Facebook · CoinDesk
How ethical hackers with just a $3,000 server found a flaw that could've put $70 billion in crypto at risk
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
A $3,000 server was enough for a blockchain security researcher to simulate an attack path they say could have put as much as $70 billion in crypto infrastructure at risk.
Key facts
- A $3,000 server was enough for a blockchain security researcher to simulate an attack path they say could have put as much as $70 billion in crypto infrastructure at risk
- Meanwhile, Grego AI, which independently verified Hexens' proof-of-concept, calculated that approximately $250 million in Aptos-native TVL was directly at risk based on the near-90% success rate
- The team ran the exploit path roughly 20 times in a simulated environment and succeeded 17 or 18 times
- It’s worth noting that $70 billion is an estimate based on minting a mammoth amount of USDC stablecoin and using Circle's Cross-Chain Transfer Protocol (CCTP) to move it across chains
Summary
Ethical hackers from security firm Hexens discovered a flaw in the Aptos blockchain that was patched but could have put up to $70 billion in digital assets at systemic risk, including stablecoins and cross-chain bridges. Researchers simulated the attack with a over-90% success rate under real network conditions, using a well-provisioned server setup that cost $3,000 to simulate about 1/3 of the validator network, and the attack required no insider access or special permissions. The vulnerability was reported through emergency security channels on Feb. 25, and a patch was deployed within days to prevent any funds from being lost.