Skip to content
Aptos Blockchain Exposed to Critical Vulnerability, $70 Billion in Assets at Systemic Risk

Aptos Blockchain Exposed to Critical Vulnerability, $70 Billion in Assets at Systemic Risk

Kucoin • July 5, 2026

According to CoinDesk, researchers at blockchain security firm Hexens discovered a "stale cache" type confusion vulnerability in the Move virtual machine of the Aptos blockchain. Attackers could launch an attack with nearly 90% success rate in a simulated environment at a server cost of only $3,000, without requiring validator privileges or insider knowledge. During simulated tests, the researchers executed approximately 20 attacks, succeeding in 17 to 18 instances, and verified the potential to gain control over management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that this vulnerability directly threatens DeFi protocols, stablecoins, and liquid staking applications on Aptos, exposing assets worth several billion dollars. If exploited through cross-chain bridges, stablecoin minting, or centralized exchanges, the systemic risk exposure could reach up to $70 billion. After receiving the vulnerability report on February 25, the Aptos team patched and deployed the fix to mainnet within hours; no user funds have been compromised.

Extracted Entities

CWE Weaknesses (1)

Platforms (2)