Why Is Full Sail Winding Down?
Full Sail, a decentralized finance protocol operating on the Sui blockchain, is shutting down after a security incident involving oracle provider Switchboard caused losses across several of its automated vaults.
The protocol said Tuesday that it had started winding down operations and immediately disabled new deposits and liquidity provider reward claims. Its regular pools are expected to move into withdrawal-only mode once final security checks are completed.
Full Sail said reimbursing affected users is now its main priority. The protocol plans to use its remaining protocol-owned liquidity for compensation, while the team has committed to covering any shortfall so community depositors are repaid before other claims.
The shutdown follows an incident disclosed on Saturday, when Full Sail confirmed that funds had been lost and temporarily suspended both deposits and withdrawals while investigating the cause.
Full Sail later said an attacker removed about $91,000 from three of its vaults. Although the loss is relatively small compared with major DeFi exploits, the decision to close rather than resume normal operations shows how a security failure in a critical external dependency can threaten the viability of a smaller protocol.
What Role Did Switchboard Play In The Incident?
The incident was linked to a suspected compromise affecting Switchboard, an oracle provider that supplies external data to blockchain applications. Oracles are critical to DeFi systems because lending markets, automated vaults and derivatives protocols often rely on them for asset prices and other information used to execute transactions.
Switchboard said Saturday that it was investigating a potential compromise involving its Move-based implementations. The company halted its network on Aptos, Sui, IOTA and Movement while it examined the issue.
That cross-chain response is important because it indicates that the potential exposure was not limited to Full Sail or even to Sui. Applications using the affected oracle infrastructure on other Move-based networks also had to assess whether their contracts or price feeds were vulnerable.
Full Sail’s automated vaults were among the systems affected. Once an oracle input becomes unreliable or can be manipulated, automated strategies may execute trades, calculate collateral values or release assets using incorrect data. A relatively narrow infrastructure weakness can therefore spread quickly into protocols that depend on the same service.
Investor Takeaway
Full Sail’s closure shows that DeFi security risk extends beyond a protocol’s own smart contracts. Applications can inherit vulnerabilities from oracle providers and other infrastructure partners, making third-party dependencies an important part of assessing protocol risk.
Were Other DeFi Protocols Affected?
Full Sail was not the only project to report losses connected to the incident. Virtue, a stablecoin lending protocol operating on IOTA, said it lost about $455,000 and that the backing of its VUSD stablecoin had been impaired.
The larger loss at Virtue shows how the same underlying infrastructure problem can create different outcomes depending on how individual protocols use an oracle and how much capital is exposed through affected contracts.
Stablecoin systems carry an additional layer of risk because a loss can affect not only protocol liquidity but also the assets backing the token itself. If backing falls below the amount of stablecoins in circulation, holders may begin questioning redemption value and liquidity, potentially extending the impact beyond the original exploit.
The incident also illustrates the concentration risk created when multiple DeFi applications rely on the same infrastructure provider. Shared oracle systems make development easier and can provide consistent data across chains, but a compromise can simultaneously expose several otherwise unrelated protocols.
What Happens To Full Sail Users Now?
Full Sail expects to publish detailed withdrawal and compensation instructions within the coming days. Until its final security checks are completed, users will need to wait for the protocol to confirm when regular pools can safely enter withdrawal-only mode.
The repayment plan reduces some of the immediate financial risk for depositors because Full Sail has said protocol-owned liquidity will be used first and that the team will cover any remaining deficit. The final outcome will depend on the amount available, the verification of affected balances and the claims process established during the wind-down.
For the DeFi sector, the episode adds another example of infrastructure risk becoming protocol risk. Smart-contract audits alone cannot eliminate exposure when applications depend on external price feeds, bridges, custodians or other third-party systems.
The broader issue now is whether Switchboard identifies the exact source of the compromise and whether applications across Aptos, Sui, IOTA and Movement need additional changes before affected oracle services can operate normally again. For Full Sail, however, the incident has already produced a permanent outcome: the protocol is choosing repayment and closure rather than attempting to rebuild after the loss.
