Move Smart Contract Audit
Security review for Move contracts where resource ownership, abilities, modules, signers, and object models shape the attack surface.
Move removes some classes of smart contract risk, but it also introduces chain-specific questions around resources, abilities, object ownership, package upgrades, signer capability, and module boundaries.
CTDSEC reviews Move code with attention to both generic resource safety and the execution model of Aptos or Sui.
What CTDSEC reviews
The review is tailored to the target chain and codebase, but the audit always starts with assets at risk, trust boundaries, and the concrete ways the protocol can fail.
Audit focus
Move Smart Contract Audit with manual review, tool-assisted coverage, and remediation support.
Audit Coverage
- Resource ownership, abilities, and capability handling
- Signer validation, access control, and package upgrade permissions
- Object and shared-state behavior on Sui
- Aptos resource accounts, tables, events, and module interactions
- Token standards, DeFi accounting, and precision handling
- Cross-module invariants and test coverage
Risk Areas
- Capabilities exposed to the wrong account or module
- Shared object race assumptions
- Upgrade authority misconfiguration
- Resource movement that breaks protocol invariants
- Incorrect handling of package, object, or signer state
Deliverables
- Move-specific threat model and code findings
- Chain-specific recommendations for Aptos or Sui
- Remediation notes and regression-test suggestions
- Final report for public or private disclosure
Related Audit Services
Compare coverage for your language, network, and protocol.
Aptos Smart Contract Audit
Explore related audit coverage and preparation guidance.
Sui Smart Contract Audit
Explore related audit coverage and preparation guidance.
Protocol Security Audit
Explore related audit coverage and preparation guidance.
Smart Contract Audit
Explore related audit coverage and preparation guidance.
Prepare for Your Audit
Practical review questions and scoping guidance for your engineering team.
Smart Contract Audit Checklist
A practical smart contract audit checklist covering scope, access control, accounting, oracles, upgrades, tests, deployment, and remediation.
How to Prepare for a Smart Contract Audit
How protocol teams can prepare repositories, documentation, tests, deployment details, and scope before a smart contract audit.
How Much Does a Smart Contract Audit Cost?
What affects smart contract audit cost, including code size, complexity, blockchain ecosystem, documentation, testing, and remediation needs.
Smart Contract Audit FAQ
Short answers for teams preparing an audit scope.
What does a move smart contract audit include?
It includes scope confirmation, manual code review, tool-assisted analysis where useful, severity-ranked findings, remediation guidance, and a final report for the agreed disclosure model.
Can CTDSEC review fixes after the audit?
Yes. Fix verification can be included after the team remediates reported findings, using a new commit and a clear change summary.
How is a move smart contract audit priced?
The quote depends on the agreed code scope, complexity, dependencies, and remediation review. Start with a project description; we can clarify repository access and timeline by email.
Get a smart contract audit quote
Tell us what you are building and when you plan to launch. Start with a short description; repository access and technical scope can follow.