SAN FRANCISCO, Dec. 17, 2025 /PRNewswire/ — BitsLab‘s audit and security research brand MoveBit has released a new research work, ‘Belobog: Move Language FuzzingSAN FRANCISCO, Dec. 17, 2025 /PRNewswire/ — BitsLab‘s audit and security research brand MoveBit has released a new research work, ‘Belobog: Move Language Fuzzing

BitsLab’s MoveBit Releases Research: Belobog, a Move Fuzzing Framework Oriented Toward Real-World Attacks

2025/12/17 20:45
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

SAN FRANCISCO, Dec. 17, 2025 /PRNewswire/ — BitsLab‘s audit and security research brand MoveBit has released a new research work, ‘Belobog: Move Language Fuzzing Framework For Real-World Smart Contracts’ (arXiv: 2512.02918, preprint). The paper is publicly available on arXiv: https://arxiv.org/abs/2512.02918.

Move has become a foundational language for many Web3 developers. Its strong type system and resource-oriented semantics provide strict guarantees around asset ownership, unauthorised transfers, and data race prevention, which is why multiple ecosystems increasingly deploy critical assets and core protocols on Move to achieve stronger security and lower systemic risk.

However, MoveBit’s long-term auditing shows that critical vulnerabilities rarely arise from obvious issues such as syntax errors or type mismatches. Instead, they arise from real-world system complexity—cross-module interactions, hidden assumptions, and composable call sequences—explaining why high-impact incidents still occur and why Move security research must go further.

According to MoveBit, a key gap is the absence of an effective fuzzing solution tailored to Move. Its stricter constraints make traditional fuzzing ineffective, as generating transaction sequences that are both type-correct and semantically reachable is difficult; when executions fail, deep states and absolute vulnerability paths remain unexplored.

To address this challenge, MoveBit collaborated with a university research team to develop and publish the Belobog research, releasing it on arXiv as a preprint to share early progress and gather community feedback. The work is being submitted to PLDI’26, with updates to be shared after the submission outcome and peer review are completed.

Making Fuzzing ‘Run in’ Move: From Random Trial-and-Error to Type Guidance

Belobog’s core idea is simple: since Move’s type system is fundamental, fuzzing should use types as guidance rather than an obstacle. Traditional random or mutation-based fuzzing in Move produces mostly invalid inputs, leading to frequent execution failures and little meaningful coverage before deeper states can be reached.

Belobog equips the fuzzer with a ‘map’. By building a type graph from Move’s type semantics, it guides transaction generation and mutation along valid type relationships, producing executable call sequences that move deeper into the contract’s state space.

MoveBit emphasises that the practical value of this change is not primarily about more complex algorithms, but about direct outcomes: a higher ratio of effective samples, improved exploration efficiency, and a better chance of reaching deeper paths where real-world vulnerabilities often occur.

Handling Heavy Constraints: Using Concolic Execution to ‘Open the Door’

In real Move contracts, critical logic is often protected by layers of checks and constraints, making mutation-only fuzzing prone to getting stuck at boundaries. Belobog addresses this with concolic execution, combining concrete execution with symbolic guidance to satisfy branch conditions, penetrate guarded paths, and reach deeper states with greater coverage.

MoveBit highlights this as particularly relevant in Move, where multiple layers of constraints can reinforce confidence in safety, while meaningful issues may remain hidden in the interactions among those constraints. Belobog’s objective is to push testing closer to these ‘gaps’.

Aligning With the Real World: Beyond Demos Toward Real Attack Paths

MoveBit positions Belobog as a framework evaluated against real projects and real vulnerability conclusions, rather than focusing on limited demo scenarios. Based on the paper’s reported experimental results, Belobog was assessed on 109 real-world Move innovative contract projects and detected 100% of Critical vulnerabilities and 79% of Major vulnerabilities, as confirmed by human security experts.

A further point highlighted in the work is that Belobog can reproduce full exploits from real on-chain incidents without relying on prior knowledge of vulnerabilities. The stated value of this capability is that it more closely reflects real adversarial conditions: attackers often succeed not through a single isolated function bug, but through complete paths and state evolution.

Framing the Work: Not Just ‘Another Tool’

MoveBit emphasises that this work is not just a single tool, but a practical direction that translates real-world security experience into reusable, verifiable methods. In this sense, Belobog is not ‘another fuzzer’, but a step toward more realistic Move fuzzing—able to execute reliably, reach deeper states, and better reflect real attack paths.

The team describes Belobog as a developer-friendly framework designed to lower adoption barriers and support continuous security testing within existing workflows, rather than one-off fuzzing. MoveBit also plans to open-source Belobog, positioning it as shared community infrastructure rather than a standalone experimental tool.

Paper (preprint): https://arxiv.org/abs/2512.02918
(Also submitted to PLDI’26 and currently awaiting peer review.)

About MoveBit

MoveBit is a subsidiary brand of BitsLab and a blockchain security company focused on the Move ecosystem. It was an early adopter of formal verification in Move and one of the earliest contributors to the ecosystem. The team combines academic and industry security expertise, with research published at top conferences such as NDSS and CCS, and provides comprehensive security audit services for leading global projects.

Contact:
Marketing Manager
Jason Li
BitsLab
jasonlee@bitslab.xyz 

Photo: https://mma.prnewswire.com/media/2847633/Belobog_Research_MoveBit.jpg
Photo: https://mma.prnewswire.com/media/2847687/Belobog.jpg
Logo: https://mma.prnewswire.com/media/2847632/BitsLab_Logo.jpg

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/bitslabs-movebit-releases-research-belobog-a-move-fuzzing-framework-oriented-toward-real-world-attacks-302644652.html

SOURCE BitsLab

Opportunità di mercato
Logo Movement
Valore Movement (MOVE)
$0,01767
$0,01767$0,01767
-0,67%
USD
Grafico dei prezzi in tempo reale di Movement (MOVE)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

The post Stunning 96% Surge And 50% Plunge Define Volatile Market Session appeared on BitcoinEthereumNews.com. Crypto Gainers And Losers: Stunning 96% Surge And
Condividi
BitcoinEthereumNews2026/04/03 09:20
BitGo Holdings (BTGO) Stock Climbs Following Launch of Institutional Stablecoin Platform

BitGo Holdings (BTGO) Stock Climbs Following Launch of Institutional Stablecoin Platform

BitGo Holdings (BTGO) stock climbs as the company launches BitGo Mint, streamlining stablecoin operations for institutional clients. The post BitGo Holdings (BTGO
Condividi
Blockonomi2026/04/02 21:13
Coinbase adds USDC lending with Morpho on Base

Coinbase adds USDC lending with Morpho on Base

The post Coinbase adds USDC lending with Morpho on Base appeared on BitcoinEthereumNews.com. Coinbase will introduce USDC lending directly within its app, allowing users to earn yields as high as 10.8% through a new onchain integration with Morpho, the company said on Thursday. The feature, which will roll out to customers in the US (excluding New York), Bermuda, and other jurisdictions over the coming weeks, enables users to lend their USDC to borrowers on Base, Coinbase’s layer-2 blockchain. The lending system works by creating a smart contract wallet that connects to the Morpho protocol, with Steakhouse Financial managing onchain vaults that allocate liquidity across multiple markets. This design is meant to optimize returns while preserving user access to funds, which can be withdrawn when liquidity is available. Coinbase emphasized that despite the complexity of decentralized finance (DeFi), the integration will maintain the platform’s familiar interface and security features. USDC, a stablecoin redeemable 1:1 for U.S. dollars, already provides Coinbase users with passive rewards of 4.1% APY, or 4.5% for Coinbase One members. The lending expansion marks a push to increase earnings potential for holders of the asset, which has a circulating supply of more than $73 billion. Subheading updated 9/18/25 at 1:02 p.m. to correct a typo in yield percentage. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/coinbase-usdc-onchain
Condividi
BitcoinEthereumNews2025/09/19 01:13

Trading GOLD per 1,000,000 USDT

Trading GOLD per 1,000,000 USDTTrading GOLD per 1,000,000 USDT

0 commissioni, leva fino 1,000x, liquidità profonda