Defense-in-Depth Runtime Safety in Move

📅 2026-06-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the critical security risks—such as asset loss, privilege forgery, and state corruption—that can arise from vulnerabilities in static verifiers for smart contracts. To mitigate these threats, the paper introduces a defense-in-depth mechanism orthogonal to static verification within the Move language runtime on the Aptos blockchain. By leveraging a sandboxed virtual machine, the approach dynamically enforces key safety invariants, including type safety, reference integrity, and core logical constraints. This dynamic checking effectively compensates for potential gaps in static analysis or risks posed by malicious bytecode, thereby substantially enhancing the reliability and robustness of on-chain transaction execution. The proposed mechanism establishes a new dimension of security assurance for Move in real-world deployment scenarios.
📝 Abstract
Move is a smart-contract language used to execute transactions on the Aptos blockchain. Move programs execute in a sandboxed VM as typed bytecode. The VM statically verifies foundational safety properties like type safety and reference safety at code loading time. In principle, this design gives strong guarantees for Move. However, the static verification logic is complex and continually evolving with the language; like any software, it is not immune to bugs. In a live blockchain setting, a missed rule violation can translate directly into loss of assets, forged authority, or unrecoverable corruption of on-chain state. For this reason, Aptos relies on defense-in-depth runtime safety checks that independently verify the critical invariants during execution, providing protection against latent verifier bugs and malicious bytecode. This paper motivates and describes the runtime safety checks for Move on Aptos.
Problem

Research questions and friction points this paper is trying to address.

Defense-in-Depth
Runtime Safety
Move
Smart Contracts
Blockchain Security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Defense-in-Depth
Runtime Safety
Move Language
Static Verification
Blockchain Security
V
Victor Gao
Aptos Labs, Palo Alto, USA
Wolfgang Grieskamp
Wolfgang Grieskamp
Aptos
Vineeth Kashyap
Vineeth Kashyap
Aptos Labs
Programming LanguagesSecurityPerformanceMachine Learning
G
George Mitenkov
Aptos Labs, Palo Alto, USA
T
Teng Zhang
Aptos Labs, Palo Alto, USA
R
Runtian Zhou
Aptos Labs, Palo Alto, USA
A
Andrea Cappa
Aptos Labs, Palo Alto, USA
M
Marco Ilardi
Aptos Labs, Palo Alto, USA