Summer Finance lost $6M from its USDC vault. Old tokens that were never disabled let the attacker fake the share price.
The attack on Summer Finance wasn't about the vault's current code. It was about the code everyone forgot to delete.

CryptoVibe Desk · defi · exploit · summer-finance

- →An attacker drained $6M from Summer Finance's USDC vault on July 6 by accumulating retired tokens cheaply and using them to inflate the share price before withdrawing funds.
- →The exploit didn't target the current vault code but the old token state a previous architecture left behind, retired socially but never killed at the contract level.
- →Watch for other vault protocols auditing their deprecated token state in the next two weeks, before a copycat attack lands somewhere larger.
- vgUSDC → A deprecated version of Summer Finance's vault position token, no longer actively used by the protocol but still functional at the smart-contract level, which meant it could be accumulated and used to manipulate vault accounting.
- Share-price distortion → An exploit technique where an attacker manipulates how much the protocol thinks each vault share is worth, then redeems at the inflated rate and withdraws more than they deposited.
- Deprecated → Officially retired from use but not deleted at the code level: the smart contract still exists and runs if someone calls it.
- MEV → Maximal Extractable Value: extra profit that block-builders capture by choosing which transactions go into a block and in what order. A trader with a large swap can lose value to MEV if bots detect and exploit their transaction before it confirms.
Summer Finance's Lazy Summer USDC vault lost $6M on July 6. The mechanism was not a flash loan, whatever the first headlines said.
BlockSec traced it to deprecated vgUSDC tokens. The attacker accumulated them at near-zero cost. Those tokens were retired, so nobody priced them against the risk they still carried. Then the attacker used that position to distort the vault's share price and withdrew USDC against the inflated accounting.
This wasn't a bug in the current vault logic. It was a bug in what the rewrite left behind. Deprecated tokens don't cease to exist when a protocol ships a new architecture. Their contract state stays live until someone explicitly kills it. Nobody did.
Summer Finance paused all vaults and sent an on-chain message to the attacker asking for contact. Block Analitica, the vault's risk advisor, hadn't flagged vgUSDC as a live attack surface. And that's the catch: "deprecated" is a social convention. The EVM doesn't know what's retired.
If you're running a vault that has gone through any architecture rewrite, the old token state is still there. That's where the attacker looked.
The $6M was just over 25% of Lazy Summer's pre-exploit TVL, per Protos. July 6 also brought a separate ~$2M MEV incident on a Uniswap v3 pool. Different mechanism, unrelated event.
Block Analitica was the vault's risk advisor and never flagged vgUSDC as a live attack surface. Deprecated in the docs is not the same as dead in the bytecode. That difference cost $6M.
A post-mortem from Summer Finance or Block Analitica naming the specific contract state that was never killed. If none arrives within 72 hours, the vault ecosystem hasn't absorbed the actual lesson.
Primary links and supporting reads used by the desk for this story.
Forward this.











