DeFi lending exploit-risk monitoring · starting with Ethereum
Exploit-Risk Intelligence for DeFi Lending Protocols
BlockSentinel monitors live Ethereum lending activity, scores exploit risk with evidence, and prepares multisig-ready guard proposals so protocol teams can respond before stress becomes an incident.
Advisory by design: no custody, no autonomous execution, no unilateral control.
Early access for protocol, security, and risk teams. Not an audit replacement and not a guarantee of exploit prevention.
- Oracle deviation persisted 38mHigh
- Liquidation spike z=3.1Med
- Same-tx borrow/repay elevatedMed
Audits catch code risk. Exploits often emerge from live market stress.
When market stress starts moving, protocol teams need more than raw events. They need a ranked risk signal, evidence they can trust, and a safe response package signers can review.
Signals move faster than governance
Oracle deviations, utilization spikes, and liquidation cascades can compound within minutes.
Monitoring creates noise
Raw event alerts are hard to prioritize without confidence, evidence, and severity.
Response is still manual
Teams need the next safe action packaged for signers, not another dashboard to interpret.
Product operating loop
Ingest → detect → score → alert → propose. Advisory throughout: BlockSentinel does not execute.
Event-log based Ethereum ingest for lending activity.
Phase 1: Borrow, repay, and liquidation logs from configured emitters.
Spot abnormal stress in rolling windows.
Phase 1: Counts, z-scores, and same-transaction borrow/repay patterns.
Produce an explainable near-term risk score.
Phase 1: Rule-based 7d / 30d score with factors, evidence, and confidence.
Notify the team when thresholds move.
Phase 1: Slack and email with severity and dedupe windows.
Package a bounded next action for signers.
Phase 1: Guard proposal JSON; Safe packaging is optional / roadmap.
Live risk command center
A static product illustration of how protocol, security, and risk teams would triage lending exploit risk. No live API on this page.
- Oracle deviation persistence38m
- Liquidation spikez=3.1
- Same-tx borrow/repayelevated
- 14:02Oracle deviation > 2% detected
- 14:18Deviation still open · 16m persistence
- 14:31Liquidation spike z=3.1 on WBTC market
- 14:40Risk 7d crossed 8.0 · confidence 0.82
- 14:41Guard proposal prepared · freeze WBTC
Sample data for illustration. Figures are not live protocol measurements.
Signals built for lending-risk triage
Phase 1 focuses on event-log signals that protocol security teams can argue with — not a generic on-chain firehose.
Borrow/repay anomalies
Rolling counts and z-scores on borrow and repay activity.
Liquidation stress
Spike detection when liquidations cluster above baseline.
Flash-loan-like activity
Same-transaction borrow/repay proxy from event logs.
Market-specific thresholds
Per-protocol risk thresholds and alert severity tiers.
Oracle deviation persistence
Persistence windows are in the product model. Full oracle feed integration is on the roadmap.
Cross-market propagation · multi-chain
Richer contract decoding, oracle feeds, and chains beyond Ethereum are not in the current MVP.
Explainable risk score
Every score is built to be argued with. Protocol teams see the factors, the window, the evidence, and the confidence behind the number.
| Factor | Window | Weight |
|---|---|---|
| Oracle deviation persistence | 38m | High |
| Liquidation spike z-score | 1h | Med |
| Same-tx borrow/repay | 1h | Med |
Phase 1 scores are rule-based. Optional AI explanations, if added later, stay capped and secondary to the evidence bundle.
Guard proposal workflow
This is not an auto-executor. BlockSentinel prepares a bounded, allowlisted proposal. Signers keep control.
What the proposal includes
- Human-readable summary of why risk increased
- Structured JSON with evidence and an audit trail
- Allowlisted action type, scope, cooldown, and expiration
- Optional Safe transaction packaging (proposal only, when ready)
Safety bounds
- Proposal only — no autonomous execution
- Allowlisted actions per protocol
- Cooldowns and expiration on recommendations
- No custody and no unilateral control
- Multisig approval required to change anything on-chain
Sample alert and JSON
What a protocol security channel would receive when lending stress crosses a threshold. Examples only.
Sample payloads for evaluation. All actions require multisig approval. Safe-ready packaging is optional depending on backend readiness.
Who it's for
Teams responsible for keeping lending protocols safe after deployment.
Protocol founders / core teams
Pain: Live market stress can outrun governance and parameter reviews.
You get: A ranked exploit-risk score, evidence, and a bounded next-step package for signers.
Faster, calmer response without giving up control.
Security engineers
Pain: Raw logs and generic alerts are slow to triage during an incident.
You get: Explainable drivers, evidence bundles, and an incident timeline.
Triage in minutes instead of reconstructing the story from scratch.
Risk managers
Pain: Dashboards show data but do not package an operational response.
You get: 7d/30d scores, thresholds, and alert severity designed for lending markets.
A consistent risk signal the rest of the team can act on.
DAO guardians / multisig signers
Pain: Unsigned, unbounded asks are hard to review under time pressure.
You get: Allowlisted proposals with expiration, cooldowns, and an audit trail.
Clear yes/no decisions. Execution stays with the multisig.
Auditors / advisors
Pain: Post-deploy monitoring is usually outside the audit scope.
You get: Evidence-backed scores and sample guard packages to review.
A shared artifact for follow-up recommendations.
Early pilot: monitor one Ethereum lending protocol
Apply for a founder-led pilot. We will help configure one Ethereum lending protocol, define alert thresholds, and deliver sample risk alerts and guard proposal packages.
- Protocol config review
- One monitored protocol / market set on Ethereum
- Slack and email alerts
- Sample dashboard walkthrough
- Weekly risk summary
- Guard proposal package examples
- Founder-led onboarding
Early access. Ethereum-first. Advisory proposals only.
Security and trust
Guard proposals can sound risky. The safety model is intentionally narrow.
No custody
BlockSentinel never holds protocol or user funds.
No autonomous execution
Guard actions are proposals. Signers approve or reject.
Read-only RPC ingest
Public chain data only. No signing keys over protocol contracts.
Explainable evidence
Scores include factors, windows, and evidence — not a black box.
Allowlisted guard actions
Only protocol-approved action types can be proposed.
Multisig retains control
Governance and signers keep unilateral authority.
Request early access
Tell us which Ethereum lending protocol you want monitored. We will follow up for a founder-led pilot conversation.
BlockSentinel is advisory by design: no custody, no autonomous execution, and no unilateral control over protocol contracts.
- We confirm protocol, markets, and alert recipients.
- We share sample alert and guard proposal formats.
- We schedule founder-led onboarding for the pilot.
Independent monitoring infrastructure. Not affiliated with Aave, Compound, or any protocol unless explicitly stated.