Full Sail DeFi Shuts Down After Oracle Cyberattack Exposes a Bigger Web3 Security Problem
A cybersecurity incident involving blockchain oracle provider Switchboard has forced Full Sail, a DeFi protocol built on the Sui blockchain, to shut down operations after attackers drained funds from several of its automated vaults.
The incident is another reminder that in decentralized finance, a protocol can have secure smart contracts and still be exposed through the third-party infrastructure it depends on.
Full Sail announced that it is winding down the platform, stopping new deposits and disabling liquidity-provider reward claims while preparing existing pools for withdrawals.
Its priority now is compensating affected users.
What Happened?
The security incident appears to have originated from a suspected compromise involving Switchboard’s oracle infrastructure.
Blockchain oracles are services that feed external information—such as asset prices—into smart contracts.
That makes them extremely important in DeFi.
Lending platforms, automated trading vaults, stablecoins, derivatives and liquidity protocols often depend on oracle data to decide things like:
- How much collateral a user has
- Whether a position should be liquidated
- What an asset is worth
- How much another token can be borrowed
- How automated vault strategies should behave
If that data source is compromised or manipulated, attackers may be able to exploit protocols that rely on it even if those protocols themselves were not directly breached.
Full Sail said the incident affected its automated vaults and ultimately resulted in approximately $91,000 being removed from three vaults.
The protocol initially paused deposits and withdrawals while investigating.
Switchboard also acknowledged that it was investigating a possible compromise involving its Move-based implementations and temporarily halted its network operations across several ecosystems, including Sui, Aptos, IOTA and Movement.
The Damage Wasn’t Limited to Full Sail
Full Sail was not the only project affected.
IOTA-based stablecoin lending protocol Virtue separately reported approximately $455,000 in losses connected to the incident.
Virtue also said the attack affected the backing of its VUSD stablecoin.
That broader impact is important.
It shows how one compromised piece of blockchain infrastructure can potentially create problems across multiple DeFi applications and even multiple blockchain networks.
This is effectively a Web3 version of a software supply-chain attack.
Instead of attacking every application individually, an attacker can target infrastructure that many applications trust.
Once that shared dependency is compromised, every connected protocol may become exposed.
Why Full Sail Is Shutting Down
Full Sail has decided that continuing operations after the incident is no longer the best path forward.
The protocol has already:
- Disabled new deposits
- Stopped LP reward claims
- Begun preparing regular pools for withdrawal-only mode
- Started working on compensation for affected users
Full Sail said it intends to use its remaining protocol-owned liquidity to repay users.
The team also said it would personally cover any remaining shortfall, with community depositors receiving priority.
Withdrawal and compensation instructions are expected to be provided separately.
This Was Bigger Than a $91,000 Hack
At first glance, a $91,000 loss might look relatively small compared with some of the hundreds of millions of dollars stolen in previous cryptocurrency attacks.
But the real cybersecurity story is not the amount stolen.
It is the dependency risk.
Modern DeFi applications are rarely completely independent.
A protocol may depend on:
- Oracles
- Bridges
- Smart-contract libraries
- Wallet infrastructure
- RPC providers
- Stablecoins
- Cross-chain messaging systems
- Front-end hosting services
- Liquidity providers
That creates a large attack surface.
A project can spend heavily auditing its own smart contracts but still suffer catastrophic losses because a trusted third-party component was compromised.
The Oracle Problem in DeFi
Oracles remain one of the most sensitive pieces of infrastructure in decentralized finance.
Smart contracts cannot automatically know the real-world market price of Bitcoin, Ethereum, Sui or another asset.
They need external systems to provide that information.
Attackers understand this.
If an attacker can manipulate an oracle, compromise its update mechanism or exploit how a protocol consumes oracle data, the attacker may be able to create artificial prices.
For example, an attacker might make collateral appear more valuable than it really is and then borrow assets against that false valuation.
Or they could trigger incorrect vault trades, liquidations or asset conversions.
This is why oracle security should be treated as part of a protocol’s core cybersecurity architecture—not simply as an external service.
What This Means for DeFi Businesses
The Full Sail incident highlights one of the biggest misconceptions in blockchain security:
Decentralized does not mean dependency-free.
Web3 companies increasingly operate complex technology stacks just like traditional businesses.
The difference is that in DeFi, software failures can directly control hundreds of thousands—or millions—of dollars.
A compromised dependency therefore does not simply create downtime.
It can immediately create financial losses.
Protocols should understand that every connected service effectively becomes part of their security perimeter.
Lessons to Learn From the Full Sail Incident
1. Audit Third-Party Dependencies, Not Just Your Own Code
Smart-contract audits are important, but they are not enough.
Teams should continuously assess the security of:
- Oracle providers
- Bridges
- External libraries
- Cross-chain infrastructure
- APIs
- Wallet integrations
If a critical external service becomes compromised, your protocol may become compromised indirectly.
2. Avoid Single Points of Failure
Depending entirely on one oracle creates concentration risk.
Where technically possible, protocols can consider multiple independent data sources, fallback pricing mechanisms or circuit breakers that activate when price feeds behave abnormally.
Redundancy is a cybersecurity control.
3. Build Emergency Shutdown Mechanisms Before You Need Them
Full Sail paused activity after discovering the incident.
DeFi protocols should have predefined emergency procedures capable of stopping:
- Deposits
- Withdrawals
- Borrowing
- Liquidations
- Vault automation
- Cross-chain transfers
Speed can determine how much money is lost during an attack.
4. Monitor Oracle Behavior in Real Time
Security monitoring should extend beyond wallet transactions and smart contracts.
Teams should monitor oracle feeds for unusual activity such as:
- Sudden price deviations
- Unexpected update frequencies
- Abnormal signer activity
- Large differences between independent price sources
- Unexpected smart-contract changes
Automated alerts can help security teams respond before attackers drain larger amounts.
5. Keep Incident Response Funds
Full Sail says it will use protocol-owned liquidity and team funds to compensate users.
While no company wants to plan around being hacked, protocols handling customer assets should consider maintaining reserves or insurance mechanisms specifically for security incidents.
Incident recovery is part of cybersecurity planning.
6. Users Should Evaluate Infrastructure Risk Too
Investors often look only at a protocol’s yield.
A platform offering attractive APY may still rely on multiple external services capable of introducing security risk.
Before depositing large amounts of crypto, users should consider asking:
- Which oracle does the protocol use?
- Has the protocol been audited?
- Are audits publicly available?
- Does it have an emergency pause system?
- Has the team previously handled security incidents?
- Is there an insurance or compensation fund?
High yield means very little if the infrastructure protecting the money fails.
Aqyreon’s Take
The Full Sail shutdown demonstrates an uncomfortable reality about decentralized finance: a protocol is only as secure as the weakest critical service connected to it.
The reported $91,000 loss at Full Sail is relatively small by crypto-hack standards.
But the simultaneous impact on another protocol makes the incident much more important from a cybersecurity perspective.
This was not simply one vulnerable DeFi application.
It was potentially a compromised infrastructure component capable of affecting several blockchain ecosystems.
For developers, the lesson is clear: treat oracles and other third-party services as part of your own attack surface.
For investors, the lesson is equally important: before chasing yield, understand what technology is actually protecting your money.
In Web3, cybersecurity risk does not always begin inside the protocol you are using.
Sometimes the vulnerability sits several layers underneath it.
That is what makes supply-chain-style attacks in decentralized finance particularly dangerous.



