On July 5, blockchain security company Hexens disclosed that it had identified a serious vulnerability in the Aptos Move virtual machine back in February, which could theoretically jeopardize approximately $70 billion in crypto assets. However, the Aptos team completed a mainnet fix within hours of the vulnerability disclosure, preventing any loss of user funds. Hexens stated that the vulnerability stemmed from a 'stale-cache' issue in the Move virtual machine, which could lead to type confusion, allowing attackers the opportunity to gain critical permissions for minting stablecoins, cross-chain bridges, and DeFi protocols. In simulated tests, the research team achieved about a 90% success rate in attacks using an environment set up with approximately $3,000 worth of servers, without needing to verify node permissions or internal access rights. Aptos responded by stating that the company quickly completed the fix after receiving reports through its bug bounty program and believes the exploitability of the vulnerability in a real network environment is extremely low, posing no actual threat to users or funds. Hexens warned that if the vulnerability were to be maliciously exploited, the risks could extend beyond the Aptos ecosystem, potentially affecting cross-chain bridges, stablecoins, and centralized exchanges. Independent security firm Grego AI estimates that approximately $250 million in Total Value Locked (TVL) on the Aptos chain is directly impacted, while the overall theoretical risk exposure could reach around $70 billion.
All Comments