Back Bitget A critical vulnerability was reportedly found in the Aptos blockchain, with an attack cost of ...
ChainCatcher news, according to a report from Coindesk, security firm Hexens' white-hat hackers discovered a vulnerability in the Aptos blockchain, which has now been fixed. If maliciously exploited, this vulnerability could have exposed up to 70 billion US dollars worth of digital assets to systemic risk, including stablecoins and cross-chain bridges.
In late February, Hexens researchers reported a critical vulnerability in the Move virtual machine (the execution environment for on-chain smart contracts) to the Aptos development team. It was identified as a "stale cache vulnerability," which could cause a type confusion bug, meaning the software could be tricked into mistaking one on-chain resource for another. The researchers simulated this attack in a real network environment, achieving a success rate of over 90%. They used a well-configured set of servers (costing only 3,000 US dollars) to simulate one-third of the validator network, and the attack did not require insider access or special privileges. The Aptos team fixed the vulnerability immediately after it was discovered, with no loss of funds occurring.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
