Summer.fi said its protocol guardians were pausing all vaults across the Lazy Summer Protocol after a reported exploit on Monday.

The project said it was aware of the incident and was still investigating the root cause. It did not publish a full post-mortem or final loss figure in the initial update, so the safest reading is that the response is still in containment and fact-finding mode.

Blockaid, the on-chain security firm that flagged the exploit publicly, said its detection system had identified an ongoing attack on Summer.fi and estimated that roughly $6 million had been drained. CoinDesk also reported that Summer.fi had paused the Lazy Summer vaults after an exploit that drained about $6 million from the Ethereum-based yield platform.

Lazy Summer is Summer.fi's automated vault product, designed to route deposits through DeFi lending markets and rebalance positions for yield. That model can reduce manual work for depositors, but it also concentrates trust in smart contracts, guardians, keepers, accounting logic, and the external protocols used by each strategy.

The immediate user-facing point is narrow: Summer.fi says vaults are being paused while the team investigates. Until the team publishes a technical report, claims about the exact bug, recovery prospects, or final accounting should remain provisional.

The incident is another reminder that automated DeFi vaults need clear emergency controls and fast public communication. Pausing can limit further damage, but users still need a post-incident explanation of what failed, which vaults were affected, and how future deposits will be protected.