Why a $91K Oracle Incident Ended an Entire DeFi Protocol

Full Sail is winding down after an oracle incident affected three automated vaults, leaving users to wait for proof that its repayment promise can cover their claims.
Key Takeaways
- Full Sail announced a wind-down September 1.
- The direct loss was about $91,000.
- Withdrawals remain paused on the live app.
- Repayment amounts and instructions remain undisclosed.
A $91K loss led to a much larger decision
Full Sail disclosed a security incident on August 29 and paused activity while it investigated. The protocol later announced that it was sunsetting on Sui, shifting its focus from operating vaults to repaying affected users.
In its official wind-down updates, Full Sail said about $91,000 had been removed from three automated vaults. It also said remaining protocol-owned liquidity would go to users and that the team would absorb any shortfall so community depositors are compensated first.
Direct vault loss
About $91,000 was removed from three automated vaults.
Repayment commitment
Protocol-owned liquidity and team funds have been pledged to community depositors.
Still unknown
The protocol has not disclosed total claims, available repayment liquidity or claim mechanics.
Full Sail has not published a balance sheet showing that the $91,000 loss alone made a restart impossible. The decision to wind down instead shows that the direct loss was only one part of the problem. The team must also verify the price-data dependency, review the affected vaults and decide whether rebuilding the protocol safely and credibly still makes sense.
How unreliable price data makes a vault unsafe
An oracle supplies a smart contract with information it cannot obtain by itself, including asset prices. A vault can calculate every transaction correctly against the price it receives, yet still produce the wrong economic outcome if that price is unreliable.
Valid onchain, unsafe in reality
The contract does not independently know the market price of an asset. It acts on the feed it has been programmed to accept. If that input becomes unreliable, an automated strategy can treat a transaction as valid onchain while users absorb the economic loss.
Full Sail’s suspected oracle issue is technically different from the recent Term vault governance exploit. Both, however, show that DeFi contracts can treat a compromised input as legitimate and still harm users.
Full Sail linked its incident to Switchboard. In its official incident updates, Switchboard said it was investigating a potential compromise of its Move-based implementations and halted affected services on Aptos, Sui, IOTA and Movement. Neither team has published a complete technical postmortem, so the precise exploit path and final responsibility remain unconfirmed.
The app is paused. Withdrawal-only is the next stage
Full Sail’s live security notice says deposits and withdrawals remain paused until oracle integrity is restored and verified. Its wind-down updates say new deposits and liquidity-provider reward claims have been disabled, while regular pools are expected to become withdrawal-only after final security checks.
The app’s banner is the current safety status. Withdrawal-only is the next planned stage, not a live function. Separate withdrawal and claim instructions are still pending.
What Full Sail still needs to publish
Full Sail has promised to put community depositors first. Users still need five practical answers before they can judge that promise:
- The amount of protocol-owned liquidity available for repayment.
- The total value of affected user claims.
- The date used to calculate eligible balances.
- The time when withdrawal-only pool access begins.
- The claim process and treatment of any shortfall.
Until that reconciliation is published, the $91,000 figure describes the breach—not what affected users will recover.









