Aptos VM flaw showed how a $3,000 server could model a $70 billion crypto risk

Aptos VM flaw showed how a $3,000 server could model a $70 billion crypto risk

N
News Editor 01
2026-07-23 10:50:15
Hexens disclosed a critical Aptos Move VM bug and said a roughly $3,000 server was enough to simulate an attack path with potential exposure reaching $70 billion. Aptos said it patched the issue within hours and no users or funds were affected.
Aptosblockchain-securityMove-VMvulnerability-disclosureDeFi

A server costing about $3,000 was enough for researchers to simulate an exploit path that, by their estimate, could have put as much as $70 billion in crypto infrastructure at risk. The issue centered on Aptos, but the reported blast radius extended well beyond a single chain.

The flaw was found in the Aptos Move virtual machine, the execution layer for smart contracts on the network. Blockchain security firm Hexens said it reported a critical bug to the Aptos development team in late February. The problem was described as a stale-cache bug that led to type confusion, meaning software could be tricked into treating one onchain resource as if it were another. Aptos patched the issue, and the project said no funds were lost.

Why the bug mattered inside Move’s authority model

Aptos and Sui both use the Move smart contract language, which traces back to Facebook’s shelved Diem project. In Move-based systems, protocol permissions are often stored directly as onchain resources. That can include the right to mint a stablecoin, control a bridge, or administer a lending market. If those resources are misread or compromised, the fallout is not limited to one application; it can spread to every system that relies on those permissions.

Hexens compared the issue to a bug on an Ethereum-style chain that would let attacker-controlled code write into storage owned by other contracts, bypassing the type guarantees that Move was built to enforce.

About 20 simulated runs, with 17 or 18 successes

Hexens said the exploit path was discovered by its CTO and co-founder, Vahe Karapetyan. The team tested it roughly 20 times in a simulated environment and reported 17 to 18 successful runs. The failed attempts did not halt the network, which meant an attacker could potentially wait for another opening and try again.

The setup was designed to mirror mainnet conditions rather than serve as a simple lab demo. Researchers built a cluster with more than 30 validator nodes, used a stake distribution shaped like mainnet, added organic transaction traffic, and introduced heavy execution contention. Hexens also used what it called non-armed calibration techniques, dry runs that checked mempool and block-construction conditions before committing to a live attempt. The firm said this reduced uncertainty tied to the exploit’s probabilistic behavior.

Exposure estimates reached beyond Aptos-native TVL

Independent reviewers also examined the proof of concept. Polygon CTO Mudit Gupta said the exploit worked as described and made sense, adding that it required several conditions that appeared to be present on mainnet. Grego AI, which separately verified the proof of concept, estimated that roughly $250 million in Aptos-native TVL was directly at risk based on a near-90% success rate. That figure did not include wider cross-chain exposure.

According to the report, an unpatched version of the bug could have opened a much larger systemic risk surface across bridges, stablecoins, DeFi protocols, and centralized exchanges, turning the issue into something far bigger than an Aptos-only incident.

Aptos says the patch reached mainnet within hours

An Aptos spokesperson said Aptos Labs was notified through its bug bounty program on Feb. 25, while the issue was already under internal triage. The company said a fix was developed, tested, and deployed to mainnet within hours of discovery, and that no users or funds were impacted at any point.

Aptos also challenged the practical exploitability of the flaw. The spokesperson said the team’s analysis found the bug had extremely low exploitability in real-world conditions. Even so, the disclosure put a spotlight on a sensitive class of Move-related failure: once execution-layer type safety breaks around onchain authority, the damage may not stay contained inside one protocol.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.