Switchboard Halts Move Networks After Oracle Compromise
Switchboard halted its oracle services on Aptos, Sui, IOTA and Movement after detecting a potential compromise of a Move-based deployment. The Switchboard incident has already caused material damage on IOTA, where an attacker used a compromised oracle key to push the IOTA price feed to $10 million.
The manipulated feed enabled the attacker to mint about 4.94 million VUSD through the Virtue CDP protocol. The event triggered liquidations affecting 45 users, froze exchange addresses and forced Virtue CDP to pause operations.
Switchboard said it is working with security agencies to investigate. No comparable exploit has been confirmed on Aptos, Sui or Movement, but DeFi protocols relying solely on Switchboard price feeds may be unable to process liquidations, update collateral ratios or execute other price-sensitive transactions until services resume.
Switchboard’s Solana deployment was not affected because it uses separate infrastructure, although the protocol advised Solana users to consider alternative oracle providers. Projects using redundant feeds from Pyth, Chainlink or RedStone may face less disruption.
For traders, the key risks are further losses on IOTA, forced deleveraging across affected DeFi markets and weaker confidence in Move-based ecosystems. The incident also highlights the importance of oracle redundancy and key-management controls. Switchboard said initial assessments indicated that user funds outside the IOTA-related incident remained intact, but the investigation is ongoing.
Bearish
The immediate market impact is bearish because a compromised oracle key directly distorted IOTA’s price, enabled the creation of approximately 4.94 million VUSD and caused liquidations affecting 45 users. The suspension of Switchboard services also creates operational risk for DeFi protocols on Aptos, Sui and Movement, particularly those without secondary oracle feeds.
In the short term, traders may reduce exposure to IOTA-related lending markets and Move-based DeFi, while volatility, collateral haircuts and forced deleveraging could increase. Liquidity may deteriorate as protocols pause borrowing, lending or liquidation functions. Similar oracle incidents, including the 2022 Mango Markets exploit on Solana, show how quickly manipulated pricing can trigger large losses and undermine confidence in an ecosystem.
The risk is partly contained. Switchboard’s Solana infrastructure was not affected, and protocols using Pyth, Chainlink or RedStone as backup providers may continue operating. If the compromise is isolated, affected networks restore services safely and user losses remain limited, broader crypto-market contagion could fade.
Longer term, the incident is likely to increase demand for multi-source oracle designs, circuit breakers, delayed price validation and stronger key controls. However, until the investigation clarifies the attack path and confirms the condition of user funds, the negative security signal outweighs the potential benefits of a rapid recovery.