BlockBeats report, July 6: The DeFi yield optimization protocol Summer Finance (Summer.fi) is suspected of suffering a security breach, with on-chain analytics firms estimating losses of approximately $6 million.
The blockchain security firm Blockaid was the first to detect this security incident. Cyvers stated that the attacker allegedly exploited a vulnerability in the protocol share accounting mechanism to manipulate prices, then converted the stolen assets—approximately $6 million—into DAI stablecoin and transferred them to addresses controlled by the attacker.
CertiK further analyzed that the attacker exploited a $65.4 million flash loan to manipulate the asset valuation logic of the Lazy Summer Protocol vault under Summer.fi, successfully redeeming approximately $70.9 million in assets after depositing around $64.8 million, resulting in a profit of approximately $6 million.
It is reported that the vulnerability involves the Fleet Commander contract’s asset accounting logic for the totalAssets() function. The attacker accumulated specific vault positions in advance and influenced asset calculations by donating assets to the Ark contract, thereby executing arbitrage.
As of press time, Summer.fi has not confirmed the attack through official channels, and the root cause of the vulnerability is still under investigation.

