Maxor Sentinel
Detect threats one block before they land.
Maxor Sentinel is real-time DeFi threat detection built on information theory — no training data, no hand-written rules. It flags oracle manipulation, liquidation cascades, and flash-loan attacks in the 1–4 second window, so an automated response can fire before the exploit completes. And it's verifiable by design : you can check every alert without trusting us.
Availability — 2027
The detection engine runs today — what is 2027 is when you can have it. Sentinel is not on a price list, there is no pre-order and no early-access tier, and no date on this page is a commitment. Everything below describes what it is built to do, not something you can deploy this quarter.
<200ms
p95 alert latency
$8.2B+
TVL across monitored protocols
60+
Chains — live and on the way
<0.001%
False-positive rate
Detection, not forensics.
The average DeFi exploit drains funds in under a minute — long before a human notices. Sentinel watches the chain with information-theoretic anomaly detection : no training data to poison, no brittle rule list to maintain. It catches the shape of an attack as it forms — in seconds, not the 5+ minutes manual discovery takes — so you can act while it still matters.
Connect. Detect. Act.
Point it at a feed, and it watches. One API call to start ; three ways to respond.
01 — Connect
Point Sentinel at any oracle feed, lending pool, or DEX pair. One API call — no agents to deploy, no contracts to instrument.
02 — Detect
A deterministic information-theoretic engine analyzes on-chain data in real time. No training data, no rule list — it measures the anomaly directly.
03 — Act
Get alerts via webhook, email, or Slack — or wire automated responses : pause a contract, adjust a parameter, before the exploit completes.
Fast, honest, verifiable.
Built to fire in the seconds that matter — and to be checked, not trusted on faith.
Information-theoretic detection
Anomalies are measured from first principles, not learned from a labeled dataset. Nothing to poison, nothing to retrain — deterministic math you can audit.
One block ahead
Detection in the 1–4 second window, with sub-200ms p95 alert latency. Fast enough that an automated response can land before the loss does.
Bring-your-own-verifier
Verify any alert without trusting Sentinel. The verifier is open — re-check the math yourself, on your own infrastructure.
Automated response
Webhook, email, or Slack for humans ; contract pause and parameter adjustment for machines. You decide how far the automation goes.
10 detection modules, 60+ chains
Oracle, lending, and DEX coverage across a growing chain list — one integration, broad reach.
Honest metrics
Transparent latency, false-positive rate, and coverage — published, not promised. A sub-0.001% false-positive rate means alerts you can act on.
The attacks that drain protocols.
Each class has a measurable on-chain signature. Sentinel watches for the shape, not a known signature list — so a zero-day variant trips the same alarm.
Oracle manipulation
Price-feed deviation and manipulation detected as a statistical anomaly, before it's arbitraged into a loss.
Liquidation cascades
Cascading liquidation pressure flagged as it builds — not after positions have already unwound.
Flash-loan attacks
The atomic borrow-exploit-repay pattern caught inside the block it forms in.
MEV & sandwiching
Adversarial ordering and extraction patterns surfaced in real time.
Wash trading
Artificial volume and circular flow identified from the information signature, not heuristics.
Zero-day variants
Because detection measures anomaly directly, novel attack shapes trip the same alarm — no signature update required.
Where the rest of the field guesses, this proves.
Almost every threat-detection product in this space is a machine-learning classifier trained on labelled exploits. That design choice has consequences you inherit — and they are the reason we built the detection differently.
The same input gives the same verdict
A trained classifier can score the same transaction differently across runs, model versions or retrainings. Deterministic detection returns one verdict, today and in two years — which is the only way an incident review can be re-run rather than re-argued.
No training set, so no blind spot from it
A model can only recognize attack shapes resembling what it was trained on. Measuring the information signature of a transaction flow directly means a novel exploit trips the same alarm as a known one — no signature update, no retraining window during which you are exposed.
An alert you can hand to a regulator
« The model scored 0.87 » is not an explanation. Every Sentinel alert decomposes into the measurement that produced it, so a compliance officer, an auditor or an exchange can follow the reasoning without trusting the vendor.
False-positive behaviour you can bound
With a classifier, the false-positive rate is an empirical observation on last quarter's data. With a deterministic measure and a stated threshold, it is a property of the method — which is what makes it defensible in front of a risk committee.
No silent drift
Models decay as the market changes and the decay is invisible until something is missed. There is no drift to monitor here, because there is no learned state to drift.
Runs where your risk lives
Cloud, self-hosted or fully air-gapped, Canadian-resident by default. Detection that requires shipping your order flow to a vendor's model is a different risk trade than the one you thought you were making.
Hosted, or entirely inside your perimeter.
Start in the cloud in minutes ; bring it in-house when your security review demands it.
Cloud
Fully managed on Canadian-resident infrastructure. Available on every tier — start monitoring in minutes, nothing to provision.
Self-hosted
Run the engine inside your own environment for Enterprise deployments — your keys, your infrastructure, your control plane.
Air-gapped
Fully disconnected for the most sensitive deployments. No telemetry, no phone-home — the detection runs where the data lives.
From indie builders to regulated custodians.
Anyone with value on-chain that an exploit could drain in under a minute — at any scale.
One deterministic philosophy, across the suite.
Sentinel shares the Maxor posture : deterministic math over black-box models, verifiable over trust-us, sovereign-deployable by default. The same principles run beneath every Maxor platform.
Explore the Maxor suiteAvailability
2027
Status
🟢 Production
Deployment
Cloud · Self-hosted · Air-gap
Owner
Maxor Global LLC
2027 — not a quarter before it's right.
We would rather be late than ship a detector that misses a block. Sentinel is on our roadmap, not in a price list : no pre-order, no waitlist fee, no early-access tier. If the problem is yours today, tell us what you are watching — that is useful to us, and we will say plainly whether we can help now or not at all.
Maxor Sentinel, answered
Maxor Sentinel is a real-time DeFi threat-detection system. It watches on-chain activity and flags attacks — oracle manipulation, liquidation cascades, MEV, flash-loan exploits, and wash trading — one block before the loss lands, so a protocol or fund can act before value is gone.
Oracle manipulation, liquidation cascades, MEV extraction, flash-loan attacks, and wash trading — the on-chain patterns that drain DeFi protocols. It is unsupervised and zero-day-capable, so it flags attack shapes it has never seen before, not only known signatures.
Rules catch only what you already listed; an ML model needs labelled history and drifts. Sentinel models how an attack behaves on-chain as it forms — which is why it can surface novel (zero-day) exploits one block ahead instead of after the loss.
Sentinel raises the alert while the attacking transaction is still forming — within the block before funds move — leaving a window to pause, block, or respond. Detection after the fact is a post-mortem; Sentinel is built to be pre-loss.
Yes — deployment is hybrid: in the cloud or on your own infrastructure alongside your node. Your keys, data, and monitoring stay under your control.