Skip to content
Blockchain security firm Hexens disclosed that it discovered

Blockchain security firm Hexens disclosed that it discovered

Kucoin July 5, 2026

Blockchain security firm Hexens disclosed that it discovered a critical vulnerability in the Move Virtual Machine (Move VM) of the Aptos blockchain in February this year, and the issue was patched within hours of reporting, resulting in no financial loss. Hexens stated that the vulnerability stemmed from a caching handling flaw that could lead to type confusion, allowing attackers to theoretically gain high-privilege roles such as stablecoin minting, cross-chain bridges, and DeFi protocols. The research team built a simulation environment close to mainnet using approximately $3,000 in server costs and tested exploitation paths around 20 times, succeeding 17 to 18 times. They estimated the vulnerability could have impacted approximately $250 million in Aptos-native TVL; if further extended to infrastructure such as cross-chain bridges, stablecoins, and centralized exchanges, the theoretical systemic risk exposure could reach up to $70 billion. Aptos responded that the exploitability of this vulnerability in real-world conditions is extremely low and confirmed that it was promptly patched through its bug bounty program, with no impact on users or funds. (CoinDesk)

Extracted Entities

Companies (1)

CWE Weaknesses (1)