Key Takeaways
Hexens researchers found a stale-cache bug in the Aptos MoveVM that could trick the chain into treating one type of on-chain resource as another. It was reported February 25, patched within days, and publicly disclosed July 4.
The team simulated the attack for about $3,000 in server costs, approximating mainnet conditions with more than 30 validator nodes, and succeeded in roughly 17 of 20 runs with no insider access.
Hexens put direct Aptos exposure in the low single-digit billions and broader systemic risk near $70 billion. Aptos Labs says real-world exploitability was extremely low and no users or funds were affected.
A patched vulnerability in the Aptos blockchain could have put as much as $70 billion in crypto infrastructure at risk, according to a disclosure by security firm Hexens reported July 4 by CoinDesk.
The flaw sat in the Move virtual machine, the engine that executes smart contracts on Aptos. Hexens described a stale-cache bug that produced type confusion, a condition where attacker-controlled code can make the chain treat one kind of on-chain resource as another. In Move, core permissions like the right to mint a stablecoin or control a bridge live on chain as resources, so compromising them reaches everything that trusts them.
Hexens ran the attack on a simulated network costing about $3,000, built with more than 30 validator nodes and mainnet-shaped traffic, and succeeded in roughly 17 of 20 attempts with no insider access. Polygon CTO Mudit Gupta, who reviewed the proof of concept independently, told CoinDesk, "It ran as claimed, and the exploit made sense." Verification firm Grego AI put roughly $250 million of Aptos-native value directly at risk, while Hexens assessed broader first-order exposure near $70 billion through bridges, USDC's cross-chain transfer protocol, and exchange deposit pathways.
Aptos Labs says the report came through its bug bounty program on February 25 while the issue was already being triaged internally, that a fix reached mainnet within hours, and that no users or funds were affected at any point. The company also disputes how exploitable the bug was under real conditions. A public patch followed on February 27 after a SEAL911 emergency response.
The disclosure follows the tokenized-stock exploit that drained a lending pool at Edel Finance, and it gives regulators weighing the BIS warning on stablecoin plumbing a concrete case study. The number worth sitting with is the smallest one, a $3,000 server.
People Also Ask
What was the Aptos vulnerability Hexens found?
A stale-cache bug in the Aptos Move virtual machine that caused type confusion, letting attacker code treat one type of on-chain resource as another. It was reported February 25, 2026 and patched within days.
Was any money stolen from Aptos?
No. Aptos Labs says a fix reached mainnet within hours of the report and no users or funds were affected at any point.
Why was the risk estimated at $70 billion?
The figure covers first-order systemic exposure beyond Aptos itself, including bridges, cross-chain messaging systems, stablecoin administration flows such as USDC's cross-chain transfer protocol, and centralized exchange pathways. Aptos disputes the practical exploitability behind that estimate.
What is the MoveVM?
The virtual machine that executes smart contracts written in Move, the programming language used by Aptos and Sui that originated in Facebook's shelved Diem project.
