Skip to content
Hexens Discloses and Resolves Move VM Vulnerability on the Aptos Chain

Hexens Discloses and Resolves Move VM Vulnerability on the Aptos Chain

Kucoin July 5, 2026

The blockchain security firm Hexens disclosed that in February it discovered a vulnerability in the Move VM of the Aptos blockchain, stemming from a caching handling flaw that could lead to type confusion, allowing attackers to theoretically gain high-level privileges over stablecoin minting, cross-chain bridges, and DeFi protocols. Hexens built a simulated environment using a $3,000 server to test the vulnerability, estimating its impact on approximately $250 million in Aptos-native TVL, with a theoretical systemic risk exposure of up to $70 billion. Aptos stated that the exploitability of the vulnerability in real-world conditions is extremely low, and it has been patched through its bug bounty program, with no funds lost.

Extracted Entities

Companies (1)

CWE Weaknesses (1)