Saturday, July 11, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
DeFi

Aptos Move VM Bug’s Contested $70bn Risk Estimate Tests Disclosure Norms

A patched Aptos flaw, priced by researchers at $70bn in systemic exposure against $250m in locked value, fuels debate over blockchain security disclosure.

By Rajesh Patel · ·3 min read
Aptos Move VM Bug’s Contested $70bn Risk Estimate Tests Disclosure Norms

A vulnerability discovered in the Move virtual machine underpinning the Aptos blockchain has reignited debate over how the industry quantifies systemic risk, after security researchers put a $70 billion figure on potential cascading exposure while the network’s own assessors valued directly locked funds at a fraction of that sum.

Blockchain security firm Hexens identified what it termed a “stale-cache bug” in Aptos’s Move VM on 25 February 2026, according to Crypto Briefing. The flaw, a type-confusion vulnerability, could have allowed an attacker to trick the system into misreading data types, potentially seizing control of critical on-chain functions such as minting permissions and bridge management systems.

Low-cost exploit, high simulated success rate

Hexens simulated the exploit using a server setup costing roughly $3,000 and recorded a success rate approaching 90 per cent, succeeding in 17 to 18 out of 20 attempts. Polygon chief technology officer Mudit Gupta independently reviewed the proof-of-concept, according to the report, adding external corroboration to the firm’s findings.

The modest cost of the attack infrastructure set against the scale of the claimed exposure is likely to draw scrutiny from institutional risk teams evaluating Layer-1 networks, where the barrier to a credible proof-of-concept can matter as much as the theoretical maximum damage.

A disputed $70bn figure against $250m in locked value

Hexens’s $70 billion systemic risk estimate does not reflect Aptos’s direct total value locked, which security assessment firm Grego AI placed at approximately $250 million. Instead, the figure is intended to capture cascading exposure across stablecoins, DeFi protocols, cross-chain bridges and centralised exchange pathways that rely on Aptos infrastructure.

Aptos Labs disputed the severity of the assessment, arguing that the bug carried low exploitability in practical conditions on the live mainnet. The gap between the two figures underscores a persistent tension in blockchain security disclosure: whether risk should be measured against a protocol’s own balance sheet or against its footprint across the wider ecosystem it services.

Rapid patch, coordinated disclosure

Aptos Labs patched the vulnerability on mainnet on 27 February, two days after Hexens’s discovery, and no funds were reported lost. Disclosure was coordinated through the SEAL911 emergency response channel, with four downstream projects notified on the same day the flaw was identified. Public disclosure followed responsible-disclosure protocols and was made on 4 July 2026.

Aptos operates a bug bounty programme offering up to $1 million for serious vulnerabilities, a structure increasingly common among Layer-1 networks seeking to incentivise responsible reporting ahead of public exploitation.

Implications for DeFi deployment decisions

The Move VM, originally developed at Meta’s now-defunct Diem project, was designed with safety as a founding principle and is also used by rival Layer-1 Sui. Aptos additionally competes with Solana and various Ethereum scaling solutions for institutional and developer attention.

Even contested, a $70 billion systemic risk estimate is likely to factor into due diligence for DeFi teams and institutional allocators weighing where to deploy capital, given the growing emphasis regulators and risk committees place on the security track record of base-layer infrastructure rather than headline valuation alone.

Read more: $21m BONK Treasury Drain Exposes Governance Gaps in DAO Oversight

More DeFi

Leave a Reply

Your email address will not be published. Required fields are marked *