BlockSentinel logoBlockSentinel

DeFi lending exploit-risk monitoring · starting with Ethereum

Exploit-Risk Intelligence for DeFi Lending Protocols

BlockSentinel monitors live Ethereum lending activity, scores exploit risk with evidence, and prepares multisig-ready guard proposals so protocol teams can respond before stress becomes an incident.

Advisory by design: no custody, no autonomous execution, no unilateral control.

Early access for protocol, security, and risk teams. Not an audit replacement and not a guarantee of exploit prevention.

Risk command center
Aave V3 · Ethereum
Guard proposal prepared
Risk 7d
8.4
Confidence
0.82
Window
7d
Top signals
  • Oracle deviation persisted 38mHigh
  • Liquidation spike z=3.1Med
  • Same-tx borrow/repay elevatedMed
Proposed action
Freeze WBTC reserve
Expires in 120m · JSON package
Proposal only. Multisig retains execution.

Audits catch code risk. Exploits often emerge from live market stress.

When market stress starts moving, protocol teams need more than raw events. They need a ranked risk signal, evidence they can trust, and a safe response package signers can review.

Signals move faster than governance

Oracle deviations, utilization spikes, and liquidation cascades can compound within minutes.

Monitoring creates noise

Raw event alerts are hard to prioritize without confidence, evidence, and severity.

Response is still manual

Teams need the next safe action packaged for signers, not another dashboard to interpret.

Product operating loop

Ingest → detect → score → alert → propose. Advisory throughout: BlockSentinel does not execute.

1
Ingest

Event-log based Ethereum ingest for lending activity.

Phase 1: Borrow, repay, and liquidation logs from configured emitters.

2
Detect

Spot abnormal stress in rolling windows.

Phase 1: Counts, z-scores, and same-transaction borrow/repay patterns.

3
Score

Produce an explainable near-term risk score.

Phase 1: Rule-based 7d / 30d score with factors, evidence, and confidence.

4
Alert

Notify the team when thresholds move.

Phase 1: Slack and email with severity and dedupe windows.

5
Propose

Package a bounded next action for signers.

Phase 1: Guard proposal JSON; Safe packaging is optional / roadmap.

Live risk command center

A static product illustration of how protocol, security, and risk teams would triage lending exploit risk. No live API on this page.

Protocol
Aave V3 Ethereum
SlackEmailAPI
Risk 7d
8.4
Elevated
Risk 30d
6.1
Trend
Confidence
0.82
Fresh signals
Guard status
Prepared
Pending review
Signal drivers
  • Oracle deviation persistence38m
  • Liquidation spikez=3.1
  • Same-tx borrow/repayelevated
Timeline
  • 14:02Oracle deviation > 2% detected
  • 14:18Deviation still open · 16m persistence
  • 14:31Liquidation spike z=3.1 on WBTC market
  • 14:40Risk 7d crossed 8.0 · confidence 0.82
  • 14:41Guard proposal prepared · freeze WBTC

Sample data for illustration. Figures are not live protocol measurements.

Signals built for lending-risk triage

Phase 1 focuses on event-log signals that protocol security teams can argue with — not a generic on-chain firehose.

Available in MVP

Borrow/repay anomalies

Rolling counts and z-scores on borrow and repay activity.

Available in MVP

Liquidation stress

Spike detection when liquidations cluster above baseline.

Available in MVP

Flash-loan-like activity

Same-transaction borrow/repay proxy from event logs.

Available in MVP

Market-specific thresholds

Per-protocol risk thresholds and alert severity tiers.

Partial / proxy in MVP

Oracle deviation persistence

Persistence windows are in the product model. Full oracle feed integration is on the roadmap.

Roadmap

Cross-market propagation · multi-chain

Richer contract decoding, oracle feeds, and chains beyond Ethereum are not in the current MVP.

Explainable risk score

Every score is built to be argued with. Protocol teams see the factors, the window, the evidence, and the confidence behind the number.

Risk 7d
8.4
Near-term
Smoothed 30d
6.1
Trend
Confidence
0.82
0–1
Freshness
~5m
Ingest cadence
Factors and evidence
FactorWindowWeight
Oracle deviation persistence38mHigh
Liquidation spike z-score1hMed
Same-tx borrow/repay1hMed

Phase 1 scores are rule-based. Optional AI explanations, if added later, stay capped and secondary to the evidence bundle.

Guard proposal workflow

This is not an auto-executor. BlockSentinel prepares a bounded, allowlisted proposal. Signers keep control.

Risk threshold crossed
Guard policy checked
Proposal package created
Slack/email notified
Multisig reviews
Protocol executes or rejects

What the proposal includes

  • Human-readable summary of why risk increased
  • Structured JSON with evidence and an audit trail
  • Allowlisted action type, scope, cooldown, and expiration
  • Optional Safe transaction packaging (proposal only, when ready)

Safety bounds

  • Proposal only — no autonomous execution
  • Allowlisted actions per protocol
  • Cooldowns and expiration on recommendations
  • No custody and no unilateral control
  • Multisig approval required to change anything on-chain

Sample alert and JSON

What a protocol security channel would receive when lending stress crosses a threshold. Examples only.

Slack
BlockSentinel Risk Alert — Aave V3
Risk (7d): 8.4 · Confidence: 0.82
Trigger: Oracle deviation persisted 38 min
Supporting signals: liquidation spike z=3.1, same-tx borrow/repay elevated
Recommended action: Freeze reserve for WBTC (if allowlisted)
Action ID: BS-ETH-AAVE-2026-00019 · Status: PENDING · proposal only

Sample payloads for evaluation. All actions require multisig approval. Safe-ready packaging is optional depending on backend readiness.

Who it's for

Teams responsible for keeping lending protocols safe after deployment.

Protocol founders / core teams

Pain: Live market stress can outrun governance and parameter reviews.

You get: A ranked exploit-risk score, evidence, and a bounded next-step package for signers.

Faster, calmer response without giving up control.

Security engineers

Pain: Raw logs and generic alerts are slow to triage during an incident.

You get: Explainable drivers, evidence bundles, and an incident timeline.

Triage in minutes instead of reconstructing the story from scratch.

Risk managers

Pain: Dashboards show data but do not package an operational response.

You get: 7d/30d scores, thresholds, and alert severity designed for lending markets.

A consistent risk signal the rest of the team can act on.

DAO guardians / multisig signers

Pain: Unsigned, unbounded asks are hard to review under time pressure.

You get: Allowlisted proposals with expiration, cooldowns, and an audit trail.

Clear yes/no decisions. Execution stays with the multisig.

Auditors / advisors

Pain: Post-deploy monitoring is usually outside the audit scope.

You get: Evidence-backed scores and sample guard packages to review.

A shared artifact for follow-up recommendations.

Early pilot: monitor one Ethereum lending protocol

Apply for a founder-led pilot. We will help configure one Ethereum lending protocol, define alert thresholds, and deliver sample risk alerts and guard proposal packages.

  • Protocol config review
  • One monitored protocol / market set on Ethereum
  • Slack and email alerts
  • Sample dashboard walkthrough
  • Weekly risk summary
  • Guard proposal package examples
  • Founder-led onboarding
Apply for Pilot Access

Early access. Ethereum-first. Advisory proposals only.

Security and trust

Guard proposals can sound risky. The safety model is intentionally narrow.

No custody

BlockSentinel never holds protocol or user funds.

No autonomous execution

Guard actions are proposals. Signers approve or reject.

Read-only RPC ingest

Public chain data only. No signing keys over protocol contracts.

Explainable evidence

Scores include factors, windows, and evidence — not a black box.

Allowlisted guard actions

Only protocol-approved action types can be proposed.

Multisig retains control

Governance and signers keep unilateral authority.

Read the full security model

Request early access

Tell us which Ethereum lending protocol you want monitored. We will follow up for a founder-led pilot conversation.

By submitting, you agree to our Terms and Privacy Policy.

Safety statement

BlockSentinel is advisory by design: no custody, no autonomous execution, and no unilateral control over protocol contracts.

What happens after you submit
  • We confirm protocol, markets, and alert recipients.
  • We share sample alert and guard proposal formats.
  • We schedule founder-led onboarding for the pilot.

Independent monitoring infrastructure. Not affiliated with Aave, Compound, or any protocol unless explicitly stated.