NewsCryptoSwitchboard Halts Oracle Operations on Four Move-Based Chains After Potential Compromise

Switchboard Halts Oracle Operations on Four Move-Based Chains After Potential Compromise

Author: Blockonomi·

Key Takeaways

  • Switchboard halted oracle operations on Aptos, Sui, IOTA, and Movement after contributors identified a potential compromise in its Move-based deployments.
  • The suspension affects DeFi applications relying on Switchboard feeds for prices, collateral valuations, and liquidations, but the blockchains themselves remain operational.
  • A separate IOTA incident reportedly involved a compromised oracle key that pushed an asset price to $10 million, allowing an attacker to mint approximately 4.94 million VUSD and triggering liquidations affecting 45 users.
  • No similar issue has been identified in Switchboard's Solana implementation, and users were advised to temporarily migrate to alternative oracle providers.
  • Switchboard has not confirmed a root cause, attacker, losses, or number of affected applications, and no technical postmortem has been published.
Switchboard Halts Oracle Operations on Four Move-Based Chains After Potential Compromise

Switchboard has halted oracle operations across Aptos, Sui, IOTA, and Movement after contributors identified a potential compromise affecting its Move-based deployments. The coordinated shutdown affects applications that rely on Switchboard's data feeds for prices, collateral valuations, liquidations, and other automated decentralized finance functions. Switchboard is a multi-chain oracle provider, and oracles of this kind serve as the bridge between off-chain market data and on-chain smart contracts, which execute automatically based on the values they receive.

ALERT: Oracle network @switchboardxyz has halted operations on Aptos, Sui, IOTA and Movement after identifying a potential compromise affecting its Move based implementations. No similar issue has been identified on @Solana, but users are being advised to temporarily migrate… pic.twitter.com/mfc68xd0ty — SolanaFloor (@SolanaFloor) August 29, 2026

The blockchains themselves remain operational, as the suspension applies only to the Oracle Network deployments running on those ecosystems. Contributors coordinated with affected teams and security organizations while investigators examine the incident and determine whether additional applications were exposed.

IOTA's $10M Oracle Feed Incident Raises DeFi Risk

The investigation follows a separate incident on IOTA involving an allegedly compromised oracle key that reportedly pushed an asset price feed to $10 million. That manipulated valuation was then reportedly used against Virtue, an IOTA-based collateralized debt position protocol.

According to the reported incident details, the attacker minted approximately 4.94 million VUSD using collateral whose apparent value had been inflated by the corrupted feed. The event also reportedly triggered liquidations affecting 45 users.

Virtue allows users to mint VUSD after depositing assets including IOTA and stIOTA as collateral. Accurate external pricing is therefore essential for maintaining collateral ratios and determining when positions should be liquidated. When an oracle reports an extreme price, however, smart contracts can treat relatively small collateral deposits as assets worth far more than their market value. That distortion can consequently affect borrowing limits, debt creation, and automated liquidations before the incorrect data is removed.

Oracle manipulation is a recurring failure mode in DeFi rather than a novel risk. Past incidents, such as the October 2022 Mango Markets exploit on Solana, which involved a manipulated price oracle used to inflate collateral values, demonstrated how automated lending and margin systems can be drained when a single feed reports distorted prices.

Switchboard has not publicly confirmed that the reported IOTA event explains the entire potential compromise. Its initial disclosure did not identify a root cause, attacker, confirmed losses, or the number of affected applications. A technical postmortem has also not been published. As a result, the available information does not establish whether the issue originated from contract code, signing credentials, infrastructure, or another component.

Switchboard Halts Move Deployments as Solana Shows No Similar Issue

The four suspended deployments share Move-based smart-contract infrastructure, making that common architecture central to the investigation. Move was originally developed at Facebook for the Diem blockchain project. It later became fundamental to Aptos and Sui, while IOTA adopted the Move Virtual Machine through its Rebased upgrade. That architecture reached mainnet in May 2025 and introduced a programmable Move-based Layer 1.

The shared programming environment does not establish that Move itself contains the vulnerability. The known issue is limited to Switchboard's potentially compromised Move implementations across the affected networks. No similar reports have emerged involving the provider's Solana implementation. Users were nevertheless advised to temporarily migrate to alternative oracle solutions while the investigation continues.

The incident highlights how oracle failures can spread quickly through DeFi systems, as applications depend on external prices for automated decisions. Multiple providers, deviation limits, circuit breakers, and emergency pauses can limit exposure when feeds behave unexpectedly. Switchboard's halt itself functions as one such emergency measure, cutting off the compromised feeds before further automated actions could be executed against bad data.

For developers and users, the central questions now concern the precise attack vector, the number of affected applications, and restoration timelines. Until investigators publish their findings, the halted Move deployments will remain the clearest containment measure taken across Aptos, Sui, IOTA, and Movement.