Full Sail Shuts Down After $91,000 Switchboard Oracle Exploit
- Full Sail, a capital-efficient yield protocol on the SuiSUI-- blockchain, announced its permanent shutdown on September 2, 2026, after attackers drained approximately $91,000 from three of its vaults.
- The root cause was traced to a compromised signing key in Switchboard's Move-language oracle implementation, which manipulate price feeds across multiple networks.
- The incident underscores the critical systemic risks associated with shared third-party oracle infrastructure in decentralized finance ecosystems.
What triggered the permanent shutdown of Full Sail on the Sui blockchain?
Full Sail initiated an orderly wind-down after a security breach compromised its automated vaults on August 29, 2026. The attack exploited a vulnerability in Switchboard, a prominent oracle provider used across the Sui, AptosAPT--, IOTAIOTA--, and Movement networks. Attackers gained access to a compromised signing key in Switchboard's production code, enabling them to distort price data for the IOTA token. By artificially manipulating the price feed, attackers deposited assets at heavily distorted rates and subsequently withdrew significantly more than they contributed.
Despite Full Sail implementing multi-oracle validation safeguards, the manipulated data allowed the exploit to succeed before the protocol could pause operations. The breach resulted in a direct loss of $91,000 from three specific vaults managed by the protocol. Notably, direct liquidity pool positions were reported to be untouched, isolating the damage to the automated vault structures.
How does the Switchboard vulnerability extend beyond the Sui network?
The compromise of Switchboard's oracle infrastructure had immediate and widespread repercussions across the broader Move-based blockchain ecosystem. Upon detecting the anomaly, Switchboard halted operations on four distinct networks: Sui, Aptos, IOTA, and Movement. The underlying blockchains themselves continued normal block production, but decentralized finance applications relying on Switchboard for pricing data were severely disrupted.
The impact extended significantly beyond Full Sail. The Virtue Money protocol on the IOTA network reported approximately $455,000 in losses, affecting 45 users who were liquidated based on fabricated prices. Attackers used the inflated IOTA price data to mint 4.94 million VUSD stablecoins against non-existent collateral on the Virtue CDP protocol. This incident highlights how a single point of failure in critical infrastructure can trigger cascading financial damages across multiple protocols and ecosystems simultaneously.
What is the protocol's strategy for repaying affected users?
Full Sail has committed to an orderly exit strategy, disabling new deposits and liquidity provider reward claims while shifting all pools to withdrawal-only mode. The team announced it would utilize remaining protocol-owned liquidity to compensate affected users, pledging to cover any shortfalls using its own treasury funds. This approach prioritizes the repayment of community depositors before addressing other potential claims against the protocol.

Despite these efforts, the broader context reveals significant challenges in third-party infrastructure risk management. Switchboard has not yet provided technical specifics regarding the code failure or committed to any form of financial compensation for affected users. Furthermore, Full Sail's request for financial assistance from Mysten Labs, the foundation behind the Sui network, was declined.
Withdrawal and claim instructions are expected to be published shortly, alongside a comprehensive incident report in the coming days. The shutdown serves as a stark reminder of the fragility of decentralized finance protocols that rely heavily on centralized or semi-centralized oracle providers. Smart contract audits alone cannot mitigate risks stemming from incorrect external data supplied by compromised infrastructure.
Why does this incident matter for future DeFi security standards?
This event reinforces the necessity for robust oracle security standards and the diversification of data sources in decentralized finance. Previous incidents, such as the 2025 Cetus hack on Sui, have already highlighted the dangers of infrastructure vulnerabilities, but this incident demonstrates the unique risks of cross-chain oracle dependencies. Protocols must increasingly rely on decentralized data sources, time-weighted averaging, deviation checks, and fallback oracles to mitigate such threats.
The Full Sail shutdown illustrates that even financially sound protocols can fail due to third-party infrastructure vulnerabilities rather than internal insolvency. As the industry evolves, the concentration of critical services like oracles among a few providers creates systemic risks that extend far beyond individual chain security. Investors and developers must recognize that infrastructure security is a broader concern that requires continuous monitoring and diversification.
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet