Another DeFi protocol has fallen victim to a vulnerability in oracle infrastructure. The Full Sail project, which operated within the Sui ecosystem, officially announced it was winding down operations after an attacker exploited a flaw in the Switchboard service and drained approximately $91,000 from three liquidity vaults. This is not a catastrophic amount by industry standards, but it proved fatal for the project itself.

Attack Details and Team Response

The incident was detected when monitoring revealed anomalous transactions linked to price feed manipulation. Switchboard oracles, which were supposed to provide reliable asset valuation data, became the entry point for the exploit. As a result, the protocol immediately suspended new deposits and reward accruals to prevent further outflow of funds.

The Full Sail team has already stated that it does not intend to restore operations in their previous form. Instead, the priority is returning funds to affected users. To this end, the project plans to use its own treasury liquidity, and if that proves insufficient, cover the shortfall from reserve funds. This approach, while not guaranteeing full compensation, demonstrates an attempt to preserve the remnants of its reputation amid the collapse.

A Systemic Problem or an Isolated Mistake?

This case raises a broader question about the dependence of DeFi protocols on third-party oracles. Even minor discrepancies in data can be exploited for arbitrage attacks, especially in pools with low liquidity. Full Sail is not the first and likely not the last project to pay the price for underestimating risks in this area.

From my perspective, the closure of the protocol after losing $91,000 is a signal that the team did not see a sustainable future for its model. In an environment of intense competition and declining trust in small DeFi platforms, any failure can become a point of no return. For the market, this is a lesson: oracle audits and stress-testing manipulation scenarios must be mandatory, not optional. As for users, it is worth remembering that even "small" protocols carry risks that cannot be fully insured against.