CONTACT

EVALUATION
QUOTATION

AUDIT

DELIVER
REPORT

ISSUE
FIXING

REPORT
UPDATE

ONGOING
MONITORING

Wed Aug 26 2026
Stable ABI, Changing Trust Root: How the Pyth Core Upgrade Redefines Sui Oracle SecurityOn August 26, Pyth Core introduced a major infrastructure upgrade. The new architecture preserves compatibility at the Hermes API and on-chain ABI layers, but the underlying verification model changes significantly: the previous path relied on Pythnet and a 13-of-19 Wormhole Guardian signature threshold, while the new design uses five independent routers with a 3-of-5 quorum.
Learn more
Tue Aug 18 2026
Can Aptos Move Really Avoid Reentrancy? What Function Values ChangedFor a long time, many Move developers have operated under a simple assumption: reentrancy is primarily a Solidity problem, and Move largely avoids it by design.
Learn more
Thu Aug 13 2026
When Account History Was Misclassified as Deposit Proof: A Technical Analysis of the XRPL–Coreum Bridge VulnerabilityThe issue in the XRPL–Coreum bridge incident appears straightforward: when identifying inbound XRPL transfers, the relayer failed to verify whether the Payment Destination was the bridge address.
Learn more
10+ Years of Cybersecurity Experience
20+ Blockchain Security Academic Papers
100+ Selected Audit Projects
MoveBit, a subsidiary brand of BitsLab, is a blockchain security team that specializes in the Move ecosystem. It's at the forefront of utilizing cutting-edge Formal Verification techniques. The team comprises security professionals with extensive experience in both academia and enterprise. As one of the earliest contributors to the Move ecosystem, MoveBit has collaborated closely with Move developers to establish security standards for secure Move applications, making it the most secure Web3 destination.
Transaction-based classification and detection approach for Ethereum smart contract.
Proactive worm propagation modeling and analysis in unstructured peer-to-peer networks.
Tracking the Insider Attacker: A Blockchain Traceability System for Insider Threats.
......
