{"investigation":{"slug":"sentiment","entity_name":"Sentiment","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Sentiment is an undercollateralized DeFi lending protocol originally deployed on Arbitrum, later migrating activity to HyperLiquid L1. On April 4, 2023, the protocol suffered a read-only reentrancy exploit resulting in approximately $1 million in losses, of which 90% was returned by the attacker following a negotiated $95,000 bounty. ZachXBT has flagged the entity for elevated risk; the protocol remains operational with a low TVL of roughly $518,000 as of 2025.","sections":[{"content":"Sentiment (sentiment.xyz) is a permissionless, undercollateralized lending protocol that allows borrowers to access leverage of up to 5x against a portfolio of on-chain assets. The protocol enables users to deploy borrowed capital into integrated DeFi protocols including Balancer, Curve, Sushi, and Aave without requiring full collateralization. Originally deployed on Arbitrum, Sentiment has transitioned its primary activity to HyperLiquid L1 as of 2024-2025. The protocol raised $2.4 million in a seed round on September 10, 2022, led by Archetype Ventures, with participation from Castle Island Ventures, Matrixport, Caballeros Capital, 0xVentures, Yunt Capital, Shine Capital, Grug Capital, and others. As of early 2025, the protocol reported a total funding of $3.4 million including a subsequent public sale of $1 million that closed February 24, 2025. The undercollateralized lending model is inherently higher risk than overcollateralized alternatives as it requires protocol-level solvency controls rather than direct collateral liquidation.","heading":"Protocol Overview","sources":[{"url":"https://defillama.com/protocol/sentiment","name":"defillama.com","type":"other","credibility":3},{"url":"https://itsa-global.medium.com/defi-insight-undercollateralized-lending-with-sentiment-protocol-587166141207","name":"itsa-global.medium.com","type":"other","credibility":3},{"url":"https://cryptorank.io/ico/sentiment","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://candydrops.xyz/en/projects/sentiment","name":"candydrops.xyz","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 4, 2023, Sentiment suffered a read-only reentrancy exploit on Arbitrum resulting in losses of approximately $1 million. The attacker exploited a known vulnerability in Balancer's pool pricing mechanism that Sentiment integrated for collateral valuation. The attack sequence began with a flash loan of 606 WBTC, 10,130 WETH, and 18 million USDC drawn from the Sentiment lending pool. The attacker then called Balancer Vault's joinPool() and exitPool() functions, triggering a fallback function during the ETH withdrawal phase. At that point, pool balances had not yet been updated, causing the total supply of LP tokens to decrease while recorded token balances remained stale. By calling Sentiment's borrow function during this window, the attacker was able to borrow multiple assets at artificially inflated collateral valuations. The attack was facilitated by the Balancer 'read-only reentrancy' bug, a class of vulnerability first documented by ChainSecurity over a year prior to this exploit. The wallet conducting the attack was labelled 'Sentimentxyz Exploiter' by Arbiscan. The Sentiment team detected abnormal borrowing activity at approximately 18:00 UTC on April 4 and paused the main contract, restricting the protocol to withdrawal-only mode. Total estimated loss at time of detection was reported variously as over $500,000 (initial reports) and approximately $1 million (later confirmed figure after full accounting). PeckShield was engaged for on-chain analysis.","heading":"April 2023 Exploit — Read-Only Reentrancy Attack","sources":[{"url":"https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-lending-platform-sentiment-loses-1m-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.investing.com/news/cryptocurrency-news/liquidity-protocol-sentiment-exploited-for-over-500k-3049036","name":"investing.com","type":"other","credibility":3},{"url":"https://crypto.news/sentiment-defi-platform-losses-1m-to-hacker-on-arbitrum/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Sentiment team publicly offered the attacker a $95,000 bounty in exchange for the return of stolen funds, with a deadline of 08:00 UTC on April 6, 2023. The team stated they would not pursue legal action if the attacker complied. On April 6, 2023, approximately 90% of the stolen funds (estimated at $900,000) were returned. The team announced the recovery and stated the protocol had been restored to 100% solvency. Sentiment held $2 million in coverage through Sherlock, a smart contract audit marketplace and insurer. Sherlock paid out approximately $50,000 (reported as 75% of the remaining 10% loss after attacker return), covering residual losses not recovered from the attacker. By April 8, the Sentiment team announced full fund recovery. An official post-mortem was published on April 11, 2023. This recovery pattern — where attackers return funds after accepting a negotiated bounty — was observed in several high-profile 2023 DeFi incidents including Euler Finance.","heading":"Funds Recovery and Bounty Negotiation","sources":[{"url":"https://beincrypto.com/defi-trend-sentiment-hacker-returns-90-stolen-funds-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/public/index.php/news/sentiment-recovers-870k-after-negotiations-with-the-hacker/amp","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/arbitrum-defi-sentiment-hacker-recovery-bounty/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/sherlock-defi-insurer-on-edge-euler-hack/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Sentiment had undergone a Sherlock audit in January 2023, approximately three months before the exploit. The GitHub repository for the audit (sherlock-audit/2023-01-sentiment-judging) contains adjudication of security findings from that contest. The read-only reentrancy vulnerability exploited in April 2023 was not caught in the audit. The Sentiment exploit, alongside the larger Euler Finance hack of March 2023, caused Sherlock's reserves to fall approximately 90%, materially straining the insurer. Sherlock's coverage for Sentiment was $2 million, sufficient to fully cover the loss had the hacker not returned funds. The exploit highlighted a systemic risk: protocols relying on external integrations (such as Balancer) for pricing and collateral valuation inherit the security assumptions and vulnerabilities of those integrations, even if the core protocol itself passes audit.","heading":"Sherlock Audit and Insurance Impact","sources":[{"url":"https://github.com/sherlock-audit/2023-01-sentiment-judging","name":"github.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/sherlock-defi-insurer-on-edge-euler-hack/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://medium.com/rektify-ai/learning-from-the-biggest-defi-hacks-of-2023-1cab753ac4ea","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2025, Sentiment operates primarily on HyperLiquid L1 with a reported TVL of approximately $517,964, down significantly from pre-exploit levels. Active loans total approximately $342,749. The Arbitrum deployment retains minimal liquidity ($6,600). The protocol's undercollateralized model introduces structural solvency risk: if collateral asset prices decline rapidly and the protocol cannot liquidate unhealthy positions in time, it may accumulate bad debt leading to insolvency. Sentiment uses the GARCH model and claimed zero-knowledge proof technology for risk management in its HyperLiquid iteration. The protocol has not announced a native token as of early 2025. ZachXBT has flagged Sentiment as an entity of elevated risk concern, though the specific basis of that flag is not independently verifiable from public reporting at the time of this investigation. The small TVL and history of at least one material exploit make this a higher-risk protocol for capital deployment.","heading":"Current Status and Risk Profile","sources":[{"url":"https://defillama.com/protocol/sentiment","name":"defillama.com","type":"other","credibility":3},{"url":"https://candydrops.xyz/en/projects/sentiment","name":"candydrops.xyz","type":"other","credibility":3},{"url":"https://blog.ezkl.xyz/post/sentiment/","name":"blog.ezkl.xyz","type":"other","credibility":3}],"severity":"medium"},{"content":"Sentiment's core design allows borrowers to access capital exceeding the value of their deposited collateral, which is the defining characteristic of undercollateralized lending. In contrast to overcollateralized protocols like Aave or Compound (where collateral always exceeds debt), undercollateralized protocols rely on smart contract-enforced position management and real-time oracle pricing to remain solvent. The April 2023 exploit demonstrated that oracle or pricing manipulation is the primary attack vector for this architecture. If asset prices used to value collateral can be artificially inflated (as occurred via the Balancer reentrancy bug), attackers can borrow far more than the true collateral value. This structural risk category requires ongoing vigilance and is not resolved by a single audit. The protocol's current HyperLiquid deployment inherits the broader risks of that L1 ecosystem, including smart contract risk in bridge and oracle infrastructure.","heading":"Structural Risks of Undercollateralized Lending","sources":[{"url":"https://itsa-global.medium.com/defi-insight-undercollateralized-lending-with-sentiment-protocol-587166141207","name":"itsa-global.medium.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://zokyo.io/blog/read-only-reentrancy-attacks/","name":"zokyo.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-09-10","event":"Sentiment raises $2.4 million seed round led by Archetype Ventures, with Castle Island Ventures and others participating.","source":""},{"date":"2023","event":"Sherlock audit of Sentiment protocol completed; audit judging repository published on GitHub.","source":"","date_original":"2023-01-01"},{"date":"2023-04-04","event":"Read-only reentrancy exploit executed on Arbitrum via Balancer integration. Approximately $1 million drained. Sentiment pauses main contract at 18:00 UTC.","source":""},{"date":"2023-04-05","event":"Sentiment team publicly offers $95,000 bounty to attacker with deadline of April 6, 08:00 UTC. Engages PeckShield and law enforcement.","source":""},{"date":"2023-04-06","event":"Attacker returns approximately 90% of stolen funds (~$900,000) after negotiation. Protocol announced 90% recovery.","source":""},{"date":"2023-04-07","event":"Sherlock insurance pays approximately $50,000 to cover a portion of the remaining unrecovered losses.","source":""},{"date":"2023-04-08","event":"Sentiment announces 100% fund recovery and full protocol solvency restoration.","source":""},{"date":"2023-04-11","event":"Sentiment publishes official post-mortem detailing the exploit mechanics and remediation steps.","source":""},{"date":"2025-02-24","event":"Sentiment completes a public token sale raising $1 million, bringing total disclosed funding to $3.4 million. Protocol operating on HyperLiquid L1.","source":""}],"sources_used":[{"url":"https://defillama.com/protocol/sentiment","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://itsa-global.medium.com/defi-insight-undercollateralized-lending-with-sentiment-protocol-587166141207","name":"itsa-global.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptorank.io/ico/sentiment","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829235613/https://cryptorank.io/ico/sentiment","credibility":3,"archive_timestamp":"2026-08-29T23:56:13+00:00"},{"url":"https://candydrops.xyz/en/projects/sentiment","name":"candydrops.xyz","type":"other","archive_url":"https://web.archive.org/web/20260829233431/https://candydrops.xyz/en/projects/sentiment","credibility":3,"archive_timestamp":"2026-08-29T23:34:31+00:00"},{"url":"https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017172448/https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376","credibility":3,"archive_timestamp":"2025-10-17T17:24:48+00:00"},{"url":"https://beincrypto.com/defi-lending-platform-sentiment-loses-1m-exploit/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260210234344/https://beincrypto.com/defi-lending-platform-sentiment-loses-1m-exploit/","credibility":3,"archive_timestamp":"2026-02-10T23:43:44+00:00"},{"url":"https://www.investing.com/news/cryptocurrency-news/liquidity-protocol-sentiment-exploited-for-over-500k-3049036","name":"investing.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/sentiment-defi-platform-losses-1m-to-hacker-on-arbitrum/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20250908181133/https://crypto.news/sentiment-defi-platform-losses-1m-to-hacker-on-arbitrum/","credibility":3,"archive_timestamp":"2025-09-08T18:11:33+00:00"},{"url":"https://beincrypto.com/defi-trend-sentiment-hacker-returns-90-stolen-funds-exploit/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/public/index.php/news/sentiment-recovers-870k-after-negotiations-with-the-hacker/amp","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.dlnews.com/articles/defi/arbitrum-defi-sentiment-hacker-recovery-bounty/","name":"dlnews.com","type":"other","archive_url":"http://web.archive.org/web/20260617114604/https://www.dlnews.com/articles/defi/arbitrum-defi-sentiment-hacker-recovery-bounty/","credibility":3,"archive_timestamp":"2026-06-17T11:46:04+00:00"},{"url":"https://www.dlnews.com/articles/defi/sherlock-defi-insurer-on-edge-euler-hack/","name":"dlnews.com","type":"other","archive_url":"http://web.archive.org/web/20260617165936/https://www.dlnews.com/articles/defi/sherlock-defi-insurer-on-edge-euler-hack/","credibility":3,"archive_timestamp":"2026-06-17T16:59:36+00:00"},{"url":"https://github.com/sherlock-audit/2023-01-sentiment-judging","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829134303/https://github.com/sherlock-audit/2023-01-sentiment-judging","credibility":3,"archive_timestamp":"2026-08-29T13:43:03+00:00"},{"url":"https://medium.com/rektify-ai/learning-from-the-biggest-defi-hacks-of-2023-1cab753ac4ea","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.ezkl.xyz/post/sentiment/","name":"blog.ezkl.xyz","type":"other","archive_url":"http://web.archive.org/web/20260608232006/https://blog.ezkl.xyz/post/sentiment/","credibility":3,"archive_timestamp":"2026-06-08T23:20:06+00:00"},{"url":"https://zokyo.io/blog/read-only-reentrancy-attacks/","name":"zokyo.io","type":"other","archive_url":"http://web.archive.org/web/20260129075907/https://zokyo.io/blog/read-only-reentrancy-attacks/","credibility":3,"archive_timestamp":"2026-01-29T07:59:07+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:42.956736+00:00","updated_at":"2026-08-30T05:14:11.500014+00:00"}}