Full Sail, a decentralized exchange on Sui, said it is shutting down after an August 29 exploit drained about $91,000 from three of its vaults. The team described the incident as a security failure tied to Switchboard production code rather than an internal admin key breach.
The protocol said deposits and withdrawals were paused once the attack was confirmed. Full Sail also said it will direct all remaining protocol-owned liquidity to users and absorb the shortfall so community depositors are repaid first.
How the attack unfolded
According to Full Sail, the attacker abused Switchboard production code that determines which keys are allowed to sign oracle price updates. The team said the attacker inserted a key they controlled into a live oracle, after which the network treated manipulated prices as legitimate.
With that access, the attacker allegedly pushed prices to around 100 times below market levels and deposited into the affected vaults. After prices were restored, the attacker was able to withdraw more value than had been deposited, producing the loss across three vaults.
What was and was not affected
Full Sail said direct liquidity pool positions were not impacted by the exploit. The team also stressed that the incident was not caused by a compromise of Full Sail admin keys, drawing a distinction between the protocol's own controls and the external oracle-signing issue it says enabled the attack.
The protocol moved to halt deposits and withdrawals on August 29 after confirming the breach. That pause remains part of its shutdown process as the team works through the fallout from the incident.
Wider fallout from the Switchboard incident
The Full Sail case was not the only loss linked to the same event. Virtue separately reported roughly $455,000 in damages tied to the Switchboard incident, pointing to broader impact across protocols using the affected infrastructure.
Switchboard said contributors halted its network on Aptos, Sui, Iota, and Movement. Full Sail said that, as of September 1, Switchboard had not provided the technical details it had requested and had not committed funds toward compensation. The team also said Mysten Labs declined a request for financial support.
Next steps for users and the protocol
Full Sail said its remaining protocol-owned liquidity will be used for users, with community depositors prioritized for compensation ahead of the team. It added that the shortfall will be absorbed so affected depositors are made whole first.
The team said it will publish a detailed incident report and a separate explanation of the decision to wind down. For now, the confirmed next step is the closure of the protocol on Sui following the exploit and the distribution of remaining resources to users.
Source: beincrypto.com