The DeFi protocol Full Sail, operating within the Sui ecosystem, has officially announced the winding down of its operations. The cause was the exploitation of a vulnerability related to the Switchboard oracle, which resulted in an attacker withdrawing approximately $91,000 from three of the project's vaults. This event highlights the fragility of even carefully designed architectures when external integrations become points of failure.

At present, the Full Sail administration has already suspended the acceptance of new deposits and the accrual of rewards. In its statement, the team emphasizes that the priority is returning funds to users. To this end, it plans to utilize the project's own liquidity and, if necessary, cover the shortfall from reserves to fully compensate affected depositors for their losses.

Technical Details of the Incident

Although the exact attack vector has not been disclosed, incidents involving oracles are typically associated with manipulation of price feeds or delays in data updates. In the case of Full Sail, the attacker likely exploited a discrepancy between the real value of assets and the readings from Switchboard, allowing them to withdraw liquidity at an inflated rate. This is a typical problem for protocols relying on a single data source without additional checks.

The decision to fully shut down rather than partially recover appears radical but pragmatic. For small projects, the loss of $91,000 can be critical in terms of reputation and economic model. Instead of spending resources on complex rebranding and rebuilding trust, the team chose a path of orderly exit, which under current market conditions may be a more responsible step toward the community.

My analysis: This case is yet another reminder that DeFi protocols should conduct oracle stress tests and implement emergency pause mechanisms. The Full Sail incident, although insignificant in amount compared to major hacks, demonstrates that even secondary integrations can prove fatal. The Sui market, despite its technological advancement, still needs more mature security standards to attract institutional capital.