Switchboard pulled its oracle feeds offline across four Move-based chains after a compromised key on IOTA let an attacker inflate a token price to $10 million.
Switchboard pulled its oracle feeds offline across four Move-based chains after a compromised key on IOTA let an attacker inflate a token price to $10 million.

Switchboard pulled its oracle feeds offline across four Move-based chains after a compromised key on IOTA let an attacker inflate a token price to $10 million.
Switchboard halted oracle feeds on SUI, Aptos, IOTA, and Movement on Aug. 29 after detecting a potential compromise in its Move-based implementations.
"We are actively collaborating with relevant security agencies to investigate the breach," Switchboard said in its status update. SolanaFloor confirmed on X that the blockchains themselves remain fully functional, with only Switchboard's deployments on those ecosystems affected.
The shutdown followed an incident on IOTA where an attacker used a compromised oracle key to set the IOTA price feed to $10 million, then minted approximately 4.94 million VUSD through the Virtue collateralized debt position protocol. The manipulated feed triggered liquidations affecting 45 users on Virtue, which lets users deposit IOTA and stIOTA as collateral before minting VUSD stablecoins. Exchange addresses were frozen in response, and the Virtue protocol was halted.
The incident shows how shared oracle infrastructure creates cross-chain risk across Move-based ecosystems. Protocols relying solely on Switchboard for price data cannot process liquidations, update collateral ratios, or execute price-dependent functions until service resumes. Switchboard has not confirmed whether the vulnerability is architectural or specific to signing credentials.
The attacker didn't need complex trading strategies to move the price — they gained access to a key that controlled the feed and rewrote the data directly. This distinguishes the incident from market-manipulation exploits like the $114 million Mango Markets attack on Solana in 2022, where an attacker used large positions to distort prices.
Virtue's design makes accurate external pricing essential. When an oracle reports an extreme price, smart contracts can treat relatively small collateral deposits as assets worth far more than their actual market value, distorting borrowing limits and debt creation before the incorrect data can be removed.
The four suspended deployments share a common foundation: Move-based smart-contract infrastructure. Move was originally developed at Facebook for the Diem blockchain project and later became fundamental to Aptos and SUI. IOTA adopted the Move Virtual Machine through its Rebased upgrade, which reached mainnet in May 2025.
However, the shared programming environment does not establish that Move itself contains a vulnerability. The known issue is limited to Switchboard's potentially compromised Move implementations. The protocol's Solana deployment runs on different code and was not affected, though Switchboard advised even Solana users to temporarily seek alternative oracle options during the investigation.
Protocols that integrated redundant oracle sources from providers like Pyth, Chainlink, or Redstone alongside Switchboard can continue operating. Those that didn't are learning an expensive lesson about single points of failure.
Switchboard's initial statements suggest user funds have remained intact beyond the IOTA incident, but that assessment could evolve as the investigation deepens. The key questions now: what was compromised, whether any data was manipulated beyond IOTA, and when operations will resume.
This article is for informational purposes only and does not constitute investment advice.