USENIX Security2025Top-tier venue
Let's Move2EVM
Lorenzo Benetollo, Andreas Lackner, Matteo Maffei, Markus Scherer
Abstract
The Move programming language, designed with strong safety guarantees such as linear resource semantics and borrow-checking, has emerged as a secure and reliable choice for writing smart contracts. However, these guarantees depend on the assumption that all interacting contracts are well-formed—a condition naturally met in Move's native execution environment but not in heterogeneous or untrusted platforms like the Ethereum Virtual Machine (EVM). This hinders the usage of Move as a source language for such platforms: for instance, we show in this paper that the existing Move-to-EVM compiler is not secure, meaning the compilation of secure Move contracts yields vulnerable EVM bytecode. This work addresses the challenge of preserving Move's security guarantees when compiling to EVM. We introduce a novel compiler design extending the existing Move-to-EVM compiler with an Inlined-Reference-Monitor-(IRM)-based protection layer. Our approach enforces Move's linear semantics and borrow-checking rules at runtime in EVM, ensuring the correctness and safety of the compiled smart contracts, even in adversarial execution environments. We formally define the compilation process, establish correctness guarantees for the translation, and implement our protection mechanism in the original compiler. Our evaluation draws on three datasets: (i) an ERC-20 implementation in Solidity and Move, (ii) the Rosetta dataset curated by Bartoletti et al., and (iii) modules scraped from the Aptos blockchain. The performance evaluation shows that the gas cost overhead introduced by our compiler—compared both to the original compiler and Solidity-compiled code—is modest, thereby confirming our approach as a practical solution for bringing the security guarantees of Move code to the EVM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on3
- How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injectionAsem Ghaleb, Karthik PattabiramanISSTA 2020 · 183 citations
- EVMPatch: Timely and Automated Patching of Ethereum Smart ContractsMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviUSENIX Security 2021 · 103 citations
- SGUARD: Towards Fixing Vulnerable Smart Contracts AutomaticallyTai D. Nguyen, Long H. Pham, Jun SunS&P 2021 · 69 citations
Related papers
- Tracking Borrows with Regular ExpressionsTodd Nowacki, Sam Blackshear, John Mitchell, Shaz Qadeer et al.OOPSLA 2026
- Belobog: Move Language Fuzzing Framework for Real-World Smart ContractsZiqiao Kong, Wanxu Xia, Zhengwei Li, Yi Lu et al.ISSTA 2026
- Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced AnalysisShuwei Song, Jiachi Chen, Ting Chen, Xiapu Luo et al.ISSTA 2024 · 4 citations
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
- DiSCo: Towards Decompiling EVM Bytecode to Source Code using Large Language ModelsXing Su, Hanzhong Liang, Hao Wu, Ben Niu et al.FSE 2025 · 2 citations
