DeFi just had a brutal stretch, and the most important lesson isn't about any single hacked protocol. It's that several of them were brought down by the same root cause: a compromise at one shared piece of infrastructure they all quietly depended on. It's the clearest illustration yet of a risk most users never think about.

What happened
The trouble started with Switchboard, an oracle provider used across several "Move-language" blockchains. Oracles are the services that feed real-world prices to DeFi protocols, and they're load-bearing: if a lending protocol believes a false price, everything downstream breaks. On August 29, an attacker exploited a signing-key vulnerability in Switchboard's production code, the part that governs who is allowed to sign oracle price updates, and added a key they controlled to a live oracle. Once the network accepted that key, the attacker's fabricated prices appeared completely legitimate.
The damage cascaded immediately. Switchboard halted its network across four chains, Aptos, Sui, IOTA, and Movement, but by then protocols relying on it were already exposed to poisoned price data with no independent fallback.
The casualties
Full Sail (Sui), now shutting down. The attacker pushed prices to roughly 100 times below market value, deposited into the protocol's vaults at those distorted rates, then restored prices and withdrew far more than they put in, draining about $91,000 from three vaults. The dollar figure is small, but the consequence isn't: Full Sail announced it will permanently wind down. The team was blunt that this "was not a Full Sail admin key compromise", the flaw was in its oracle dependency, not its own code, and pledged to repay affected depositors using protocol liquidity and its own treasury, noting that Switchboard had not supplied requested technical details and Mysten Labs declined a request for financial support.
Virtue (IOTA), $455,000 and a wounded stablecoin. The same Switchboard flaw hit Virtue, a stablecoin lending protocol, harder. Using manipulated prices, the attacker minted roughly 4.94 million VUSD (Virtue's stablecoin) against collateral, then triggered fabricated-price liquidations that wiped out 45 users and cleared about $455,000 in debt. Notably, Virtue's own liquidation system worked exactly as designed, it simply acted on false prices it had every reason to trust. The incident impaired the backing of the VUSD stablecoin, raising depeg risk, and Virtue froze all activity while it remediates. Combined, the two confirmed losses top $546,000, all traceable to a single provider.
Separately, reports circulated of a larger alleged $2.5 million exploit of the Solana-based Aquifer AMM, which reportedly offered a 20% white-hat bounty with a September 3 deadline; that incident was not independently confirmed through a primary source at the time of writing and should be treated as unverified.
Why this is the real story
The headline losses here are modest by crypto-hack standards, but the mechanism is what matters. Full Sail did nothing wrong with its own smart contracts, and Virtue's liquidation bot functioned perfectly. They failed anyway, because a piece of shared infrastructure they trusted was compromised. This is third-party dependency risk, and it's one of DeFi's most underappreciated dangers: a protocol can be flawlessly built and independently audited, yet inherit a fatal vulnerability from an oracle, bridge, or other service it plugs into.
It also underscores a hard truth about "decentralization." Switchboard's ability to halt four entire blockchains' worth of price feeds shows how much supposedly decentralized systems still lean on a small number of infrastructure providers, single points of failure hiding behind a decentralized façade. And Sui's ecosystem in particular now carries real scar tissue: it has weathered a string of oracle-linked and DeFi failures over the past year, from Cetus to Volo to Scallop.
For everyday users, the takeaways are concrete: a protocol's safety depends on its whole stack, not just its own code; audits of a single contract don't capture infrastructure risk; and protocols that name their dependencies, use multiple independent oracles, and build price-manipulation safeguards (like time-weighted averages) are meaningfully safer than those that don't. When you deposit into a DeFi protocol, you're trusting everything it trusts, and this week showed exactly what happens when one of those hidden links breaks.




