Mysten Labs Improves DevEx with Endor Labs
Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier.
Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can safely and reliably handle sensitive assets.
Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier.
Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can safely and reliably handle sensitive assets.
Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier.
Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can safely and reliably handle sensitive assets.

- Block risks from entering production
- Faster remediation earlier in the SDLC
- Greater developer trust and engagement
“Software analysis is hard, and there's only one company [Endor Labs] that's doing it correctly.”
Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier.
Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can safely and reliably handle sensitive assets.
Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier.
Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can safely and reliably handle sensitive assets.

Developer experience is critically important to the success of Mysten Labs’ products, and the product security program’s success is directly tied to making Mysten products secure without making developers miserable. To achieve this outcome, Mysten seeks to make the “secure way” synonymous with the “easy way.” After all, when security processes or tools are difficult or burdensome, engineers will inevitably find workarounds, undermining the security goals.
Unfortunately, Mysten Labs realized the incumbent AppSec tool, used for SCA, SAST, and secret detection, wasn’t helping achieve that outcome. Areas of concern included:
- Inability to trust findings: The tool had a high false positive rate and couldn’t reliably determine whether code was being used in production. For example, it flagged vulnerabilities in outdated dependencies or test binaries that were not actually built or shipped in the production application.
- Lack of actionable data: Engineers need contextualized findings to prioritize remediation (such as knowing if a vulnerability is reachable) but technical limitations prevented the tool from providing this level of detail. It also didn’t support reachability analysis for transitive dependencies, which is problematic since that’s where the majority of vulnerabilities are discovered.
Noise, inaccuracy, and technical limitations led to excessive manual work and made it challenging to integrate security checks into the developer workflow without causing significant friction and slowdowns, directly hindering the desired developer experience.
The security and engineering teams wanted a tool that could help them reduce risk without slowing down development. They identified three requirements for the new platform.
Requirement 1: High accuracy and reliable technical analysis
The platform needed to provide accurate, high-confidence, and reliable data, including non-subjective findings. It was critical that the tool understood teams' applications, rather than making assumptions based on code parsing alone. It had to accurately handle complex build systems and dependencies (like the distinction between test and production dependencies in Rust) and detect valid secrets before they ship.
Requirement 2: Minimal friction and enhanced developer experience
The platform had to significantly reduce excessive noise and false positives, which required a tremendous amount of extra work to refine. The aim was to minimize manual effort and provide usability data (like contextualized and reachable findings) that helped engineers effectively understand and address issues.
Requirement 3: Speed and usability for CI/CD integration
A crucial requirement was the ability to integrate security checks into the CI/CD pipeline without causing significant delays. The scans (particularly for critical issues like malware, secrets, or severe vulnerabilities) needed to be fast enough to avoid blocking developer merges. This speed was essential for the tool to be truly usable for implementing blocking strategies.
“Software analysis is hard, and there's only one company [Endor Labs] that's doing it correctly.”
— Paul Padilla, Head of Software and Infrastructure Security at Mysten Labs
Within weeks of deployment, Endor Labs helped Mysten Labs transform its application security strategy.
Developer buy-In
Engineers embraced the tool thanks to lower friction, better results, and a smoother experience. They trust the tool to surface just the vulnerabilities that can be exploited, and scans run quickly to prevent code merging delays.
Faster remediation
Due to its reliability and accuracy, Endor Labs is used to block builds for critical issues like malware, leaked secrets, and select vulnerabilities. The team now focuses on fixing just the risks that matter before the code ships.
Enhanced software supply chain security
Endor Labs helps achieve their fundamental security goal of knowing what's inside a shipped product. The team understands which dependencies are in use, and can reliably identify underused dependencies as part of their strategy to reduce technical debt and supply chain risk.
Looking Ahead
As Mysten Labs continues its goal to build and maintain the most secure blockchain in the world, it sees AI playing an increasingly important role in its security program. Participation in the Endor Labs design partner program puts the team on the forefront of AI development, where they get to test new features and engage directly with people building the product.
“Though our team is talented, building a feature like AI Security Code Review would be a lot of effort. We’re excited that Endor Labs is taking the lead in this space, and it will be a big benefit to wrap this functionality into a product we already use.”
— Paul Padilla, Head of Software and Infrastructure Security at Mysten Labs