Full Sail, a decentralized exchange on Sui, is shutting down for good. The team confirmed the closure this week, and the full sail shutdown switchboard timeline traces back to a compromised price oracle that let an attacker drain roughly $91,000 from three of the protocol's vaults on August 29. If you have funds sitting in Full Sail right now, this is the one story this week that actually requires you to do something — just not today, and not in a panic.
What actually happened
On Saturday, August 29, an attacker exploited a compromised feed from Switchboard, the oracle service Full Sail used to price its pools. An oracle is the software that feeds a blockchain app real-world prices; when one gets manipulated, the app trusts a number that isn't real. Whoever pulled this off pushed a reported price roughly 100 times away from its actual market value, then used that distorted number to withdraw far more than they had put in. Three of Full Sail's vaults were hit before the exploit was contained. It wasn't unique to Full Sail: Switchboard halted its feeds across four chains — Sui, Aptos, IOTA and Movement — while it investigated, since the failure sat in Switchboard's own infrastructure, not in Full Sail's code.
The dollar figure is small in absolute terms because Full Sail itself was small. Total value locked across the whole protocol was only around $226,000 before the exploit, so losing roughly $91,000 wiped out close to 40% of it. That size is central to what happened next: rebuilding trust in a DEX that just lost that much to a third-party oracle failure is slow and expensive, and on Tuesday, September 2, Full Sail's team announced it wasn't going to try. New deposits and LP reward claims are switched off, and the affected vaults stay paused pending a final security review.
Is my money in Full Sail safe?
For most users, yes — with a caveat about timing rather than safety. If your funds were in any Full Sail pool other than the three that were drained, the exploit never touched them; they're simply frozen inside a paused protocol until the team turns on a withdraw-only mode, which it says should happen within days of the September 2 announcement. Nothing about your funds' safety changes between now and then. They're paused, not exposed. You just can't move them yet.
If you were in one of the three exploited vaults, the picture is different. There's no normal withdrawal to make, because the attacker already extracted the excess value. Instead, you're now a claimant in a compensation process the team has committed to but hasn't yet carried out.
The full sail shutdown switchboard payout order
This is the detail that matters most for anyone actually owed money. Neither of the two parties you'd expect to backstop a DeFi exploit has stepped in: Mysten Labs, which builds Sui, has said it won't fund a bailout, and Switchboard hasn't committed to compensating anyone hit by its own feed's failure. That leaves Full Sail's team to cover the gap, and they say they will — using the protocol's own liquidity first, then having the team fund whatever's left out of pocket, with community depositors placed ahead of any other claims in that queue. It's a real commitment, and a reasonable one for a protocol this size. But as of this week it's still a promise, not a completed payout: there's no confirmed date for when funds actually move.
What should you do right now?
Nothing urgent. If you weren't in one of the three exploited vaults, wait for the withdraw-only window and the claims guide the team has promised within days, then follow those instructions to pull your funds. There's no upside to trying to act before that mechanism exists. If you were in an exploited vault, the advice is similar but with less certainty: watch Full Sail's official channels for the claims guide, and treat any compensation timeline as unconfirmed until the team publishes actual dollar amounts and dates.
What we still don't know
Two open questions will decide how this story reads in a month. First, Switchboard hasn't said publicly whether the root cause was a compromised signing key or a bug in how its contracts verified price data — that distinction matters for whether other apps that depend on Switchboard, on Sui or any of the other three affected chains, face the same risk again. Second, "within the next few days" is not a scheduled date, and the pledge to self-fund any shortfall is untested until money actually moves.
None of this is a SUI story. The token was trading around $0.77 as of Friday morning UTC, up roughly 1.3% on the day and 0.8% on the week — flat and range-bound, with no visible reaction to the Full Sail news. That's consistent with what this actually is: a contained, single-protocol wind-down, not evidence of a deeper problem with Sui's DeFi ecosystem. The risk here sits specifically with people who had funds in Full Sail, and more specifically still with the small subset who were in the three vaults the attacker actually reached.
Sources
- https://financefeeds.com/full-sail-to-shut-down-after-switchboard-oracle-incident-causes-user-losses/
- https://cryptobriefing.com/full-sail-shuts-down-switchboard-oracle/
- https://www.cryptotimes.io/2026/08/30/full-sail-confirms-sui-vault-losses-as-switchboard-halts-4-chains/
- https://x.com/FullSailFi/status/2094895966407008258
- https://www.coingecko.com/en/coins/sui