Critical Aptos Flaw Could Have Exposed Up to $70 Billion, With Attack Simulation Costing Just $3,000

Critical Aptos Flaw Could Have Exposed Up to $70 Billion, With Attack Simulation Costing Just $3,000

N
News Editor
2026-07-06 09:55:59
Security firm Hexens has disclosed a critical vulnerability in the Aptos Move VM that, if left unpatched, could have created systemic risk across bridges, stablecoins, DeFi protocols, and exchange-related infrastructure. The researchers said the attack path could be modeled with roughly $3,000 worth of server resources, while the broader industry exposure in an extreme scenario could reach as high as $70 billion. Aptos said it received the report through its bug bounty program on February 25, investigated the issue immediately, and deployed a fix to mainnet within hours, with no user funds affected. However, the team disputed the practical exploitability of the bug in real mainnet conditions. Independent reviews cited in the report, including from Polygon CTO Mudit Gupta and Grego AI, said the exploit logic was valid and reproducible. The incident highlights how low-level vulnerabilities in execution environments can propagate beyond a single chain, especially when administrative privileges for minting, bridge control, and protocol operations are stored as on-chain resources.
AptosBlockchain SecurityVulnerability DisclosureCross-chain BridgesMove VMDeFiStablecoinsTop Stories

Security firm Hexens has revealed details of a critical vulnerability that once affected Aptos, the Move-based Layer 1 blockchain, arguing that the flaw could have exposed a large portion of crypto infrastructure to cascading risk. According to the researchers, a server costing about $3,000 was sufficient to simulate a viable attack path in a mainnet-like environment, while the broader systemic exposure could have reached as much as $70 billion under extreme conditions.

The issue centered on the Aptos Move Virtual Machine, which executes smart contracts on-chain. Hexens said the bug was caused by cache invalidation leading to type confusion, potentially allowing an attacker to tamper with cached data so that one on-chain resource would be interpreted as another. Because Move stores many sensitive permissions as resources, the researchers argued that exploitation could have extended far beyond a single application.

Aptos says the bug was fixed within hours after disclosure

Hexens said it reported the vulnerability to the Aptos development team in late February. In comments cited by CoinDesk, an Aptos spokesperson said the project received the report through its bug bounty program on February 25, began internal investigation immediately, and after confirming the issue, completed the fix, testing, and mainnet deployment within hours. Aptos added that no users or funds were harmed during the process.

At the same time, Aptos challenged the practical likelihood of a real-world exploit. The team said its internal analysis suggested the vulnerability would be extremely difficult to weaponize in live network conditions. Hexens, however, said Aptos had not provided a technically substantiated rebuttal backed by data and had mainly argued that the exploit involved probabilistic hurdles rather than disputing the existence of the flaw itself.

Why the vulnerability was considered unusually dangerous

Hexens argued that the severity came from the way Move handles privileged resources. Minting rights, bridge administration powers, lending market controls, and other critical protocol permissions can all be stored directly as on-chain resources. If an attacker could confuse resource types and seize or rewrite those permissions, the blast radius would not be limited to one dApp. It could affect every protocol depending on those resource-based controls.

The researchers compared the bug to a hypothetical high-severity flaw in an Ethereum-like environment that would allow a malicious contract to bypass type safety and directly alter another contract’s storage. In Move, type safety is one of the language’s central protection mechanisms, so any failure at that layer carries outsized consequences for the broader ecosystem.

Polygon CTO Mudit Gupta said he independently reviewed the proof-of-concept package and found the exploit chain valid, reproducible, and supported by realistic mainnet preconditions. Grego AI also said it independently reproduced the issue and estimated that roughly $250 million in native locked assets on Aptos mainnet were directly exposed, excluding broader cross-chain contagion risks.

Simulation results suggested repeated attempts were feasible

The vulnerability was discovered by Hexens co-founder and CTO Vahe Karapetyan. The firm said that if the flaw had not been patched in time, it could have opened a path into bridges, stablecoin systems, DeFi applications, and centralized exchange integrations, potentially turning a chain-level bug into an industry-wide crisis.

To test the threat, the team built a mainnet-like simulation cluster with more than 30 validator nodes, recreated staking distribution, and modeled ordinary transaction flows and block congestion conditions. Hexens said it ran around 20 attack simulations and succeeded in 17 to 18 cases. The remaining 2 to 3 attempts did not bring down the network, meaning an attacker could keep retrying until successful. The researchers added that a malicious actor would not need to replicate the full environment they used; in practice, the attack could cost only a few hundred dollars and would not require validator control, inside information, or elevated protocol privileges.

Based on public on-chain data, Hexens estimated that direct exposure across Aptos-native DeFi, tokenized assets, stablecoins, and liquid staking protocols already amounted to several billions of dollars. Once cross-chain bridges, messaging systems, stablecoin issuance routes, and centralized exchanges were included, the total systemic exposure in an extreme scenario rose to an estimated $70 billion.

Cross-chain rails and exchange integrations were seen as the main transmission channels

Grego AI CEO Justus Hanna said the bug could theoretically allow an attacker to seize core administrative privileges tied to infrastructure such as LayerZero, Wormhole, and Circle’s Cross-Chain Transfer Protocol, or CCTP, thereby putting associated locked funds at risk. The report said the $70 billion estimate was based on a worst-case scenario in which an attacker mass-minted USDC and moved it across multiple chains through CCTP, amplifying both liquidity and accounting damage across the market.

The article noted that Circle would likely pause USDC transfers if such an incident occurred, although prior statements from the company suggested it would not freeze user assets without legal authorization, leaving some uncertainty around emergency execution. Even if issuers, bridges, and exchanges moved quickly to contain the incident, the market impact could still have been severe.

Hexens said its proof-of-concept did not actually mint tokens, but it fully demonstrated takeover paths for top-level bridge administration, signing authority, and protocol accounting control. The researchers identified the cross-chain routes linking Aptos to centralized exchanges as one of the most important threat vectors, since an attacker could potentially manipulate exchange deposit accounting through those channels.

Disclosure timeline and broader lessons for the industry

According to Hexens, an emergency response group called SEAL911 was formed on the same day the report was submitted. Within hours, the project team received the full disclosure package, and later that afternoon, four core downstream projects were also provided with the exploit demonstration files and privilege risk analysis. On February 27, code commits related to the fix appeared in the public repository. Aptos said private patches for validators had already been deployed before the public code was released.

No funds were ultimately lost, but the simulated results underscore how a low-level blockchain flaw can rapidly become a cross-protocol, cross-chain, and cross-platform event. The report argues that traffic throttling, issuer freezes, bridge controls, exchange monitoring, and validator patches should not be treated as secondary safeguards. In a real chain-level exploit, those mechanisms can determine whether an incident remains localized or escalates into a market-wide systemic crisis.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.