READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Oracle Hack Lets Attacker Mint $4.9 Million in Fake Stablecoins on IOTA, Forcing Switchboard to Shut Down Four Blockchains

Oracle Hack Lets Attacker Mint $4.9 Million in Fake Stablecoins on IOTA, Forcing Switchboard to Shut Down Four Blockchains
A compromised price-feed key let an attacker tell smart contracts that IOTA tokens were worth $10 million each, then borrow nearly $5 million in stablecoins against that fake collateral. Switchboard, the oracle provider, pulled the plug on Aptos, Sui, IOTA, and Movement while it investigates. Forty-five users got liquidated in the chaos, and the incident raises the old question of what happens when the single source of price truth in DeFi gets hijacked.

Switchboard, an oracle protocol that feeds price data to decentralized apps across several blockchains, halted its Move-based deployments overnight between Thursday, August 28 and Friday, August 29, after detecting what it called a potential security compromise. The affected networks are Aptos, Sui, IOTA, and Movement.

According to Crypto Briefing, an attacker got hold of a compromised oracle key on IOTA and used it to set the token's on-chain price at $10 million. Oracles exist to feed real-world data, like token prices, into smart contracts that make automated financial decisions. When that feed lies, the contracts believe the lie.

With IOTA showing a fabricated $10 million valuation, the attacker borrowed against it through Virtue, a collateralized debt position (CDP) protocol that lets users lock up crypto and mint stablecoins in return. The attacker walked away having minted roughly 4.94 million VUSD, a stablecoin, against collateral that was never actually worth anything close to that.

The fallout landed on 45 other users, who got liquidated once the price feed was corrected and reality reasserted itself, per Crypto Briefing. Exchanges froze the addresses tied to the exploit, and Virtue halted its protocol entirely while the mess gets sorted out.

The key detail is that the compromise only technically hit IOTA, but Switchboard pulled its oracle service on Aptos, Sui, and Movement too. This suggests the company is worried the vulnerability sits somewhere deeper than a single network's configuration.

All four affected chains run on Move, a programming language originally built at Meta for the now-defunct Diem stablecoin project before it got open-sourced and picked up by Aptos and Sui, with Movement and IOTA's newer infrastructure built on derivatives of it. Switchboard's decision to halt across the board suggests the company suspects an architectural weakness tied to how Move-based deployments handle oracle keys, not just a one-off IOTA misconfiguration. Switchboard has not published a technical post-mortem yet, and the company said only that it is working with unnamed security agencies to investigate.

Notably, Switchboard's Solana deployment runs on separate code and was not affected. Even so, Switchboard advised Solana-based users to consider alternative oracle providers until the investigation wraps. This suggests the company itself isn't fully confident the problem is contained.

Oracle manipulation is not a new attack vector. Mango Markets on Solana lost $114 million in 2022 when an attacker manipulated that platform's price oracle to inflate collateral value and drain the treasury. The Switchboard incident is smaller in dollar terms, under $5 million minted, but it hits the same structural weak point: a lot of DeFi's supposed decentralization still runs through a small number of price-feed providers, and if one key gets compromised, every protocol trusting that feed is exposed simultaneously.

Aptos, Sui, and Movement did not get exploited this week, but their users lost oracle service anyway because Switchboard could not rule out that they were next.

Switchboard has not said publicly which specific vulnerability let the attacker obtain the compromised key, whether it was a private-key leak, a signing-infrastructure bug, or something else. The company also has not given a timeline for restoring service on the halted networks, or said whether the roughly $5 million in minted VUSD has been recovered, frozen at the protocol level, or is still sitting in attacker-controlled wallets. Virtue's CDP protocol remains paused, and the 45 liquidated users have not been told whether they will see any compensation. Until Switchboard publishes its findings, Aptos, Sui, IOTA, and Movement developers are effectively operating without a primary price feed, and any app that depends on it is stuck waiting.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingSwitchboard halts operations on Aptos, SUI, IOTA, and Movement after detecting potential compromise
unknown
PrimeXBTRussia blacklists 2,600 crypto wallets while legalizing crypto to dodge its own sanctions
unknown
PluangZilliqa to hard fork on Sept 2, 2026, restoring exchange ZIL withdrawals but self-custodians face later migration.