Full Sail Becomes 2026’s Latest Protocol to Close After a Hack

Full Sail, an Arbitrum-based lending protocol, is shutting down after a flash-loan exploit drained roughly $18.6 million from its markets. The hack made Full Sail the latest crypto project to wind down in 2026, and remaining assets will be reserved for creditor claims.

Listen to Article — 6 min
Follow Our News on Google
Be instantly informed of developments.
Add as a preferred source on Google

Full Sail, an Arbitrum-based decentralized lending protocol, confirmed it will shut down after a flash-loan exploit drained roughly $18.6 million from two core lending pools. The wind-down makes Full Sail the latest protocol closure of 2026, a year that is already seeing hacked DeFi teams choose liquidation over rebuilding. In an incident post-mortem, Full Sail said remaining recoverable assets will not be redeployed and will instead be reserved for creditor claims.

A 60-second Attack That Broke the Lending Model

Full Sail said the exploit began with a flash-loan borrowed from Aave. The attacker repeatedly borrowed and repaid against staked ETH collateral inside a single transaction, inflating Full Sail’s internal collateral-factor calculation. That made staked ETH appear far more valuable than the protocol’s accounting model permitted, allowing the attacker to withdraw more capital than the pool should have allowed.

Full Sail’s post-mortem listed the core parameters of the exploit:

  • Target pool: Full Sail staked ETH lending module
  • Manipulated collateral factor: raised from 79.2% to 94.6% within one transaction
  • Flash-loan source: Aave v3
  • Estimated maximum loss: 17,240 ETH and 2.9M USDC
  • Recoverable or returned assets at time of shutdown vote: roughly 9,100 ETH in protocol treasury
  • Withdrawals: frozen minutes after the exploit was detected

The protocol’s risk monitors flagged the unusual borrowing pattern at 03:11 UTC. By 03:20 UTC, Full Sail’s guardian multisig had paused all borrowing and withdrawals, but the damage was already done.

In an official statement posted to the governance forum, Full Sail’s core team wrote:

“This was not a simple oracle delay or a one-block price manipulation. The loophole was structural. Once we removed the ability to borrow against staked collateral, the product no longer functioned as intended. Continuing with lower risk limits would not cover the legal and audit burden of managing the remaining assets.”

Market Impact Puts Sail Token Under Heavy Pressure

Full Sail’s governance token, SAIL, fell sharply after the incident. Market data showed SAIL trading near $0.044 before the exploit, then dropping to around $0.0092 after the protocol confirmed its closure plans.

The following timeline captures the sequence of events:

Incident Clock On-Chain or Governance Event Capital or Market Impact
Jan. 13, 03:11 UTC Attacker executes two borrow cycles against inflated staked ETH factor 17,240 ETH and 2.9M USDC leave protocol pools
Jan. 13, 03:20 UTC Guardian multisig triggers emergency pause Withdrawals frozen; SAIL begins steep decline
Jan. 14, 22:45 UTC Off-chain governance signal vote opens 84.9% of participating votes favor wind-down
Jan. 15, 09:00 UTC Final closure proposal scheduled Creditors told to prepare for claims portal

The DAO’s early voting results showed little appetite for rescuing the protocol. More than 84% of participating SAIL votes favored an organized shutdown rather than a recapitalization plan. Full Sail said the signal vote was followed by a broader on-chain proposal to disable market creation and burn administrative keys after the claims window closes.

A Growing Pattern of Post-hack Shutdowns

Full Sail is not the first hacked protocol to decide that closure is the least risky path. The decision reflects a broader trend in DeFi where security failures reveal design flaws that cannot be safely patched without fundamentally rearchitecting the protocol. For Full Sail, the issue was not a broken external price feed but an internal accounting mismatch that could be triggered by any user with access to a flash loan.

The closure also highlights the difficult legal position of anonymous or decentralized teams. Without a registered corporate entity, there is no formal bankruptcy process and no court-supervised creditor committee. Full Sail has said it will act voluntarily, using protocol-controlled treasury funds to settle claims.

Some on-chain analysts have traced part of the stolen capital to a cross-chain bridge. Full Sail said in its post-mortem that it had shared wallet profiles with blockchain intelligence firms and law enforcement. No additional recoveries have been publicly announced.

What Happens Next for Lenders and Sail Holders

Full Sail said the remaining treasury will be used to pay creditors who supplied staked ETH and USDC to the affected lending pools. The protocol plans to publish a dedicated claims dashboard where users can verify their losses and submit wallet signatures for review.

No new loans will be issued during the shutdown period. Full Sail also said no further grant distributions or contributor payments will be made from the treasury without an explicit governance vote.

The final closure proposal will disable all borrowing, remove trading incentives, and approve a final claims allocation plan. Full Sail has told users to watch its official governance forum and Discord channel for updates.

What Caused the Full Sail Hack?

Full Sail attributed the exploit to a structural flaw in its collateral-factor accounting, not a standard oracle price attack. The attacker used a flash loan to manipulate the protocol’s calculation for staked ETH collateral inside one transaction, which let them withdraw more funds than the protocol’s own risk model permitted.

Will Full Sail Users Be Repaid?

Full Sail has said remaining recoverable assets will be reserved for creditors of the affected lending pools. The protocol plans to open a claims process, though repayment is not guaranteed to cover the full loss amount.

What Is a Flash-loan Exploit in DEFI?

A flash-loan exploit uses uncollateralized loans that must be repaid within the same blockchain transaction. Attackers use flash loans to move large amounts of capital temporarily, often to manipulate prices or accounting values on vulnerable protocols before repaying the loan.

Is Full Sail the First DEFI Protocol to Close After a Hack in 2026?

No. Full Sail is described as the latest protocol to close after a hack in 2026, meaning other projects have already chosen the same path this year. The repeat pattern has drawn renewed attention from security auditors and risk managers across decentralized lending markets.

What Should Token Holders Do After the Full Sail Shutdown?

Full Sail officials say SAIL tokens do not represent legal title to recovered assets and will not function as claim tokens in the distribution process. Users with funds in affected pools should watch for the official claims dashboard and verify wallet eligibility through the protocol’s governance channels.

This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.