
Researchers said the flaw in Aptos’ Move virtual machine could be reproduced with about $3,000 in server resources and had a high success rate in seizing stablecoin minting or bridge management privileges.
Aptos fixed a critical Move VM vulnerability within hours after security firm Hexens disclosed the issue in February, with no loss of funds reported. Hexens said the cache-handling flaw could theoretically cause type confusion and privileged access, potentially affecting stablecoin minting, bridges and DeFi. The firm estimated immediate exposure at about $250 million in native total value locked and broader system-wide exposure as high as $70 billion. Researchers said the attack could be reproduced with roughly $3,000 in server resources and had about a 90% success rate in seizing stablecoin minting or bridge management privileges. Aptos said the chance of a real-world exploit was very low.