Sui DeFi Protocol Full Sail Shuts Down After $91K Switchboard Oracle Exploit
Full Sail, a decentralized finance protocol on Sui, is winding down after an attacker drained roughly $91,000 from three vaults by exploiting a vulnerability tied to oracle provider Switchboard. The shutdown underscores systemic risks in oracle-dependent DeFi protocols.
Sui DeFi Protocol Full Sail Shuts Down After $91K Switchboard Oracle Exploit
Full Sail, a decentralized finance protocol on the Sui blockchain, is winding down after an attacker drained roughly $91,000 from three of its vaults by exploiting a vulnerability tied to oracle provider Switchboard.
The exploit, which occurred on or before September 2, 2026, targeted Full Sail's reliance on Switchboard price feeds, the external data sources DeFi protocols use to price assets and trigger liquidations. When those feeds are compromised or manipulated, the downstream protocols that depend on them become attack surfaces. In Full Sail's case, the breach was decisive enough to end the project entirely.
Ninety-one thousand dollars is a modest number by DeFi's historical standards. But for a smaller protocol without deep capital reserves or an insurance backstop, a loss of that size can be existential. The team's decision to shut down rather than patch and continue signals that confidence in the protocol's security model collapsed alongside the funds.
The oracle layer has always been one of DeFi's most exposed attack vectors. The bZx flash loan attacks in 2020 were among the first high-profile demonstrations that manipulating a price feed could drain a protocol without ever touching its core code. Curve Finance dealt with a related oracle incident in 2023. Each episode reinforces the same structural problem: a protocol is only as secure as the data it trusts, and that data comes from outside the protocol's own smart contracts.
The question of exactly where the fault lies here is genuinely open. Switchboard may contend that Full Sail's integration or configuration introduced the vulnerability, not the oracle infrastructure itself. That distinction matters for how responsibility gets assigned, but it changes little for users who lost funds. Oracle security is a shared responsibility, and the division of labor between provider and protocol is rarely spelled out clearly enough until something breaks.
"Full Sail is shutting down after an attacker removed about $91,000 from three vaults during a security incident linked to oracle provider Switchboard."
The shutdown also puts a spotlight on Sui's DeFi layer at a sensitive moment in the network's growth. Sui has attracted developer attention and liquidity over the past two years on the strength of its object-based execution model and throughput claims. A protocol failure, even at this scale, adds friction to that narrative. Builders and liquidity providers considering Sui deployments will now weigh oracle risk as part of their due diligence calculus.
For the broader DeFi market, Full Sail's closure is a reminder that protocol size does not determine exploit risk. A $91,000 loss is a rounding error for a large money market but a kill shot for a smaller vault protocol. Projects without explicit oracle failsafes, circuit breakers, or loss-absorption mechanisms are structurally vulnerable to exactly this kind of attack, regardless of how well their core contracts are written. Auditing the protocol code without auditing the oracle integration is half a job.
The DeFi sector lost over $1.2 billion to exploits in 2024, with oracle manipulation accounting for a meaningful share of that total. Full Sail adds another data point to a pattern that has not meaningfully reversed: oracle-dependent protocols continue to underinvest in the security of the data layer they cannot control.





