
Researchers said the flaw in Aptos’ Move virtual machine could be reproduced with about $3,000 in server resources and had a high success rate in seizing stablecoin minting or bridge management privileges.
Multiple sources including CoinDesk confirm the core claim: Aptos patched a critical Move VM bug (a stale-cache/type-confusion flaw) that researchers (Hexens) demonstrated could be exploited for a few hundred dollars using a ~$3,000 server with ~90% success rate, potentially putting up to $70 billion in assets at systemic risk. CryptoBriefing notes the same-day patch (Feb 25, 2026) and independent PoC validation by Polygon CTO Mudit Gupta. The one nuance is that Aptos disputed full exploitability under mainnet conditions and no funds were lost, and the $70B figure represents a systemic-exposure ceiling rather than confirmed at-risk funds — consistent with the headline's 'as much as $70 billion' framing.
Aptos fixed a critical Move VM vulnerability within hours after security firm Hexens disclosed the issue in February, with no loss of funds reported. Hexens said the cache-handling flaw could theoretically cause type confusion and privileged access, potentially affecting stablecoin minting, bridges and DeFi. The firm estimated immediate exposure at about $250 million in native total value locked and broader system-wide exposure as high as $70 billion. Researchers said the attack could be reproduced with roughly $3,000 in server resources and had about a 90% success rate in seizing stablecoin minting or bridge management privileges. Aptos said the chance of a real-world exploit was very low.