Summer.fi is shutting down. The DeFi lending protocol announced it will cease operations after a $6.04 million exploit on July 6 drained its vaults and wiped out the capital the team needed to rebuild. The app will remain live until August 31 to allow users to withdraw funds, but the protocol itself will not continue.
How the exploit worked
The attacker manipulated the share price across two of Summer.fi's USDC vaults on Ethereum. LazyVault_LowerRisk_USDC lost about 5.64 million USDC, while LazyVault_HigherRisk_USDC lost roughly 0.40 million USDC. A meaningful portion of Summer.fi's own capital was held in those vaults, leaving the team without the resources to recover.
What happens to user funds
The Lazy Summer DAO is working to restore withdrawals and redemptions across all vaults. The app stays accessible until the end of August, giving users a window to pull their assets. The team hasn't disclosed whether all funds will be recoverable, but the DAO's efforts are ongoing.
A growing list of protocols that couldn't survive
Summer.fi joins a short but growing list of DeFi projects that folded after a breach. Radiant Capital suffered a $50 million exploit in June and did not recover. Step Finance lost its treasury in a hack in February and shut down. The pattern is familiar: a single exploit can erase not just user funds but the operational capital needed to keep the lights on.
The August 31 deadline
The team has set a hard cutoff. After August 31, the app goes dark. Users who haven't withdrawn by then may lose access to their funds permanently. The DAO is racing to ensure all vaults are functional for redemptions before that date.




