Full Sail disclosed a security incident on August 29 and paused activity while it investigated. The protocol later announced that it was sunsetting on Sui, shifting its focus from operating vaults to repaying affected users.
In its official wind-down updates, Full Sail said about $91,000 had been removed from three automated vaults. It also said remaining protocol-owned liquidity would go to users and that the team would absorb any shortfall so community depositors are compensated first.
Direct vault loss
About $91,000 was removed from three automated vaults.
Repayment commitment
Protocol-owned liquidity and team funds have been pledged to community depositors.
Still unknown
The protocol has not disclosed total claims, available repayment liquidity or claim mechanics.
Full Sail has not published a balance sheet showing that the $91,000 loss alone made a restart impossible. The decision to wind down instead shows that the direct loss was only one part of the problem. The team must also verify the price-data dependency, review the affected vaults and decide whether rebuilding the protocol safely and credibly still makes sense.
An oracle supplies a smart contract with information it cannot obtain by itself, including asset prices. A vault can calculate every transaction correctly against the price it receives, yet still produce the wrong economic outcome if that price is unreliable.
The contract does not independently know the market price of an asset. It acts on the feed it has been programmed to accept. If that input becomes unreliable, an automated strategy can treat a transaction as valid onchain while users absorb the economic loss.
Full Sail’s suspected oracle issue is technically different from the recent Term vault governance exploit. Both, however, show that DeFi contracts can treat a compromised input as legitimate and still harm users.
Full Sail linked its incident to Switchboard. In its official incident updates, Switchboard said it was investigating a potential compromise of its Move-based implementations and halted affected services on Aptos, Sui, IOTA and Movement. Neither team has published a complete technical postmortem, so the precise exploit path and final responsibility remain unconfirmed.
Full Sail’s live security notice says deposits and withdrawals remain paused until oracle integrity is restored and verified. Its wind-down updates say new deposits and liquidity-provider reward claims have been disabled, while regular pools are expected to become withdrawal-only after final security checks.
The app’s banner is the current safety status. Withdrawal-only is the next planned stage, not a live function. Separate withdrawal and claim instructions are still pending.
Full Sail has promised to put community depositors first. Users still need five practical answers before they can judge that promise:
Until that reconciliation is published, the $91,000 figure describes the breach—not what affected users will recover.
The post Why a $91K Oracle Incident Ended an Entire DeFi Protocol appeared first on Coindoo.