Aptos VM Flaw Exposed by Hexens Carried Up to $70 Billion in Systemic Risk

Aptos VM Flaw Exposed by Hexens Carried Up to $70 Billion in Systemic Risk

N
News Editor 01
2026-07-23 17:00:15
Hexens said a type confusion flaw in the Aptos Move VM reached nearly a 90% success rate in simulated attacks. The firm warned the broader systemic exposure could reach $70 billion, while Aptos said it patched the issue within 48 hours and no users or funds were affected.
AptosMove VMBlockchain SecurityCross-Chain BridgesStablecoins

Security firm Hexens said a flaw in the Aptos Move virtual machine could have opened the door to systemic risk across bridges, stablecoin operations, and exchange-linked assets. Its top-line estimate put the exposure as high as $70 billion. In attack simulations designed to mirror mainnet conditions, the team reported a success rate close to 90%.

Type confusion bug sat inside the Move VM

The issue was found by Hexens CTO Vahe Karapetyan. Hexens described it as a “stale-cache bug” that triggers type confusion, causing software to treat one on-chain resource as if it were another. In practical terms, the firm said the flaw could let an attacker break through the type-safety guarantees that Move is meant to enforce at the execution layer.

Hexens compared the effect to a scenario in an Ethereum-style system where attacker-controlled code can write directly into another contract’s storage. The concern goes beyond a single application. On Move-based systems, roles tied to stablecoin minting, bridge control, and lending-market administration are often stored as on-chain resources, so compromise at that level can spread through dependent protocols.

$3,000 test setup and 17 to 18 successful runs out of 20

To test whether the flaw was realistically exploitable, the researchers built an environment meant to resemble the Aptos mainnet. It included more than 30 validator nodes, a staking distribution close to mainnet, real transaction flow, and heavy execution contention. Hexens said the setup cost only about $3,000. It also said a real attack would likely cost less and would not require validator privileges, insider knowledge, or special access.

Across roughly 20 simulation attempts, the team said 17 to 18 were successful. Failed attempts did not halt the network, according to Hexens, which means an attacker could simply wait for another opening and try again. That repeatability is central to the firm’s high-risk assessment.

Disclosure on February 25, patch made public on February 27

Hexens said it reported the vulnerability through Aptos’s bug bounty program on February 25, 2026. Aptos told CoinDesk that its internal teams were already handling the issue when the report arrived. On the same day, volunteer incident-response group SEAL911 opened a war room to coordinate the response.

Aptos said affected vendors were notified within hours. Later that day, four major downstream projects received a locally runnable proof of concept. By February 27, a public patch pull request had gone live. Aptos added that the fix had already been deployed to private validators before the public commit appeared. The company’s statement to CoinDesk said the patch was developed, tested, and deployed to mainnet within hours of discovery, with no user or fund impact.

Aptos downplayed exploitability, outside reviewers did not

Aptos said its analysis found the bug had very low exploitability under real-world conditions. Hexens disputed that view, saying it had not received any evidence-based technical rebuttal. The only concern raised by Aptos, according to Hexens, was the probabilistic nature of the exploit, which the researchers said their calibration technique was designed to address.

Independent review leaned closer to Hexens. Polygon CTO Mudit Gupta said after reviewing the proof of concept that it worked as described and that the vulnerability made sense, while noting that several conditions had to be met and appeared to have been met in mainnet-like testing. Grego AI, another group that validated the PoC, said the flaw could be used to seize powers associated with protocols including LayerZero, Wormhole, and the USDC cross-chain protocol CCTP. Grego AI CEO Justus Hanna said that if a malicious actor obtained this exploit, they could take whatever TVL they wanted.

Direct TVL risk and a much larger systemic estimate

The estimates vary depending on scope. Hexens said the first layer of direct exposure on Aptos, spanning DeFi, tokenized assets, stablecoin infrastructure, and liquid staking, amounted to several billions of dollars. Grego AI used the near-90% success rate to estimate that about $250 million in Aptos-native TVL was directly at risk, excluding cross-chain exposure.

The $70 billion figure from Hexens refers to a broader systemic scenario covering bridges, cross-chain messaging systems, stablecoin issuance and management flows, and assets reachable through centralized exchanges. That estimate assumes an attacker could massively over-mint USDC and move it onto other chains through Circle’s Cross-Chain Transfer Protocol. The report also noted that Circle recently said it would not freeze assets without legal authorization. That does not make the full $70 billion scenario inevitable, but it shows how far the damage could travel if key control roles were compromised.

Hexens added that during testing it temporarily took over a role similar to a “master minter” and operated through legitimate administrative paths. The researchers stopped short of actual minting, but said the result was enough to show that such privileged roles belong in a full threat model. In their view, the main route for wider contagion would run through centralized exchanges, especially bridging paths that connect Aptos on-chain activity with exchange deposit accounting.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.