Switchboard halts operations on Aptos, SUI, IOTA, and Movement after detecting potential compromise
Switchboard, the multi-chain oracle protocol that feeds price data to decentralized applications across several blockchains, shut down operations on its Move-based deployments after discovering what it described as a potential security compromise. The affected networks include Aptos, Sui, IOTA, and Movement.
The halt, communicated during the transition from August 28 to 29, represents one of the more serious oracle-level incidents in recent memory. And the damage on at least one network was anything but theoretical.
What happened on IOTA
An attacker exploited a compromised oracle key to manipulate the IOTA price feed, temporarily setting the token’s price to $10 million.
With the feed showing a wildly inflated IOTA price, the attacker was able to mint approximately 4.94 million VUSD through the Virtue CDP protocol. CDP, or collateralized debt position, protocols let users lock up assets and borrow stablecoins against them. When the oracle says your collateral is worth $10 million per token, the protocol happily lets you borrow accordingly.
The fallout hit 45 users directly through liquidations. Exchange addresses were frozen in response to the chaos, and the Virtue CDP protocol itself was halted.
Scope of the shutdown
Switchboard’s decision to halt all Move-based implementations suggests the vulnerability may be architectural rather than network-specific. Move is the programming language originally developed at Meta (then Facebook) for the Diem project, and it now underpins Aptos, Sui, and their derivative ecosystems including Movement and IOTA’s newer infrastructure.
The protocol said it was actively collaborating with relevant security agencies to investigate the breach.
Notably, Switchboard’s Solana deployment was not affected. The protocol’s Solana-based infrastructure runs on different code, which apparently wasn’t vulnerable to the same exploit vector. Still, Switchboard advised even Solana users to temporarily seek alternative oracle options during the investigation.
Why oracle compromises are uniquely dangerous
Oracles occupy one of the most critical positions in the DeFi stack. They’re the bridge between real-world data (token prices, interest rates, asset values) and on-chain smart contracts that execute financial transactions based on that data.
The DeFi ecosystem has seen oracle-related exploits before. Mango Markets on Solana suffered a $114 million exploit in 2022 when an attacker manipulated the platform’s oracle price.
What makes the Switchboard incident particularly concerning is that the compromise appears to have occurred at the key level rather than through market manipulation. The attacker didn’t need to execute complex trading strategies to move a price. They simply gained access to a key that controlled the feed and rewrote the data directly.
What this means for affected ecosystems
For Aptos, Sui, and Movement, the shutdown is disruptive even if no exploits have been confirmed on those networks. Any DeFi protocol relying on Switchboard for price feeds is effectively flying blind until service resumes, unable to process liquidations, update collateral ratios, or execute any price-dependent function.
Protocols that integrated redundant oracle sources from providers like Pyth, Chainlink, or Redstone alongside Switchboard can continue operating. Those that didn’t are learning an expensive lesson about single points of failure.
Switchboard’s initial statements suggest that user funds have remained intact beyond the IOTA incident, but that assessment could evolve as the investigation deepens.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)