Malformed AS_PATHs can bypass ASPA unless you enforce First AS
BGP hijacks can still pass newer validation schemes when networks fail to enforce that the first AS in a received route is the neighbor that sent it
Let’s talk malformed AS_PATHs. Unless you’re enforcing the “First AS” of received routes, you’re vulnerable to hijacks that not even ASPA validation can prevent. Read more here, and enforce the First AS in BGP.