Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
White hat hackers discover critical vulnerability in Aptos blockchain that threatened $70 billion in crypto assets
00

White hat hackers discover critical vulnerability in Aptos blockchain that threatened $70 billion in crypto assets

Jul 4, 2026

Ethical hackers from Hexens discovered a critical type-confusion vulnerability in the Aptos blockchain on February 25, 2026, which threatened up to $70 billion in digital assets. Using a $3,000 server, researchers simulated the exploit with a 90% success rate. Although Aptos Labs rapidly deployed a patch within hours and disputed the bug's real-world exploitability, the incident highlights severe systemic risks across cross-chain bridges and stablecoins.

Aptos blockchain vulnerability discovery

  • ▪The vulnerability in the Aptos Move virtual machine was reported to the Aptos development team through emergency security channels on February 25, 2026
  • ▪Ethical hackers from the security firm Hexens discovered a critical stale-cache bug in the Aptos blockchain that led to a type-confusion vulnerability

Type-confusion exploit mechanics

  • ▪Hexens researchers simulated the attack with a 17 or 18 out of 20 success rate under real network conditions using a server setup that cost approximately $3,000
  • ▪The simulated attack required no validator access, insider knowledge, or privileged protocol permissions to execute
  • ▪The type-confusion vulnerability allowed software to be tricked into treating one type of onchain resource as another, bypassing the type-system guarantees of the Move language

Systemic cross-chain risk exposure

  • ▪Grego AI calculated that approximately $250 million in Aptos-native total value locked was directly at risk from the exploit, separate from broader cross-chain exposure
  • ▪The exploit could potentially allow attackers to steal protocol capabilities held by LayerZero, Wormhole, and USDC's Cross-Chain Transfer Protocol
  • ▪Hexens assessed that the vulnerability posed a first-order systemic risk of approximately $70 billion across bridges, stablecoins, DeFi protocols, and centralized exchanges

Emergency disclosure process

  • ▪A SEAL911 emergency warroom was opened on February 25, 2026, the same day Hexens filed its report, to coordinate the response
  • ▪Four major downstream projects were alerted on the afternoon of February 25, 2026, receiving local-runnable proof-of-concept material and authority pattern analysis

Rapid patch deployment

  • ▪Aptos Labs deployed a private-validator patch to the mainnet within hours of the February 25, 2026 discovery, preventing any users or funds from being impacted
  • ▪A public pull request reflecting the Aptos security patch became available on February 27, 2026

Blockchain security infrastructure weaknesses

  • ▪Hexens stated that it has not received a technical rebuttal or evidence-based argument from Aptos disputing the demonstrated impact classes
  • ▪An Aptos spokesperson disputed the practical exploitability of the bug, stating that their analysis determined it would have extremely low exploitability in real-world conditions

Perspective of Hexens (Security Researchers)

  • ▪Hexens researchers simulated the attack with a 17 or 18 out of 20 success rate under real network conditions using a server setup that cost approximately $3,000
  • ▪Ethical hackers from the security firm Hexens discovered a critical stale-cache bug in the Aptos blockchain that led to a type-confusion vulnerability
  • ▪Hexens stated that it has not received a technical rebuttal or evidence-based argument from Aptos disputing the demonstrated impact classes
  • ▪Hexens assessed that the vulnerability posed a first-order systemic risk of approximately $70 billion across bridges, stablecoins, DeFi protocols, and centralized exchanges

Perspective of Aptos Labs (Developers)

  • ▪An Aptos spokesperson disputed the practical exploitability of the bug, stating that their analysis determined it would have extremely low exploitability in real-world conditions
  • ▪Aptos Labs deployed a private-validator patch to the mainnet within hours of the February 25, 2026 discovery, preventing any users or funds from being impacted

1 source

Coindesk
How white hat hackers with a $3,000 server found a flaw that could've put $70 billion in crypto at risk
View source article

Story comments

Loading comments…

Related Projects

HexensAptos

Topics

Layer 1sSmart contract platformsCrypto hacks