Move SR @spearbit | Ambassador @Walrusprotocol

Joined October 2023
500 Photos and videos
Pinned Tweet
24 Oct 2023
1/ As a Solidity auditor, I'll be the first to tell you how unreliable Solidity is for smart contract development. Exploits are a dime a dozen. The #Move programming language was designed for blockchain. Here's one reason why Move will outperform Solidity: Modules 👇🧵
13
24
140
34,341
MoveJay retweeted
📢 Big news from @suidevelopers and @SuiNetwork! A new bounty target is live: Bella Ciao — next-generation Sui VM execution layer rewrite with enhanced performance and new Move capabilities — offers a wide range of bounties: Critical: $100,000 - $1,000,000 High: $10,000 - $50,000 Medium: $5,000 - $10,000 Low: $2,500 - $5,000 Start the #bugbounty hunt right now: hackenproof.com/programs/sui…
8
86
3,889
MoveJay retweeted
Mar 17
We are so back! Mark your calendars: Sui Basecamp 2026 📅 October 7-8 🇸🇬 Singapore ( @token2049 )
125
152
927
94,297
DPRK rn:

ALT Laugh Suspicious GIF

Feb 20
the era of smart contract auditors is over
2
8
907
"Make no mistakes"
1
1
3
579
“AI is gonna take our security jobs!” also AI:
“AI wiLL RePlAcE eVeRy WhItE cOllAr JoB”
1
1
457
while i do understand this pov and the plight of alot of dev teams, what's not being considered is that audit prices are the symptom not the disease. this all stems from something sec ppl have been saying for years, across all industries, which is security isn't prioritized early nor internally. the 10 dev teams in question waiting until they're ready to launch on mainnet to prioritize security exemplifies the problem. dev teams created the environment of high audit costs. you can't build something that take months to complete then outsource months of risk to someone with: - no knowledge of the codebase - to find all crits/highs/mediums/lows/infos vulns - in only a week or sometimes a few days and expect cheap costs. that puts auditors in a high pressure situation coupled with short time constraints while shifting the blame of exploits to the audit team - effectively absolving themselves of their own mistakes. the cheapest option is for devs to prioritize security themselves- or at the very least contract vCISOs- and include ongoing manual reviews, static analysis, fuzzing and/or fv throughout the dev process not ad hoc. but until that's done, framing audit prices as an unnecessary evil and dev practices as a necessary good is oxymoronic.
One of the biggest reasons why it's hard to experiment in crypto is security audits and their costs. I've spoken to more than 10 teams in the last month who are all currently ready to launch on mainnet, but are held back by audits and their insane cost. A basic audit can cost up to 50k for a small codebase, which makes it hard for bootstrapped projects to launch and explore if they should even be spending their time on this. The industry did a terrible job of overpricing security audits and it has strongly held the space back.
3
2
19
1,507
Not just Move. @SuiNetwork Move. Arbitrum is bringing objects to Ethereum. Powered by Stylus
It’s official, you can deploy Move Smart Contracts on @arbitrum! After months of work, we’re proud to introduce the Move-to-WASM compiler for Arbitrum’s Stylus Virtual Machine. This is great news for Move developers: you can now build in one of the largest and most well-funded ecosystems, while benefiting from Arbitrum’s tooling, incentives, and developer support. If you need any help or guidance while using the compiler, feel free to reach out, we’re happy to help. Move on Arbitrum is live 💫🚀 ratherlabs.com/blog/welcome-…
2
2
9
905
Move feels alien to Solidity devs until the object model clicks. Once that clicks, the rest follows. This is a solid walkthrough of that mental shift, honestly worth the read 🔻
1
1
11
550
Today’s the first Monday of February, so here’s a quick January check-in: - only 2 audits - both in Sui Move Bad news is it was kinda slow. The good news is I still cleared ~20k for a slow month. Looking to build on it in February 🔥
2
3
51
2,261
Protocol on Sui was exploited today. Still waiting for the post-mortem but it appears the attacker generated an AdminCap that allowed them to mint tokens. This is why access control capability management is EXTREMELY important. Wishing the team the best on recovery.
🚨 Security Notice Unfortunately, our Cross-Smart-Contract package was exploited. The attacker was able to generate an Admin Cap and mint resource tokens. We've contained the issue and are currently evaluating recovery options. Further updates soon.
3
2
15
1,651
THIS is how you should learn Move security. Every one of these labs maps to bugs I’ve seen slip through real Sui reviews because the code looked "reasonable". Read the workshop below and try to break the labs yourself 🔻
Yesterday someone caught me publishing the repo👀 So today publishing the full writeup from the Sui Security webinar I prepared for @SuiNetwork_PL. medium.com/@monethic/sui-mov… Kudos to @thepantherplus for catching me red-handed with the repo😄
2
1
20
1,436
MoveJay retweeted
31 Dec 2025
My 2025 Web3 Security Wrapped > Joined @spearbit as a Move SR > Audited Aave’s LayerZero’s Move integration w/ some of the most goated auditors > Grew my formal verification skills in Move > Worked with some of the most respected web3 sec firms > Fully booked every month of the year > Began doing Rust audits > >90% of audits this year were in Move > Consistently hit high-5figs every month in Q4 > Was able to fund a trip for my friends to Bali got a private client there > Earned more this year than I ever thought possible > Met and made friends with some of the best people in this industry Goals for 2026 > Tapping into fuzzing in Move > Double the amount of protocols I secure > Build out AI FV tool > Work with more protocols firms > Contribute more to Move security knowledge > Work with more firms new SRs I’m just incredibly proud of the work I put in this year. It was hard to close myself off to a single new and niche language for 2 years with no results but it’s paid off immensely this year. Only tip I have to offer: Study foresight and study conviction. See you all in 2026 🫡
10
2
120
3,824
27 Dec 2025
formal verification during the fix review is probably the most underrated underutilized place to leverage it. problem is: > too much work > clients don’t care for the extra effort might incorporate it in future audits and see the impact it makes
3
14
876
22 Dec 2025
on the real, i don’t even read some of y’all’s posts. if you’re the homie or i see a post from a familiar pfp - it’s an automatic like.
3
1
8
513
17 Dec 2025
2 exploits in 3 weeks????
#PeckShieldAlert YearnFinanceV1 @yearnfi has suffered an exploit, resulting in a total loss of ~$300K. The exploiter has swapped the stolen funds for 103 $ETH, which now sit in the address: 0x0F21...4066.
1
1
12
954
15 Dec 2025
we are starting to see the decoupling between crypto and blockchain
2
1
7
533
14 Dec 2025
“AI is gonna take our security jobs!” also AI:
13 Dec 2025
how many r's in garlic?
1
1
11
1,022
12 Dec 2025
If you care about formal verification, read this. Despite Move being designed hand in hand with FV, you'd be interested in seeing where Certora's Prover outshines the Aptos Move Prover. Read more about it here: arxiv.org/pdf/2502.13929
1
3
20
1,753