Hexens’ disclosure this time is hard-hitting: a $3,000 server uncovered a near-mainnet-level vulnerability. Aptos says it’s extremely low exploitability, but the bounty was paid anyway—those who know, know.

APT3.75%
View Original
CoinNetwork
Hexens: Discovered a critical vulnerability in the Aptos blockchain Move virtual machine and has fixed it.
Hexens stated that in February, it discovered a type confusion vulnerability caused by a cache handling defect in the Aptos Move Virtual Machine. This could potentially grant high-level permissions, such as stablecoin minting, cross-chain bridges, and DeFi. Using servers costing around $3,000, it tested in an environment close to the mainnet about 20 times, with 17–18 successful attempts. If exploited, the native TVL would be about $250 million, and the maximum systemic risk could be around $70 billion. Aptos stated that exploitability is extremely low, the issue has been fixed through a bounty, and it has not affected users or funds.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned