Smart contract security

Move Smart Contract Audit

Security review for Move contracts where resource ownership, abilities, modules, signers, and object models shape the attack surface.

Move removes some classes of smart contract risk, but it also introduces chain-specific questions around resources, abilities, object ownership, package upgrades, signer capability, and module boundaries.

CTDSEC reviews Move code with attention to both generic resource safety and the execution model of Aptos or Sui.

What CTDSEC reviews

The review is tailored to the target chain and codebase, but the audit always starts with assets at risk, trust boundaries, and the concrete ways the protocol can fail.

Audit focus

Move Smart Contract Audit with manual review, tool-assisted coverage, and remediation support.

Manual reviewTool-assistedRemediation support

Audit Coverage

  • Resource ownership, abilities, and capability handling
  • Signer validation, access control, and package upgrade permissions
  • Object and shared-state behavior on Sui
  • Aptos resource accounts, tables, events, and module interactions
  • Token standards, DeFi accounting, and precision handling
  • Cross-module invariants and test coverage

Risk Areas

  • Capabilities exposed to the wrong account or module
  • Shared object race assumptions
  • Upgrade authority misconfiguration
  • Resource movement that breaks protocol invariants
  • Incorrect handling of package, object, or signer state

Deliverables

  • Move-specific threat model and code findings
  • Chain-specific recommendations for Aptos or Sui
  • Remediation notes and regression-test suggestions
  • Final report for public or private disclosure

Smart Contract Audit FAQ

Short answers for teams preparing an audit scope.

What does a move smart contract audit include?

It includes scope confirmation, manual code review, tool-assisted analysis where useful, severity-ranked findings, remediation guidance, and a final report for the agreed disclosure model.

Can CTDSEC review fixes after the audit?

Yes. Fix verification can be included after the team remediates reported findings, using a new commit and a clear change summary.

How do we request this audit?

Send the repository, target network, language, approximate size, timeline, and any architecture notes through the audit request form.

Ready for a focused smart contract audit?

Share your repository, target network, language, and launch timeline. CTDSEC will review the scope and respond with practical next steps.

Get an Audit Quote