By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
18px_cookie
e-remove

Mysten Labs Improves DevEx with Endor Labs

Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier. 

Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can  safely and reliably handle sensitive assets. 

Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier. 

Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can  safely and reliably handle sensitive assets. 

Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier. 

Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can  safely and reliably handle sensitive assets. 

Written by
A photo of Jenn Gile — Director of Product Marketing at Endor Labs.
Jenn Gile
Published on
June 17, 2025

Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier. 

Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can  safely and reliably handle sensitive assets. 

Founded in 2021, Mysten Labs is a research and deployment lab forging the path to uplift and advance a better internet. As the original contributors to the Sui Layer 1 blockchain, Mysten Labs is a pioneer of decentralized technology, redefining the capabilities of blockchain via Move, the programming language created by Mysten Labs CTO Sam Blackshear. Mysten Labs also designs open source products that make building on and interacting with Sui easier. 

Mysten Labs aims to make web3 secure, reliable, and ready for mass adoption. User and investor faith is paramount, so Mysten products, like crypto wallets and smart contracts, must demonstrate that they can  safely and reliably handle sensitive assets. 

The Challenge

Developer experience is critically important to the success of Mysten Labs’ products, and the product security program’s success is directly tied to making Mysten products secure without making developers miserable. To achieve this outcome, Mysten seeks to make the “secure way” synonymous with the “easy way.” After all, when security processes or tools are difficult or burdensome, engineers will inevitably find workarounds, undermining the security goals.

Unfortunately, Mysten Labs realized the incumbent AppSec tool, used for SCA, SAST, and secret detection, wasn’t helping achieve that outcome. Areas of concern included:

  • Inability to trust findings: The tool had a high false positive rate and couldn’t reliably determine whether code was being used in production. For example, it flagged vulnerabilities in outdated dependencies or test binaries that were not actually built or shipped in the production application. 
  • Lack of actionable data: Engineers need contextualized findings to prioritize remediation (such as knowing if a vulnerability is reachable) but technical limitations prevented the tool from providing this level of detail. It also didn’t support reachability analysis for transitive dependencies, which is problematic since that’s where the majority of vulnerabilities are discovered.

Noise, inaccuracy, and technical limitations led to excessive manual work and made it challenging to integrate security checks into the developer workflow without causing significant friction and slowdowns, directly hindering the desired developer experience.

The Solution

The security and engineering teams wanted a tool that could help them reduce risk without slowing down development. They identified three requirements for the new platform.

Requirement 1: High accuracy and reliable technical analysis

The platform needed to provide accurate, high-confidence, and reliable data, including non-subjective findings. It was critical that the tool understood teams' applications, rather than making assumptions based on code parsing alone. It had to accurately handle complex build systems and dependencies (like the distinction between test and production dependencies in Rust) and detect valid secrets before they ship.

Requirement 2: Minimal friction and enhanced developer experience

The platform had to significantly reduce excessive noise and false positives, which required a tremendous amount of extra work to refine. The aim was to minimize manual effort and provide usability data (like contextualized and reachable findings) that helped engineers effectively understand and address issues. 

Requirement 3: Speed and usability for CI/CD integration

A crucial requirement was the ability to integrate security checks into the CI/CD pipeline without causing significant delays. The scans (particularly for critical issues like malware, secrets, or severe vulnerabilities) needed to be fast enough to avoid blocking developer merges. This speed was essential for the tool to be truly usable for implementing blocking strategies.

The Impact

“Software analysis is hard, and there's only one company [Endor Labs] that's doing it correctly.”
— Paul Padilla, Head of Software and Infrastructure Security at Mysten Labs

Within weeks of deployment, Endor Labs helped Mysten Labs transform its application security strategy.

Developer buy-In

Engineers embraced the tool thanks to lower friction, better results, and a smoother experience. They trust the tool to surface just the vulnerabilities that can be exploited, and scans run quickly to prevent code merging delays.

Faster remediation

Due to its reliability and accuracy, Endor Labs is used to block builds for critical issues like malware, leaked secrets, and select vulnerabilities. The team now focuses on fixing just the risks that matter before the code ships. 

Enhanced software supply chain security

Endor Labs helps achieve their fundamental security goal of knowing what's inside a shipped product. The team understands which dependencies are in use, and can reliably identify underused dependencies as part of their strategy to reduce technical debt and supply chain risk.

Looking Ahead

As Mysten Labs continues its goal to build and maintain the most secure blockchain in the world, it sees AI playing an increasingly important role in its security program. Participation in the Endor Labs design partner program puts the team on the forefront of AI development, where they get to test new features and engage directly with people building the product. 

“Though our team is talented, building a feature like AI Security Code Review would be a lot of effort. We’re excited that Endor Labs is taking the lead in this space, and it will be a big benefit to wrap this functionality into a product we already use.”
— Paul Padilla, Head of Software and Infrastructure Security at Mysten Labs

Book a Demo

Book a Demo

Book a Demo

Welcome to the resistance
Oops! Something went wrong while submitting the form.

Book a Demo

Book a Demo

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Book a Demo