Skip to content
Private, independent platform.Private, independent platform: free for clients, funded by a commission paid by vendors.Funding
smart-contract.com

Directory by blockchain

Aptos smart contract audit and development

Building and auditing on Aptos: Move modules, resources and signers, the object model, upgrade policies, key risk areas and how to prepare.

Aptos is a layer 1 blockchain that runs smart contracts written in Move and executes transactions in parallel. Move was designed to represent assets as resources that cannot be copied or lost by accident. For a project, building on Aptos means benefiting from these language guarantees, while still needing a careful review of permissions and business logic.

Building on Aptos

Code is organized in modules published under an account. State is stored as resources in global storage under accounts or in objects, and access is governed by the signer of the transaction and by capabilities the module chooses to issue. Modules can be upgraded according to a policy declared at publication, from compatible upgrades to immutable code. The Move Prover can be used to formally specify and check properties of a module.

  • Language: Aptos Move
  • Tooling: the Aptos command-line interface, Move unit tests, the Move Prover
  • Standards: the fungible asset and digital asset frameworks
  • Not EVM-compatible

What auditors look at

  • Signer and permission checks: functions that act on a resource without verifying who is allowed to
  • Capabilities and signer capabilities stored in resources, and who can retrieve them
  • Resource and object ownership, including transfers and the ability to delete or extract assets
  • Entry and public functions that can be combined by an attacker in unexpected orders
  • Arithmetic, rounding and the module upgrade policy

Before requesting quotes

  • Describe every resource and object type and the account or object that holds it
  • List privileged roles, the capabilities that implement them and who holds them after deployment
  • Share unit tests, and any Move Prover specifications you have written
  • State whether the code will be upgradeable and under which policy

Aptos smart contract auditors

  • Adevar Labs

    Public informationUnited States

    Blockchain security firm offering audits, fuzzing, formal verification and penetration testing

    • Audit
    • Penetration testing

    Solana · Ethereum · Sui · Aptos · BNB Chain

  • ChainSecurity

    Public informationSwitzerland

    Zurich smart contract audit firm reviewing DeFi, stablecoin, bridge and L1/L2 code

    • Audit

    Ethereum · Solana · Starknet · Sui · Aptos

  • Cyfrin

    Public information

    Smart contract audits, penetration testing and security education, maker of Aderyn and Solodit

    • Audit
    • Penetration testing

    Ethereum · ZKsync · Arbitrum · Avalanche · BNB Chain · +8 more

  • FuzzingLabs

    Public informationFrance

    French offensive security company auditing blockchains and smart contracts with fuzzing

    • Audit

    Solana · Ethereum · NEAR · Starknet · Sui · +3 more

  • Hexens

    Public informationUnited Kingdom

    Offensive security firm auditing smart contracts, L1/L2 protocols, ZK and cryptography

    • Audit
    • Penetration testing

    Ethereum · Polygon · ZKsync · Aptos

  • MoveBit

    Public information

    Security team dedicated to the Move ecosystem, auditing contracts, dApps and blockchains

    • Audit

    Sui · Aptos · Polygon

  • Oak Security

    Public informationGermany

    Munich-based Web3 security firm auditing EVM, Solana, Cosmos, Substrate and Starknet code

    • Audit
    • Penetration testing

    Ethereum · Solana · Cosmos · Polkadot · Starknet · +2 more

  • OtterSec

    Public information

    Blockchain security firm auditing layer 1s, wallets, DeFi and bridges, with pentesting and fuzzing

    • Audit
    • Penetration testing

    Solana · Ethereum · Sui · Aptos · Cosmos · +1 more

  • QuillAudits

    Public information

    Smart contract audit firm also offering dApp penetration testing, wallet audits and monitoring

    • Audit
    • Penetration testing

    Ethereum · NEAR · BNB Chain · Polygon · Optimism · +8 more

  • Rather Labs

    Public informationUnited States

    Web3 and AI engineering firm with a Buenos Aires team, building and auditing smart contracts

    • Development
    • Audit

    Ethereum · Arbitrum · Base · Optimism · Polygon · +5 more

  • softstack

    Public informationGermany

    Flensburg Web3 company offering smart contract audits, pentests, development and compliance

    • Development
    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more

  • Three Sigma

    Public information

    Code security audits and economic audits for Web3 protocols, in Solidity, Rust and Move

    • Audit

    Ethereum · Arbitrum · Polygon · Base · Optimism · +4 more

  • Trail of Bits

    Public informationUnited States

    Security firm reviewing smart contracts, nodes and bridges, maker of Slither and Echidna

    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Solana · Sui · +4 more

  • Verichains

    Public informationVietnam

    Security firm auditing smart contracts, protocols and cryptography, with penetration testing

    • Audit
    • Penetration testing

    Ethereum · BNB Chain · Solana · Avalanche · Polygon · +1 more

  • Zellic

    Public information

    Security assessments of smart contracts, ZK circuits, L1s and web applications

    • Audit
    • Penetration testing

    Ethereum · Solana · Aptos · Sui · Cosmos

  • Zokyo

    Public informationUnited Arab Emirates

    Smart contract and protocol audits, pentesting, compliance and product development, Dubai

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more

Aptos smart contract developers

  • Rather Labs

    Public informationUnited States

    Web3 and AI engineering firm with a Buenos Aires team, building and auditing smart contracts

    • Development
    • Audit

    Ethereum · Arbitrum · Base · Optimism · Polygon · +5 more

  • softstack

    Public informationGermany

    Flensburg Web3 company offering smart contract audits, pentests, development and compliance

    • Development
    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more

  • Zokyo

    Public informationUnited Arab Emirates

    Smart contract and protocol audits, pentesting, compliance and product development, Dubai

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more

Describe your project once. Compare with confidence.

Get comparable quotes from vetted developers, then secure your code with an independent auditor.

Get quotes

Free for clients. No commitment.