Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
move-vulnerability-database — Move Vulnerability Database | Kitploit
Tools/GitHubGitHub/movemaverick/move-vulnerability-database
Vulnerability AnalysisPapers & ResearchLearning & EducationCurated Resources
GitHubmovemaverick/move-vulnerability-database

move-vulnerability-database

Move Vulnerability Database

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website
90151 month agoReviewed by Kitploit

Welcome to the Move Vulnerability Database (MVD) v3.0!

A comprehensive collection of vulnerability patterns in the Move ecosystem.

What's Inside

  • Vulnerability Patterns - Categorized security issues with examples and severity ratings
  • Appendix - Audit reports and protocol references
  • Learning Resources - Curated materials for learning Move security

This resource consolidates 1000+ security vulnerabilities extracted from 200+ public Move audit reports across multiple firms and auditors. The database categorizes vulnerabilities into common patterns—from Input Validation and Business Logic flaws to Access Control and State Management issues—providing a central reference for developers, auditors, and security researchers to understand, recognize, and learn from real-world mistakes in Move codebases.

Vulnerability PatternsFindings
Business Logic296
Input Validation170
Calculation Errors148
Coding Mistake76
Access Control73
State Management64
Code Optimization43
Denial of Service40
Missing Functions37
Data Inconsistency31
Oracle Issues27
Centralization Risk25
Constant Definition21
Cross-Implementation16
Runtime/Development Issues15
Missing Version Check12
Gas-related Issues11
Looping Issues10
Front-running7
Collision5
Inflation Attacks5
Documentation Mismatch3
Signature Replay3
Third-Party Risk2
Race Condition1
Total1141

Data sourced from public Move audit reports by the following auditors/firms:

Refer to the Appendix for the full list of reports and protocols.

⚠️ Disclaimer

All findings and summaries in this database are sourced from publicly available audit reports.

I do not own or claim ownership of any reports, documents, or content referenced here — all rights belong to their respective auditors, firms, and project teams.

This repository is an independent, educational, and non-commercial project created to help the community study and understand common vulnerability patterns in the Move ecosystem.

While I aim for accuracy, there may be typos, errors, broken links, or misattributed information.

If you spot any mistakes or missing details, please open an issue or reach out so I can correct them.

💬 Support & Contributions

If you'd like to learn more about the project or support future development, see the About section.

Download Tool
Audit Firm/AuditorReport Links
OtterSecSampled Public Audit Reports (OtterSec Notion)
MoveBitMoveBit — Sampled Audit Reports
MoveJayMoveJay (Jayfromthe13th)
ZellicZellic Reports
SpearbitSpearbit Reports
CantinaCantina Reports
Code4ArenaCode4Arena Reports
CertoraCertora Security Reports
HackenHacken Audits
Pashov Audit GroupPashov Audit Group — Audits
ExVul SecurityExVul Audits
QuantstampQuantstamp Reports
SlowMistSlowMist Reports
Three SigmaThree Sigma Reports
AsymptoticAsymptotic Reports
SherlockSherlock Reports