Back Kucoin Hexens Discloses and Resolves Move VM Vulnerability on the Aptos Chain
The blockchain security firm Hexens disclosed that in February it discovered a vulnerability in the Move VM of the Aptos blockchain, stemming from a caching handling flaw that could lead to type confusion, allowing attackers to theoretically gain high-level privileges over stablecoin minting, cross-chain bridges, and DeFi protocols. Hexens built a simulated environment using a $3,000 server to test the vulnerability, estimating its impact on approximately $250 million in Aptos-native TVL, with a theoretical systemic risk exposure of up to $70 billion. Aptos stated that the exploitability of the vulnerability in real-world conditions is extremely low, and it has been patched through its bug bounty program, with no funds lost.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
