The vulnerability was linked to the totalAssets() function in the Fleet Commander contract. Summer.fi has not confirmed the attack, and the root cause remains under investigation.

BlockBeats report, July 6: The DeFi yield optimization protocol Summer Finance (Summer.fi) is suspected of suffering a security breach, with on-chain analytics firms estimating losses of approximately $6 million.


The blockchain security firm Blockaid was the first to detect this security incident. Cyvers stated that the attacker allegedly exploited a vulnerability in the protocol share accounting mechanism to manipulate prices, then converted the stolen assets—approximately $6 million—into DAI stablecoin and transferred them to addresses controlled by the attacker.


CertiK further analyzed that the attacker exploited a $65.4 million flash loan to manipulate the asset valuation logic of the Lazy Summer Protocol vault under Summer.fi, successfully redeeming approximately $70.9 million in assets after depositing around $64.8 million, resulting in a profit of approximately $6 million.


It is reported that the vulnerability involves the Fleet Commander contract’s asset accounting logic for the totalAssets() function. The attacker accumulated specific vault positions in advance and influenced asset calculations by donating assets to the Ark contract, thereby executing arbitrage.


As of press time, Summer.fi has not confirmed the attack through official channels, and the root cause of the vulnerability is still under investigation.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.