New SummerFi DeFi exploit shows AI automation now sits above smart contract risk

Summary

Blockaid said on July 6 that Summer.fi’s automated vault system was under active exploit and that roughly $6 million had been drained at the time of detection. Summer.fi later confirmed awareness, began investigating the root cause, and paused all vaults across the Lazy Summer Protocol. The final loss and cause are still unconfirmed pending a full incident review. The incident highlights risks in delegated DeFi yield systems. Lazy Summer is designed as a “set-and-forget” product using Lazy Vaults/Fleets, where a Fleet Commander handles deposits, withdrawals, and allocation; ARKs run yield strategies; and RAFT harvests and compounds rewards. Keeper AI Agents can also rebalance assets within governance-set constraints. That structure shifts trust into share accounting, strategy contracts, automation, and emergency controls, making the boundary between safe automation and user exposure a central security question.