Aptos blockchain was found to have a critical vulnerability, with an attack cost of only a few hundred dollars; the team has promptly fixed it.
Related
Hexens disclosed that it has patched a major vulnerability in Aptos, with a theoretical risk exposure of up to $70 billion.
According to Mars Finance, on July 5th, blockchain security company Hexens disclosed that it discovered a critical vulnerability in the Aptos Move virtual machine in February of this year, which could theoretically jeopardize approximately $70 billion in crypto assets. However, the Aptos team completed a mainnet patch within hours of the vulnerability disclosure, preventing any user losses. Hexens stated that the vulnerability stems from a "stale-cache" issue in the Move virtual machine, which can lead to type confusion, potentially allowing attackers to gain critical permissions such as stablecoin minting, cross-chain bridges, and DeFi protocols. In simulation tests, the research team achieved an attack success rate of approximately 90% using only a server costing around $3,000, without needing to verify node permissions or internal access rights. Aptos responded that the company quickly completed the patch after receiving the report through its bug bounty program and believes that the vulnerability has extremely low exploitability in a real network environment and will not have any actual impact on users or funds. Hexens believes that if the vulnerability were maliciously exploited, the risks could extend beyond the Aptos ecosystem to include cross-chain bridges, stablecoins, and centralized exchanges. Independent security firm Grego AI estimates that approximately $250 million in TVL on the Aptos chain is directly affected, while the overall theoretical risk exposure could reach as high as approximately $70 billion.
Summer fi: The Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism.
PANews reported on July 8th that Summer.fi released an analysis report on the Lazy Summer Protocol USDC vault attack. On July 6th, attackers manipulated the prices of two USDC vault shares in a single atomic transaction, withdrawing approximately $6.04 million from depositors. The core of the attack lay in the way the vault's Net Asset Value (NAV) was calculated. The attackers donated tokens that still retained their old valuation to Silo Ark, which was suspended after the November 2025 incident but not yet fully removed. This caused the vault's total assets to inflate by approximately 9.5%, raising the share prices. They then redeemed the tokens at the inflated prices and withdrew funds from the vault's real liquidity. The report emphasizes that this attack was not due to a contract code vulnerability, but rather a missing step in the vault's decommissioning process—the Ark's deposit limit had been set to zero, but it was still being counted in the NAV within the active asset pool.
Specter reveals clues about a BONK DAO governance attack, suggesting that the financial flows of Realms' founder may be linked to the attackers.
According to Mars Finance, on-chain security firm Specter released preliminary findings of its investigation into the BONK DAO governance attack. Tracing the on-chain fund flow revealed significant suspicious activity: financial transactions were found between Realms founders' and Crypto Notte-related addresses and the wallet of the suspected attacker. The analysis indicates that the attacker released a malicious governance proposal on June 30th, with a pass threshold of 1% of the total circulating supply of BONK. From July 4th to 5th, the attacker used approximately $4 million in cryptocurrency purchases on exchanges and MarginFi lending to acquire sufficient voting power to push the proposal through and complete the governance attack.
Warning: A wallet generation vulnerability known as "Ill Bloom" leaves thousands of accounts at risk.
PANews reported on July 6th that, according to Coinspect Security, a wallet generation vulnerability called "Ill Bloom" is being exploited by attackers, allowing them to control affected wallets and steal funds. This vulnerability has affected wallets on multiple blockchains since 2018, and the affected wallets were still being generated weeks ago, indicating it did not originate from a single software wallet. Coinspect stated that hundreds of accounts had already lost approximately $3 million on May 27th, and another $2 million has been transferred from exposed wallets in the last few hours. Thousands of accounts remain at risk, covering Bitcoin, Ethereum and L2, Tron, and Solana. Coinspect has released an affected address checking tool and is urging wallet providers to integrate lightweight weak seed phrase detection functionality.
The Ethereum blockchain project BackedFi suffered a suspicious attack, resulting in a loss of approximately $204,200.
PANews reported on July 1 that, according to TenArmorAlert monitoring, the Ethereum blockchain project BackedFi suffered a suspicious attack, resulting in a loss of approximately $204,200.
AI Agents Just Slashed the Cost of a Quantum Attack on Bitcoin
The ECDSA.Fail challenge cut a resource benchmark for one component of a potential quantum attack by 86%.