How ethical hackers with just a $3,000 server found a flaw that could've put $70 billion in crypto at risk

Security researchers at Hexens discovered a critical 'stale-cache' vulnerability in the Aptos blockchain that could have potentially compromised billions in assets. Aptos Labs patched the flaw immediately upon notification, stating that no user funds were impacted and the bug had low real-world exploitability.
Why it matters
This incident underscores the systemic risks inherent in smart contract languages and the vital role of bug bounty programs in preventing catastrophic financial losses in decentralized finance.
At the center of the disclosure was a flaw in Aptos, a layer-1 blockchain built on Move, the smart contract language used by Aptos and Sui, that stems from Facebook’s shelved Diem project .
The article provides a balanced technical account, including both the researchers' findings and the company's official response regarding the severity of the bug.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in