Back Kucoin Hexens Reveals Aptos Fixed a Critical Vulnerability with Theoretical Exposure of Up to $70 Billion
BlockBeats report: On July 5, blockchain security firm Hexens disclosed that in February, it identified a critical vulnerability in the Aptos Move virtual machine, which theoretically could have compromised approximately $70 billion in crypto assets. However, the Aptos team completed a mainnet fix within hours of the vulnerability disclosure, resulting in no loss of user funds.
Hexens stated that the vulnerability stems from a "stale-cache" issue in the Move virtual machine, which could lead to type confusion, allowing attackers to gain critical permissions such as minting stablecoins, accessing cross-chain bridges, and interacting with DeFi protocols. In simulated tests, the research team achieved approximately 90% attack success rate using only a $3,000 server setup, without requiring validator node privileges or internal access.
Aptos responded that the company quickly patched the issue after receiving the report through its bug bounty program and believes the vulnerability has extremely low exploitability in a live network environment, posing no actual risk to users or funds.
Hexens believes that if the vulnerability is maliciously exploited, the risks may extend beyond the Aptos ecosystem to critical infrastructure such as cross-chain bridges, stablecoins, and centralized exchanges. Independent security firm Grego AI estimates that approximately $250 million in TVL on the Aptos chain is directly affected, with the total theoretical risk exposure reaching up to $70 billion.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
