How white hat hackers with a $3,000 server found a flaw that could’ve put $70 billion in crypto at risk

Share This Post

Meanwhile, Grego AI, which independently verified Hexens’ proof-of-concept, calculated that approximately $250 million in Aptos-native TVL was directly at risk based on the near-90% success rate, separate from broader cross-chain exposure.

The $70 billion risk

The vulnerability, discovered by Vahe Karapetyan, CTO and co-founder of Hexens, could, if left unchecked, have exposed a far larger systemic risk surface across bridges, stablecoins, DeFi protocols and centralized exchanges, costing billions and creating a crisis far beyond Aptos itself.

And all it would’ve taken was a few thousand dollars’ worth of servers.

The total cost to spin up the infrastructure needed to run this experiment was approximately $3,000 for a server that simulated an environment designed to approximate Aptos mainnet conditions. Although if a malicious attacker were to actually go through the exploit, it would have required considerably less, without requiring validator access, insider knowledge or privileged protocol permissions.

The team ran the exploit path roughly 20 times in a simulated environment and succeeded 17 or 18 times. The two or three failed attempts didn’t stop the network, meaning the attacker could have simply had another window to try again.

The simulation was built to closely approximate real network conditions, using a cluster of more than 30 validator nodes, a mainnet-shaped stake distribution, organic transaction traffic and heavy execution contention. The Hexens team also tested what they call “non-armed calibration techniques”: dry runs that measured mempool and block-construction conditions before committing to an armed attempt. The firm said those steps materially reduced the uncertainty introduced by the exploit’s probabilistic elements, making the attack path more reliable in practice.

Related Posts

Crypto is going through a massive dot-com style shakeout as over 100 projects fold in 2026

"There were way too many general-purpose layer twos, which...

Bybit sues North Korea and Lazarus Group over $1.5 billion hack, secures asset freeze

“The order is intended to preserve identified stolen digital...

Bitcoin’s exploit week worsens as BTCPay flaw drains Lightning nodes

Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut,...

Bitcoin split after BIP-110 fails, the new chain stopped after two blocks

Bitcoin mining firm AntPool mined the first non-signaling block,...

Why Bitwise predicts a $1.3M Bitcoin price target fueled by institutions

Bitcoin will draw trillions of dollars from institutional investors...

Bitcoin hits block 961,632 as the controversial BIP-110 soft fork attempt begins

Bitcoin has reached block 961,632, triggering the long-awaited mandatory...