★ Watchlist 0
MOVEMENT NETWORK · L1 · STAGE 0 UNAWARE · QRI 18 v3.2.2 methodology
In plain terms

What it is. Movement is a public network that spent its first year as an add-on to Ethereum and now settles its own transactions on software copied from another chain.

What we found. Movement has published nothing about protecting itself from quantum computers, and after the company that originally built the chain filed for bankruptcy in July 2026 there is nobody publicly assigned to start.

Why it matters. Anyone who has ever sent a transaction from a Movement account has already exposed what a future quantum computer would need to forge their signature, and this chain has nothing safer to move the coins into.

Movement M1 mainnet authenticates accounts with Ed25519 (RFC 8032) and aggregates consensus votes under BLS12-381 in the minimal-pubkey-size variant with proof-of-possession, which contradicts Movement's own published M1 protocol specification: that document names Ed25519, Multi-Ed25519 and SHA-3 (Keccak) only and attributes consensus vote authentication to Ed25519, while the on-chain validator set returns a 48-byte G1 consensus public key for each of the four active validators. No post-quantum primitive runs on Movement mainnet and none exists in its consensus client: the SLH-DSA-SHA2-128s (FIPS 205) feature flag that upstream aptos-core defines under AIP-137, a proposal at status Accepted and not activated on Aptos mainnet, is not defined in Movement's fork at all and its bit position is clear in Movement mainnet's on-chain feature bitvector, so Gate 1a-Sig and Gate 1a-KEM both fail and the mainnet-traffic cap binds at 0% post-quantum signing traffic.

inLinkedIn ↷Audit access ⇆Compare Last reviewed 2026-08-20

Summary

Movement Network scores QRI 18, Band 2, Migration Stage 0 (Unaware), on a sovereign Move-VM Layer 1 forked from Aptos Core. Mainnet primitives: Ed25519 (RFC 8032) and Multi-Ed25519 for account authentication, secp256k1 and secp256r1 ECDSA as single-key authenticator variants, BLS12-381 minimal-pubkey-size with proof-of-possession for consensus vote aggregation and for the randomness PVSS and VUF, Groth16 over BN254 on the keyless-account path (present on mainnet, inert, zero OIDC providers configured), X25519 with AES-256-GCM under Noise_IK_25519_AESGCM_SHA256 at validator and fullnode transport, and SHA3-256 for authentication keys and Jellyfish Merkle Tree commitments. Every asymmetric primitive breaks under Shor; the symmetric and hash primitives weaken under Grover. A code search of Movement’s fork for the upstream post-quantum scheme returns zero results and the fork does not define its feature flag despite enumerating flags past 220, so the absence is Movement’s own rather than a stale fork. Native authentication-key rotation is live at the framework level with no post-quantum scheme to rotate into. Four validators hold roughly equal voting power and advertise endpoints in one cloud region, so consensus public keys are epoch-public and the Nakamoto coefficient is 2. The ledger runs continuously from 2024-12-05. MVMT Labs, Inc. filed Chapter 11 on 2026-07-15.

Dominant quantum risk

Forge. Forge-dominant: this chain secures value and consensus with signatures, so the principal quantum risk is forgery of spends and of validator attestations once Shor breaks the underlying groups. Two distinct forge surfaces exist here. Account spends rest on Ed25519, forgeable once the account's public key is revealed, which happens at first transaction. Consensus rests on aggregated BLS12-381, and every validator public key is epoch-public on-chain by design, so that surface needs no harvesting step at all. Decrypt and harvest-now-decrypt-later applies only to transport confidentiality, where the Noise IK handshake over X25519 means a stored transcript yields endpoint identities as well as payload.

Forge subtotal 18 / Decrypt subtotal 6
Announced → Shipped

0 announced → 0 shipped on mainnet under a named primitive. none, no inflation.

LayerQu scores deployment, not announcements. Announcements score zero.

What the gates say

  • Gate 1a, Hybrid signature: FAIL , no documented hybrid signature composition AND or OR; no Movement-specific PQ signature is deployed; the SLH-DSA-SHA2-128s feature flag defined upstream in Aptos is absent from Movement's fork and its flag position is clear in Movement mainnet's on-chain feature bitvector; AIP-137 inheritance is undeclared
  • Gate 1a, Hybrid KEM: FAIL , no hybrid KEM composition at validator transport or RPC TLS; validator and fullnode transport is Noise_IK_25519_AESGCM_SHA256, an X25519 static-key Diffie-Hellman handshake with AES-256-GCM and SHA-256, classical only; partner RPC endpoints terminate standard TLS with no hybrid key exchange documented
  • Gate 1b, Commit-to-hash: COND , Gate 1a-Sig failed; OR-composition commit-to-hash not in scope
  • Gate 2, Evidence reconstruction: PASS , every sub-score reconstructible from public artifacts: Movement's published protocol specification, live mainnet REST queries against the on-chain validator set, feature bitvector, account module ABI and framework resources, the public consensus-client fork and its release tags, the upstream Aptos improvement proposal and its source tree, and dated press coverage
  • Gate 3, Primitive naming: PASS , Ed25519 per RFC 8032, Multi-Ed25519, BLS12-381 minimal-pubkey-size with proof-of-possession, Groth16 over BN254, X25519, AES-256-GCM, SHA-256, SHA3-256 (Keccak), and the absent SLH-DSA-SHA2-128s per FIPS 205, each named with mechanism and deployment status

Burn-vs-rescue policy on file

Declared option f, Undeclared. No published Foundation policy on dormant-account or lost-key handling under quantum threat. No analogue mechanism (Hourglass-style rate-limit, freeze proposal, optional-migration window) has been scoped publicly.

Seven dimensions

Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.

1 Cryptographic Exposure weight 15% 18 / 100
1a · primitive inventory 8 / 20

Movement's published M1 protocol specification names three primitives and attributes consensus vote authentication to Ed25519. The running chain returns 48-byte BLS12-381 G1 consensus public keys, so the published inventory is both incomplete and wrong at one named point. Partial credit reflects that specific algorithms are named at all with usage attached; the deduction reflects a documented inventory that a reader cannot rely on for the consensus signature path.

Primitives: Ed25519 per RFC 8032, transaction authentication, account authentication keys, P2P message authentication · Multi-Ed25519, threshold and multi-signature scheme, framework module live on mainnet · BLS12-381 minimal-pubkey-size with proof-of-possession, validator consensus vote signatures and multisignature aggregation, 48-byte G1 public keys observed for all four active validators on mainnet · BLS12-381 weighted publicly-verifiable secret sharing and verifiable unpredictable function, on-chain randomness, randomness configuration active on mainnet · Groth16 over BN254, keyless-account verification key present on mainnet and currently inert, zero OIDC providers configured and zero observed JSON Web Key entries · secp256k1 ECDSA and secp256r1 ECDSA, available as single-key authenticator variants, framework module live on mainnet · X25519 with AES-256-GCM and SHA-256 under Noise_IK_25519_AESGCM_SHA256, validator and fullnode transport encryption and authentication · SHA3-256 (Keccak), authentication-key derivation, block hashing and Jellyfish Merkle Tree commitments
1b · shor grover pq tag 4 / 20

The classification above is LayerQu's. Movement publishes no per-primitive Shor or Grover classification and no post-quantum tagging of any kind, which is what the score reflects.

Tags:
  • Ed25519 → Shor-break-via-DL-without-pairings
  • Multi-Ed25519 → Shor-break-via-DL-without-pairings (composition of Ed25519)
  • BLS12-381 consensus signatures → Shor-break-via-pairings
  • BLS12-381 randomness PVSS and VUF → Shor-break-via-pairings
  • Groth16 over BN254 (keyless) → Shor-break-via-pairings
  • secp256k1 ECDSA and secp256r1 ECDSA → Shor-break-via-DL-without-pairings
  • X25519 (transport key exchange) → Shor-break-via-DL-without-pairings
  • AES-256-GCM (transport) → Grover-weaken (256 to 128 bit key search post-Grover)
  • SHA-256 (transport hash) → Grover-weaken
  • SHA3-256 / Keccak → Grover-weaken (256 to 128 bit collision and preimage post-Grover)
1c · family diversity 0 / 20

0 post-quantum families. The deployed surface is entirely classical: discrete-log signatures (Ed25519, Multi-Ed25519, secp256k1 and secp256r1 ECDSA), pairing-based constructions (BLS12-381, Groth16 over BN254), Diffie-Hellman key exchange (X25519), and Grover-weakened symmetric and hash primitives (AES-256-GCM, SHA-256, SHA3-256). No lattice, hash-based, code-based or isogeny family is deployed.

1d · nist security category 0 / 20

No NIST PQC primitives deployed, so no NIST security category 1 to 5 mapping exists for this chain. The active surface contains only classical primitives: Ed25519 at roughly 128-bit classical security, BLS12-381 at roughly 128-bit classical security, BN254 below that after the extended tower number field sieve results, and SHA3-256 at roughly 128-bit post-Grover collision resistance.

1e · implementation quality 6 / 20

The consensus client is a fork of Aptos Core and inherits Aptos's Move Prover formal-verification tooling for Move smart contracts. Library provenance is inherited Rust crates: the BLS12-381 module wraps the blst library and its own documentation warns that non-aggregated verification requires public keys to be wrapped in a validating type to prevent small-subgroup attacks, a caveat that transfers to Movement unexamined. No published audit specifically of Movement-divergent cryptographic code was found. The public mainnet RPC fullnode advertises a build from a fork commit dated 2026-04-27 while the fork's branch head carries later commits, so deployed build currency lags the source tree. Cryptanalytic-maturity tiers: Ed25519 and SHA-2 tier 1, SHA-3 and Keccak tier 2, BLS12-381 and BN254 pairing-based and classically mature but pairing-exposed under Shor.

2 Quantum Recovery Exposure weight 10% 24 / 100
Forge subtotal: 18/75 Decrypt subtotal: 6/25
2a · active key exposure 6 / 25

Accounts authenticate with Ed25519 under the Aptos-derived model, in which the authentication key is a SHA3-256 commitment to the public key and the public key itself is revealed with the first transaction the account signs. Validator consensus public keys need no such trigger: all four BLS12-381 G1 keys are readable from the on-chain validator-set resource right now. MOVE traded at roughly 0.0062 USD on 2026-08-19, having set an all-time low of roughly 0.0058 USD the same day, which lowers dollar value at risk without changing the fraction of accounts with revealed public keys.

2b · cold key exposure 8 / 25

The mainnet ledger is continuous from its first block, timestamped 2024-12-05, giving roughly 20 months of accumulated account history at evaluation rather than the shorter horizon implied by the 2025 sovereign-L1 cutover. Any account that has ever transacted has a revealed Ed25519 public key and stays Forge-exposed indefinitely unless its authentication key is rotated to a post-quantum scheme, which no such scheme exists on this chain to rotate into. LayerQu has not measured the share of dormant or abandoned accounts on this chain and makes no claim about it.

2c · sig long term validity 4 / 25

All historical Ed25519 account signatures and all historical BLS12-381 consensus signatures across the full ledger are forgeable once Shor is available, the latter meaning that historical quorum certificates can be re-forged as well as individual spends. No published signature-scheme transition plan, no archival re-anchoring, and no hash-based commitment to long-term-valid history.

2d · encryption confidentiality hndl 6 / 25

Validator and fullnode transport uses Noise_IK_25519_AESGCM_SHA256, a stripped-down Noise IK handshake over X25519 with AES-256-GCM and SHA-256, per the consensus client's own transport module. The handshake pattern is IK, not NK: the initiator knows the responder's static X25519 key in advance and transmits its own static key encrypted, so a harvested transcript yields both endpoint identities and the session payload to a future Shor attacker. Movement's primary mainnet RPC endpoint and its five documented partner endpoints (Sentio, Hello Moon, BlockPi, Lava, Ankr) terminate standard TLS with no hybrid post-quantum key exchange documented at any of them. NodeOps does not appear in Movement's endpoint documentation.

3 Metadata, Anonymity & Confidentiality weight 13% 24 / 100
3a · tx graph visibility 5 / 20

Movement is a transparent ledger; the Move account model and Move-VM execution traces are publicly observable through the public REST endpoint and the block explorer. No native shielding and no zk-account scheme. The keyless-account module, which would introduce an OIDC-derived identity path, is present on mainnet but inert with zero configured providers.

3b · rpc mempool concentration 5 / 20

Five documented partner RPC endpoints (Sentio, Hello Moon, BlockPi, Lava, Ankr) plus Movement's primary endpoint; NodeOps is not on the documented list. No RPC traffic-share telemetry is published, so partner concentration is not measurable. Mempool propagation is measurably concentrated for a different reason: all four active validators advertise both their validator and their fullnode network addresses as load-balancer hostnames in a single cloud provider's us-east-1 region, so transaction propagation among validators traverses one operator's network. Validator metadata-retention policy is undeclared.

3c · cross chain bridge correlation 6 / 20

Movement integrates LayerZero, whose developer tooling is maintained as a public fork under the Movement organization, and the framework carries a native atomic-bridge configuration resource on mainnet. Bridge transactions between Ethereum L1 and Movement create observable source and destination address pairs. No mixing and no bridge-level privacy primitive is deployed.

3d · retroactive de anonymization 8 / 20

Movement does not deploy on-chain encryption at the protocol level: no ElGamal note ciphertexts in use, no discrete-log ring signatures, no zk-SNARK shielded pool. The framework does carry inherited ElGamal and Bulletproofs modules from upstream Aptos, but no shielded-asset path is configured on mainnet. Post-Shor, the marginal retroactive privacy loss beyond what is already public from a transparent ledger is small.

3e · mixnet shuffle 0 / 20

No mixnet, no on-chain commit-reveal mixing, no cryptographic shuffle, no information-theoretically secure cMix-class mixing.

4 Migration Architecture weight 10% 45 / 100
4a · crypto agility 6 / 15

The Aptos-derived account module deployed on Movement mainnet exposes rotate_authentication_key, rotate_authentication_key_call, rotate_authentication_key_from_public_key and rotate_authentication_key_with_rotation_capability, with the matching rotation-proof-challenge structures, so the signature scheme bound to an account can change without changing the address. Movement has no published production instance of rotating an account to a new signature family, and no post-quantum family exists on this chain to rotate into. Inherited capability, no deployed precedent.

4b · aa key rotation 15 / 20

Native authentication-key rotation is deployed and live at the framework level on mainnet, confirmed against the account module's on-chain ABI, which is account-model-abstraction equivalent and scores 15 under the rubric's account-model band for rotation without a documented client-layer post-quantum path. Movement's standard accounts commit to an RFC 8032 Ed25519 seed-derived key, so the scheme seed floor of 6 also applies but is subsumed by the higher account-model component, combined by maximum rather than sum. The post-quantum rebind bonus is 0: there is no chain-specific rebind design, no post-quantum-sound prover, and no path to freeze acceptance of raw Ed25519 signatures. No Movement-specific client-layer PQC path is documented.

4c · hard fork track record 5 / 15

Movement executed an L2-to-L1 architectural pivot on an existing ledger, announcement-dated to 2025-12-22, with no new genesis. Coordinated-upgrade history since then is real but thin: four tagged sovereign-L1 full-node releases shipped between 2026-03-18 and 2026-05-29, and the consensus-client fork has carried commits continuously through 2026-08-19, including through the Chapter 11 period. Against that, the public mainnet RPC fullnode still advertises a build from 2026-04-27, so shipping a release and having the network run it are visibly different things here, and no upgrade in this period has been documented as a coordinated network-wide hard fork. Concurrent governance turbulence, including the May 2025 leadership terminations and the Foundation-to-Move-Industries operational transfer, further limits what the coordination record demonstrates.

4d · hybrid deployment readiness 4 / 15

Architecturally possible through the authentication-key abstraction and the single-key authenticator, which already carries multiple public-key variants and could in principle carry another. Movement has not announced or scoped a hybrid post-quantum deployment. Upstream, aptos-core has merged SLH-DSA-SHA2-128s (FIPS 205) implementation code under AIP-137 and defines its feature flag in the Rust-side default feature set, but the proposal remains at status Accepted, the flag position is clear in Aptos mainnet's own on-chain feature bitvector, and none of that code or that flag exists in Movement's fork. Announced-not-shipped upstream, absent downstream; architectural-possibility credit only.

4e · stateful hash state management 15 / 15

Not applicable, no stateful hash-based scheme (XMSS per RFC 8391, LMS per RFC 8554, leanXMSS) is deployed, so no state-management or one-time-key-reuse risk exists. Default 15.

4f · bft aggregation path 0 / 20

In scope and scored 0. Movement M1 runs a Jolteon-style BFT consensus whose quorum certificates aggregate BLS12-381 signatures: every active validator's consensus public key is a 48-byte G1 element in the minimal-pubkey-size variant with proof-of-possession, read directly from the on-chain validator set. This is a BLS-aggregating BFT chain with epoch-public validator keys and zero declared post-quantum aggregation path, which the rubric flags as consensus-layer-exposed regardless of finality speed. No merged specification, no research statement, and no acknowledgement that the aggregation path needs replacing. This sub-score is in scope for Dim 4: the chain state shows consensus votes are not Ed25519-only.

5 Deployment Execution weight 22% 15 / 100
5a · mainnet pqc traffic pct 0 / 25

0% of Movement M1 mainnet signing traffic is on post-quantum primitives. Account signatures are Ed25519 and consensus vote signatures are BLS12-381. SLH-DSA-SHA2-128s, the post-quantum signature scheme carried in the upstream Aptos tree, has its feature-flag position clear in Movement mainnet's on-chain feature bitvector and is not defined in Movement's fork at all, so no post-quantum authenticator can be submitted.

5b · pqc code in consensus client 0 / 15

No post-quantum code in the Movement consensus client. A code search for the SLH-DSA scheme across Movement's active fork returns zero results, and the fork's feature-flag enumeration does not define the flag despite enumerating flags well past the upstream number, so this is an absence in Movement's own tree rather than a stale fork. Upstream aptos-core carries the implementation, is not activated on Aptos mainnet, and earns Movement no credit.

5c · validator pqc key adoption 0 / 15

0% of validators run post-quantum keys. All four active validators present 48-byte BLS12-381 G1 consensus public keys, and their owner and operator accounts authenticate with Ed25519. No post-quantum key type exists in the client to adopt.

5d · published dated milestones 0 / 10

Voided per the rule that milestone discipline requires non-zero mainnet post-quantum traffic (5a = 0). Independently, no published dated PQC migration milestones exist from the Movement Network Foundation or Move Industries, and Movement's own improvement-proposal repository contains 13 numbered proposals with no post-quantum entry.

5e · pqc washing delta 15 / 15

Trailing-12-month post-quantum announcements from Movement: 0. Trailing-12-month shipped post-quantum capability: 0. Nothing has been claimed that was not delivered, so no washing tag fires. This sub-score credits the absence of inflation, not the presence of progress.

5f · signature footprint multiplier 0 / 20

Undisclosed. No post-quantum scheme is deployed and Movement publishes no sizing or gas analysis for one. Per the scoring table, undisclosed scores 0. For reference, the upstream proposal Movement has not adopted would carry a 7,856-byte signature with a 32-byte public key against Ed25519's 64 and 32 bytes.

6 Supply Chain Vendor Readiness weight 22% 5 / 100
6a · wallet 1 / 25

Wallets named in Movement's current documentation: Motion, described there as the official self-custodial wallet built by Move Industries with keys encrypted and stored locally, plus OKX Wallet and Nightly. Razor Wallet does not appear. None of the three publishes a post-quantum roadmap and no quantum-safe language appears for any of them on Movement's documentation.

6b · bridge 1 / 25

LayerZero is the dominant cross-chain messaging integration; its developer tooling is maintained as a public fork under the Movement organization, and Movement's framework carries a native atomic-bridge configuration resource on mainnet. Stargate, which provides liquidity transport over LayerZero, was acquired by LayerZero in a deal approved by Stargate governance in August 2025 at a stated 110 million dollars. LayerZero publishes no post-quantum roadmap. Wormhole and Celer are secondary or absent integrations on Movement.

6c · custodian 1 / 25

A major US-regulated spot exchange announced on 2025-05-01 that it would suspend MOVE trading, effective 2025-05-15, reported at the time as a delisting, which narrowed institutional venue coverage for the asset. The 2026-07-15 Chapter 11 filing of MVMT Labs, Inc. and the continued MOVE price decline add counterparty and relevance uncertainty for custodians, even with Move Industries stating that network operations are unaffected. Fireblocks, BitGo and Anchorage publish no Movement-specific post-quantum support, and no top-3 custodian publishes a Movement-specific post-quantum roadmap.

6d · rpc hsm tee infra 2 / 25

Documented RPC partners: Sentio, Hello Moon, BlockPi, Lava, Ankr, with NodeOps absent from the list. No partner publishes a Movement-specific post-quantum RPC roadmap and none advertises hybrid key exchange at its TLS termination. HSM and TEE attestation chains for Movement validator infrastructure are not documented at the Foundation level, and the validator set's advertised endpoints are cloud load-balancer hostnames with no attestation surface published.

7 Governance & Coordination weight 8% 11 / 100
7a · validator stake distribution 2 / 20

Measured, not estimated. The on-chain validator-set resource returns four active validators and zero pending, holding roughly 24.8%, 25.5%, 24.6% and 25.2% of voting power, so two validators together exceed one third and the Nakamoto coefficient for consensus halting is 2. All four advertise their validator and fullnode network addresses as load-balancer hostnames in a single cloud provider's us-east-1 region, so operator and jurisdiction concentration compounds stake concentration. Validator-set change is permitted by the staking configuration, but no validator has joined or is pending. Movement publishes no Foundation-grade transparency report and its block explorer surfaces price, transaction and account totals with no consensus-decentralization metric, so this figure has to be read off the chain rather than off a Movement page. Client diversity is single-client.

7b · upgrade cadence under pressure 4 / 20

The L2-to-L1 pivot was announced in May 2025 and dated to December 2025. Engineering output did not stop under pressure: four tagged sovereign-L1 full-node releases shipped between 2026-03-18 and 2026-05-29, and the consensus-client fork carried commits through the Chapter 11 window and up to 2026-08-19. Against that, the public mainnet RPC fullnode advertises a build from 2026-04-27, so released does not equal deployed, and the period includes co-founder termination, leadership turnover, a major-exchange trading suspension, and the 2026-07-15 Chapter 11 filing of the original core-development entity, alongside a publishing pivot to stablecoin-payments output. Demonstrated capacity to keep a client moving is not the same as demonstrated capacity to coordinate a protocol-wide cryptographic migration across a validator set, and nothing in the record demonstrates the latter.

7c · named coordination lead 4 / 20

Move Industries is the named primary operating service provider and CEO Torab Torabi is re-confirmed by name and title in the official statement of 2026-07-28 responding to the Chapter 11 filing. The President and CTO roster named in 2025 press is not re-confirmed in that statement and is treated as unconfirmed-current. The original core-development entity, MVMT Labs, Inc., is in Chapter 11 as of 2026-07-15. The Movement Network Foundation oversees governance. There is no named post-quantum working group, no named post-quantum technical lead, and no published post-quantum mandate anywhere in Movement's documentation, blog, improvement proposals or code repositories.

7d · adversarial coordination precedent 1 / 20

The 2025 token-dump episode, in which an undisclosed market-making arrangement placed tens of millions of dollars of MOVE with an intermediary, drew an exchange action against the market maker on 2025-03-25, investigative press coverage from 2025-04-30, a major-exchange trading suspension announced 2025-05-01 and effective 2025-05-15, and the dismissal of a co-founder in May 2025. The 2026-07-15 Chapter 11 filing followed. Both episodes were answered with leadership change and corporate or legal restructuring, not with a coordinated technical fork, rollback or emergency protocol response. There is no post-quantum-relevant adversarial coordination precedent, and no adversarial precedent of any kind that exercised the validator set.

7e · canary tripwire mechanism 0 / 20

No canary, no Hourglass-style rate-limit, no cryptographic tripwire embedded in consensus, and no automated-response mechanism. Nothing in the deployed framework watches for anomalous signature validity or for a break in either the Ed25519 or the BLS12-381 path.

Source-disagreement disclosure

v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.

BLS12-381 at consensus: published specification contradicts the running chain

Movement's published M1 protocol specification names Ed25519, Multi-Ed25519 and SHA-3 (Keccak) as the system's primitives and assigns validator consensus vote authentication to Ed25519. The running mainnet says otherwise: the on-chain validator-set resource returns a 48-byte consensus public key for each of the four active validators, and Movement's own consensus client documents its BLS module as the minimal-pubkey-size variant of BLS12-381, which places public keys in G1 at 48 bytes and signatures in G2, with a proof-of-possession scheme against rogue-key attacks. We score the running chain over the published document where the two disagree, and we record that Movement's published primitive inventory is incomplete and incorrect at the consensus signature path.

M1 sovereign-L1 cutover date versus ledger genesis

Movement's documentation carries no dated launch or migration statement. A press announcement carried in trade media dates the M1 mainnet go-live to 2025-12-22, and that is announcement-grade sourcing, not a Movement engineering artifact. Independently, the chain serving Movement's mainnet endpoint reports a continuous ledger whose first block is timestamped 2024-12-05, with the oldest retained ledger version at zero, so the sovereign-L1 architecture was a change of settlement model on an existing ledger rather than a new genesis. We report the cutover as announcement-dated and we use the on-chain genesis, not the cutover date, wherever signature-history length is load-bearing.

AIP-137 status and where the code lives

Upstream Aptos AIP-137 (SLH-DSA-SHA2-128s per FIPS 205) is at status Accepted with a last-call end date of 2026-02-09; that is a proposal status, not a finalized on-chain capability. Upstream aptos-core defines the SLH-DSA-SHA2-128s feature flag and includes it in the Rust-side default feature set, but the flag position is clear in Aptos mainnet's own on-chain feature bitvector, so it is not activated by governance on the running Aptos mainnet. Movement's fork does not define the flag at all and a code search for the scheme in that fork returns zero results, and the flag position is likewise clear in Movement mainnet's feature bitvector. Movement has not stated whether it intends to inherit AIP-137 if it activates. We score Movement's posture against Movement's own documentation, code and chain state, not against Aptos's roadmap.

GitHub organization: rename, not restructuring

The appearance of an empty organization under Movement's former handle could be taken as evidence of a corporate restructuring of the code estate following the bankruptcy. That reading is not supported. Repository paths under the former handle still redirect to the current organization, which is the standard signature of a GitHub organization rename rather than a migration between accounts; the current organization's account predates the former handle's account by more than three years and holds the repositories with their original creation dates; and the empty placeholder account occupying the vacated handle was created 2026-05-21, roughly two months before the Chapter 11 filing. In-repository commits renaming the old handle to the new one landed 2026-07-30 and are string cleanup inside an already-renamed repository. We therefore do not treat the GitHub estate as evidence of post-bankruptcy restructuring.

Entity separation after the Chapter 11 filing

The Chapter 11 filing of MVMT Labs, Inc. on 2026-07-15 is established by court documents and by coverage across at least nine independent outlets. The claim that Move Industries, the Movement Network Foundation, the MOVE token and the network are separate legal entities and unaffected comes from Movement's own official statement of 2026-07-28 and has not been independently adjudicated. We treat the filing as fact and the separation claim as the company's own.

Wallet list changed between evaluations

Movement's current documentation names Motion (the self-custodial wallet built by Move Industries), OKX Wallet and Nightly as the recommended wallets. The 2026-05-01 evaluation recorded OKX Wallet, Razor and Nightly; Razor no longer appears. The date of the documentation change could not be independently established, so the current page is treated as authoritative.

Band range versus band label

The published band table maps a QRI of 11 to 20 to Band 2, whose label reads Acknowledged and whose descriptive text is a public statement with no plan. Movement has made no public post-quantum statement of any kind, so for this chain the numeric range and the label diverge. We publish the band the rubric produces rather than adjusting it, and we record the divergence here. The primary headline output, Migration Stage 0 (Unaware), carries no such ambiguity.

Delta-QRI under alternative weighting

Vendor-readiness 25% and governance 5% rebalance: minus 2 to plus 1, within CI; does not change Band or Migration Stage.

Announcement-to-shipped ratio

Announced: 0. Shipped: 0. Ratio: 0.

Tag: none, no inflation

Peers in the L1 profile

9 chains closest to Movement Network by Stage then QRI.

S3 41
S3 46
S2 22
S2 25
S2 25
S2 31
S2 33