Sub-brand of @0xbitslab. A security team focused on the Move ecosystem, building the standard and delivering security audits for the Move ecosystem.

Audits ✉️ contact@movebit.xyz
Filter
Exclude
Time range
-
Minimum likes
MoveBit retweeted
🚨【Internet Token DAO Exploit Analysis】 On September 21, @internet_token on Base was exploited after an authentication flaw in its LiquidityUnifier contract allowed an attacker to supply a fake Uniswap V3 pool and forge a callback. 💸 The attacker ultimately bypassed the protocol’s supply validation and minted roughly 925M INT out of thin air. Part of the newly minted supply was then sold into the official INT/WETH pool, draining around 5.847 WETH, roughly $16K, while the attacker retained a large amount of INT. Subsequent copycat minting pushed the INT supply to approximately 156B. This is a textbook Smart Contract Security trust-boundary vulnerability. There was no obvious arithmetic bug in a single function. The real root cause emerged from the interaction between external contract authentication, callback trust, and cross-contract state transitions. 🔑 Key On-Chain Information Network: Base INT Token: 0x968D6A288d7B024D5012c0B25d67A889E4E3eC19 INT/WETH Pool: 0xdec6eadbd8ed3f655cba4bb4eeff6fb43b16969d Governor: 0xc5C3a1882Eff9539527D88E2453cAB10d9bc1581 Treasury / Timelock: 0xE05dD5B785f578337B2B8F695Fbc521669c69403 🛡️ Root Cause The issue sits between LiquidityUnifier.swapV3() and uniswapV3SwapCallback(). swapV3() lets the caller supply the pool address. The contract checks token0/token1, but does not verify that the pool was actually deployed by a trusted Uniswap V3 Factory. That means an attacker can deploy a fake pool, return the expected token0/token1, and pass it into swapV3(). The flow then becomes: Fake Pool → swapV3() → fake swap() → forged callback → INT mint So the protocol did not just trust the callback caller. It trusted a caller whose identity was chosen by the attacker. 🌍 Full Analysis:bitslab.xyz/blog/internet-to…
2
162
4,623
🚨 Security Alert | Harmony Hit by Massive Unauthorized Mint 📡Harmony is investigating a major security incident after roughly 4 billion unauthorized ONE tokens were reportedly created — equivalent to around 26% of its previous circulating supply. On-chain researchers say the exploit may be related to empty blocks, while Harmony’s totalSupply data reportedly failed to immediately reflect the newly created tokens. 💸Around 2.8 billion ONE were reportedly sent to exchanges shortly after the incident. ✅Harmony has since: • Released an emergency validator patch • Paused the Harmony Bridge • Contacted exchanges to freeze related funds • Begun evaluating a possible blockchain rollback The full root cause has not yet been disclosed. 💡The key security question is now whether a flaw in protocol-level validation allowed an invalid state transition to be accepted by the network. 🔘For any Layer 1, token supply is a fundamental protocol invariant. If that invariant can be bypassed, the issue goes far beyond a vulnerable smart contract. MoveBit will continue monitoring the technical disclosure. #BlockchainSecurity #Harmony #Web3Security
1
6
1,479
We’re excited to announce our collaboration with @pivyme 🙌 This partnership reflects a shared commitment to building infrastructure that is robust, secure, and reliable for both users and developers.🛡️
2
2
9
1,446
Excited to explore this new security hub🙌
Security isn't just a feature on Sui. It's the foundation. From the Move language up, every layer is built to protect builders, users, and assets. Explore it all on our new hub for everything security 👇
4
472
Try it in Move Web IDE and let us know what you’d like to see next. 🙌
4
266
🚀Move Web IDE — latest release✅ Auto Completion is now live in the LSP WASM build. Get contextual suggestions as you type — keywords, variables, functions, structs, modules, and more. View symbol types, icons, signatures, and type details in the suggestion popup. 🔘Press Enter or Tab to complete. No install. No setup. Open and code.🙌 🔗ide.bitslab.xyz/ #Sui #Move #Web3 #DevTools
4
3
17
1,486
🚀 Move Web IDE — new release Outline View is now live in the LSP WASM build. Browse Move modules, structs, and functions from a single panel — pinned to the bottom-left of the editor. No install. No setup. Open and code. 🔗 movebit.xyz/MoveWebIDE #Sui #Move #Web3 #DevTools
17
6
25
1,313
🎉 We’re excited to share that MoveBit will be presenting today at the Web3 Scholars Conference 2026 in Hong Kong. web3scholar.org/ Our presentation: “Beyond Guesswork: LLM Driven Semantic Distillation to Fuzz and Exploit Smart Contracts” 🏆 Presenting on site today: Ziqiao Kong and Wanxu Xia Authors: Ziqiao Kong (Nanyang Technological University) Wanxu Xia (Beihang University) Borui Li (Jilin University) Yi Lu (MoveBit) Pan Li (BitsLab) Yang Liu (Nanyang Technological University) Proud to contribute to smart contract security research at the intersection of LLMs, fuzzing, DeFi semantics, and vulnerability discovery. See you at #Web3Scholars2026 in Hong Kong. @DRK_Lab #MoveBit #BitsLab #SmartContractSecurity #BlockchainSecurity #DeFiSecurity #Web3
1
6
11
1,187
Static code audits cannot catch attacks that use legitimate entry points. The Volo incident wasn't a contract bug — it was a privilege design flaw. When a single Keeper holds both `OperatorCap` and oracle submission rights, the loss_tolerance check becomes a self-validating loop the moment that key is compromised. Move's type system protects you from many things. It does not protect you from trusting the wrong signer.
🚨 Incident Analysis: Volo Protocol (Sui) Vault Exploit On 2026-04-21, Volo Protocol on Sui suffered a vault theft resulting in ~$3.27M in direct losses, plus ~$230K in LP share-ratio collapse — combined impact of ~$3.5M. BitsLab's post-incident analysis below. 👇
4
631
Replying to @PawtatoFinance
We are pleased to have completed the comprehensive security audit for @PawtatoFinance 🔐 At MoveBit, we remain committed to upholding the highest security standards to ensure the safety and integrity of the Sui ecosystem.
3
4
15
860
Keep Moving, Stay Secure! 🐎 Happy Chinese New Year from the MoveBit team! As we gallop into the Year of the Horse, we’re committed to accelerating the safety of the Move ecosystem. Wishing our community a year of high-speed growth and zero-vulnerability code. Let’s make 2026 the strongest year for Move yet! 🧧🛡️ #MoveBit #MoveLang #Aptos #Sui #CNY2026 #Web3Security
1
4
271
Replying to @TokenLabsX
Security always comes first 🛡️
1
1
3
127
🚀 sui-move-analyzer v1.5.2 is LIVE! We’ve just dropped a major update to supercharge your @SuiNetwork development! Experience these updates instantly on the Move Web IDE!🔗 ide.bitslab.xyz 💻 Or install sui-move-analyzer extension and directly use it in the Cursor What's New in v1.5.2: 1️⃣ showStructDependencyGraph: Double-click the struct name to jump to the source code definition. 2️⃣ Support use fun: New syntax support added. 3️⃣ Support Implicit Use Funs: New functionality enhanced 4️⃣ Optimisation: Adjusted the mouse scroll zoom speed for showStructDependencyGraph. 5️⃣ Bug Fix: Fixed the issue where the alias syntax in use statements failed to jump. Join our Telegram community to discuss more about Move Analyser: t.me/moveanalyzer #MoveLang #Sui #MoveBit #Web3 #Blockchain
3
3
16
2,141
🔐 We are excited to announce that we have successfully completed the security audit for @ekidenfi Ekiden is a decentralised, orderbook-based hybrid exchange built on the @Aptos blockchain, delivering high performance and capital efficiency. The audit process for their Move smart contracts included: Architecture Review, Unit Testing, and Manual Review 🔧 We are pleased to support the security efforts of the Ekiden team as they build on Aptos. #Aptos #MoveBit #SecurityAudit #DeFi #MoveLang
1
2
15
2,003
🏃Major Update: sui-move-analyzer is leveling up! Build smoother and faster than ever ⚡️ Experience these updates instantly on the Move Web IDE!🔗 ide.bitslab.xyz What's New 👇 1️⃣ New Feature: showStructDependencyGraph > Visualise your code hierarchy by Module ➡️ Struct ➡️ Field ➡️ Type. (Features interactive highlighting on selection and free drag-and-zoom for effortless code reviews) 2️⃣ Massive Performance Boost: Eliminate redundant dependencies to vastly improve loading speed 3️⃣ Bug Fix #16: failed goto on stdlib when implicit dep absent 4️⃣ Bug Fix #17: can't find definition like a::b::fun_name() MoveBit has integrated the latest sui-move-analyser directly into our browser-based IDE. No installation required—just pure productivity: ✅ One-click dependency fetching & server restarts. ✅ Seamless Go-to-Definition. ✅ Flexible plugin management. 🔗 Build better on BitsLab IDE: ide.bitslab.xyz #Sui #MoveLang #Web3 #MoveBit #BlockchainDevelopment @SuiNetwork
6
12
1,271