Asymptotically verifying all software infrastructure Audit & Formal Verification Partner of Sui Foundation

Attackers now run frontier models against deployed code. We built Asymptotic to converge faster than they do. Formal verification on 10+ Sui protocols: @Scallop_io @CetusProtocol @EmberProtocol @currentsui @bluefinapp @MMTFinance @navi_protocol, Sui Staking. cc @SuiDevelopers
6
12
41
7,786
Software assurance, including security, is hard to measure or brag about. You do a good job when nobody hears about it. These are the lending protocols on @SuiNetwork that we have formally verified: @Scallop_io @CurrentSUI @navi_protocol Beyond our technical results, we learned that they have solid teams who care about security.
3
13
36
2,455
Formal Verification reports here: Scallop: scallop.asymptotic.tech/lend… Current: current.asymptotic.tech/lend… NAVI: pending publication
1
3
212
Just read this post by the Sui security team, and fully agree. We've been applying these principles with our partners for a while now: 1. Rule out problems before production -- Move is great here; on the smart-contract layer, our partners' releases are gated by our FV+audit 2. Keep review evidence with the code -- package versions, code, and our FV+audit findings are connected as (package, commit, findings) triples 3. Keep watching after deployment -- both mainnet and github are continuously monitored; whenever the team changes code, our platform automatically updates the FV and surfaces any problems 4. Put attention where the consequences are greatest -- a lot can be done here; for now, our agentic FV+audit infra has deep work prioritization built-in; a run is not a yes/no binary, effort scales with the risk profile of the protocol Looking forward to more of this reporting moving on-chain (attestations) and surfaced in MVR
Audits matter, but they can't do it all. Security should be part of the platform: prevent problems before launch, verify what runs onchain, track changes, and focus response where value is most exposed. That’s what Sui is building toward. Learn more ↓ sui.io/blog/security-should-…
4
3
26
1,868
the full Current page, similar for our other partners current.asymptotic.tech/lend…
3
1,796
Asymptotic retweeted
Now latest Audit report and Formal Verification with @AsymptoticTech covering Current's latest oracle upgrade has been added and accessible to the public. Visit here: current.asymptotic.tech/lend…
2
12
41
2,117
The @CurrentSUI team is thorough when it comes to security. Before their upgrade, we made sure all the i’s were dotted and the t’s were crossed. Their on-chain code matches what we audited and formally verified. See our live report of the protocol here current.asymptotic.tech/lend…
Scheduled Maintenance Completed The scheduled maintenance has been successfully completed. The protocol upgrade to support the latest Pyth Oracle upgrade has been deployed as planned, and all post-upgrade checks have been completed. All Current functions are now fully operational, and normal protocol operations have resumed. User funds remained unaffected throughout the maintenance. Thank you for your patience and support.
2
2
15
1,950
Asymptotic retweeted
In March, Hashi was first introduced: a new way to put $BTC to work on Sui without moving it off the Bitcoin network. Today, Hashi testnet is live.
94
184
994
195,784
Comprehensive Formal Verification of the @CetusProtocol DLMM We formally verified the core protocol and the router strategies built on it: swaps, positions, the math kernel, and the bin grid itself. Together with the CLMM verification we published in March, both of Cetus's AMMs are now comprehensively formally verified. @suidevelopers, check it out!
2
2
32
12,760
Some of what we proved (the report has the full picture): → Swap conservation: each flash-swap repay credits exactly the receipt's pay amount to the input-side reserve, and every other pool field is proven byte-identical to its pre-call value → Math kernel: swap-amount conversion, liquidity↔amount, fees, and growth accumulators proven against exact integer formulas, down to the floor/ceil rounding direction of each step → Volatility fees: the three-regime time-decay of the volatility references and the quadratic variable-fee formula proven with explicit overflow guards → Access control: seven ACL roles partition the admin surface; covered entry points proven to abort unless the caller holds the role bit and the protocol version is current
1
3
123
Building mathematically-proven secure foundations for @SuiNetwork
2
74
great to see the Sui Move Prover help keep 💧 protocols secure
we ran Sui Move Prover against 1,726 lines of Move across 25 structs and 62 functions.
2
2
24
1,494
Comprehensive Formal Verification of the @bluefinapp CLMM on @SuiNetwork (heads up, @suidevelopers) We machine-checked the core mechanisms behind Bluefin's concentrated-liquidity AMM (pools, positions, and swaps, down to the math that swap solvency rests on) and proved they behave as specified. This is part of our ongoing security partnership with Bluefin.
8
3
45
3,234
Some of what we proved (the report has the full picture): → Swap solvency: the single-step swap kernel never pays out more value than it takes in, over any valid price range; liquidity conversion rounds in the solvent direction and round-trips without overcrediting a depositor. → Tick state: tick updates and crossings preserve the signed net-liquidity invariant, keeping active liquidity exact as the price moves across ticks. → Position accounting: fees and rewards are recomputed with wrapping fee-growth deltas, refreshed in lockstep with every liquidity change. → Flash swaps: receipt-pattern settlement is proven end to end; the pool pauses until repaid, then credits exactly the receipt amount on the correct side. → TWAP oracle: the circular observation buffer preserves its cardinality, index wrap-around, and cumulative-value invariants. → Admin: every capability-gated admin operation requires a synchronized config version and leaves unrelated state untouched.
1
3
173
Tick math is where automated proving usually stops: the price↔tick conversions approximate a real-valued curve, √(1.0001^tick), with a per-bit table of magic constants that automated solvers have to reason through symbolically and time out on. We proved them in Lean 4, exhaustively checking all 887,273 valid ticks. get_tick_at_sqrt_price returns the correct floor tick for any price, the conversions are monotonic, and the tick→price→tick round-trip recovers the original tick. These reports are snapshots. We keep the specs and proofs in sync with the protocol as it ships new code, as part of our partnership.
2
104
Asymptotic retweeted
Sui public mainnet just reached a peak of 6M+ TPS. Watch the livestream to see.👇
127
463
1,391
285,077
→ @bluefinapp has been amazing as a security partner. We've been working together to create the processes and on-chain governance that ensure every package upgrade passes multiple security checks, including formal verification, before it ships. The team is extremely thoughtful about security on all levels: from formal verification to supply-chain defense to human processes.
Security has been a first-class citizen for both Bluefin and Suilend. Suilend was among the first lending protocols to build withdrawal rate limits directly into the protocol at inception, a standard we independently developed across Bluefin's own infrastructure. Their contracts have been audited by @osec_io, one of our long-standing audit partners, and formally verified by @Certora. That foundation is strong and complements our own posture. We've spent years thinking through and refining our risk models, including liquidation engines, isolated markets, oracle integrity, and black swan event behavior, all of which we'll be leveraging to refine how risk is handled here. It will also draw on our real-time security partners, OtterSec and @AsymptoticTech, which we'll use for all enhancements and to include their verification attestations for contract upgrades. The same engineering standards we hold at Bluefin will apply across both platforms: defense in depth from the contract layer through operations, institutional multisig custody, timelocked upgrades gated by audit-partner co-signers and a guardian pause, withdrawal limits sized to the real worst-case outflow, among the broader set of controls that make up our security standard.
1
4
25
1,167
We're looking forward to seeing everyone in person again! 👯
Sui Basecamp is back. October 7-8. Marina Bay Sands, Singapore 🇸🇬 with @token2049. The next $5 trillion in transactions won’t be human. The agentic future will be built on Sui. Build with us.
2
17
818