SC Audit//UPDATE · Campaign 6 UpdateCommand center

SC Campaign 6 final update

Sentiment V2 leveraged lending protocol · autonomous SC audit pipeline
Sherlock bounty #37 removed. Pivoting to direct disclosure.

Bounty status

REMOVED
Sherlock #37, all fields null. 310 IDs scanned, 0 matches.

Verified findings

3
1 Critical (10/10), 1 High (9/10), 1 Medium (8/10)

Total API cost

~$35
1.67M tokens · 890 tool calls · 28 agents

Disclosure status

IN PROGRESS
5 emails, Discord ticket, Twitter DM, 8 messages sent.

Findings rated 1 to 10

ID Title Severity Rating Confidence Verification Status
S-02 HyperliquidUsdcOracle ETH_INDEX=4 is DYDX, not ETH CRITICAL 10/10
99% Mainnet API, precompile, docs DISCLOSING
S-04 RedstoneOracle ms/s staleness check bypass HIGH 9/10
95% Redstone source code confirmed DISCLOSING
S-01 AggV3Oracle missing non-positive price check MEDIUM 8/10
99% Forge PoC 6/6 PASS DISCLOSING
S-03 Hyperliquid oracles zero price DoS MEDIUM 7/10
90% Code review HELD
S-05 SuperPool paused pool removal MEDIUM 6/10
80% Code review HELD

API usage, full Campaign 6

Session 1, main audit pipeline

Agents23 (20 audit + 3 verification)
Tokens~1,550,000
Tool Calls~805
ModelClaude Opus 4.6
Cost$25-35

Session 2, submission and disclosure

Agents5 (research + scan)
Tokens~120,000
Tool Calls~85
Web Searches8
Sherlock IDs Scanned310
Cost$3-5

Campaign 6 totals

Total Agents28
Total Tokens~1,670,000
Total Tool Calls~890
Total Cost~$35
Cost per Finding$11.67

Pipeline lifetime, 6 campaigns

Total Campaigns6
Findings Submitted4 (C1+C2)
Targets Killed2 (C3+C4)
Ready/Blocked2 (C5+C6)
Kill Rate97-98%

Expected value if the bounty were active

S-02
$15K to $50K (Critical)
S-04
$5K to $15K (High)
S-01
$1K to $5K (Medium)
Total EV (0.3x discount)$5,600 to $18,700
Stake saved, bounty dead$750 USDC not risked
Direct disclosure EV (realistic)$1,500 to $4,000
Team pays a voluntary bounty around 15-20% of the time.40-50% fix silently with no reward.

Disclosure outreach across all channels

Gmail SMTP
0xhitgo@sentiment.xyz
SENT
Gmail SMTP
ruvaag@gmail.com
SENT
Gmail SMTP
coldroohafza@gmail.com
SENT
Gmail SMTP
sriyantra717@gmail.com
SENT
Gmail SMTP
0xhitgo@protonmail.com
SENT
GitHub Advisory
sentimentxyz/protocol-v2
404, NO ACCESS
Discord
ONYX server, ticket #0600
SENT
Telegram
@ruvaag (core dev)
PENDING, MANUAL
Twitter/X DM
@sentimentxyz
SENT

Campaign 6 timeline

Session 1, full pipeline deployment

20 agents audited 22 contracts (~5,135 LoC). 250+ raw findings narrowed to 5 submittable. 3 verification agents upgraded S-02 to Critical and S-04 to High.

Forge PoC, S-01 validated

6 of 6 tests pass. Zero price silent acceptance and negative price panic both confirmed. The AggV3Oracle pattern gap against sister contracts is proven.

Mainnet verification, S-02 confirmed critical

Hyperliquid mainnet API shows index 4 = DYDX ($0.15), index 1 = ETH ($2,269). That's a 15,127x overvaluation. Rating moved from 7/10 to 10/10.

Submissions prepared

4 SC-prefixed submission files created, with AppleScript automation for Chrome. The call was to submit 3 and hold 2.

Session 2, bounty removed

Sherlock #37 returns null on every field. We scanned 310 IDs and found zero Sentiment matches. The bounty was removed sometime between March and May 2026.

Pivot to direct responsible disclosure

Five-channel outreach to the Sentiment team. Email, GitHub Advisory, Discord, Telegram, and Twitter. No details shared yet. We're asking for a secure channel first.

Campaign 6 lessons learned

1.Verify the bounty is live before doing verification work. We spent $3-5 on verification agents for a bounty that was already dead. Check API status first.
2.Verification agents still earn their keep. S-02 went from 7/10 to 10/10 Critical. S-04 went from 50% to 95% confidence. Cost was $3-4. Always deploy for findings rated 6 or higher.
3.Post-audit oracle contracts stay prime targets. 4 of 5 findings came from 6 contracts (~558 LoC) added after all audits.
4.Always keep a disclosure fallback. Bounty platforms can pull programs at any time. Direct team contact preserves the finding value.
5.Fix DeepSeek routing before Campaign 7. 1.67M tokens on Opus ran ~$35 against ~$2 on DeepSeek Flash. That's 17.5x cost overhead.

Campaign 6 honest scorecard (user feedback)

DimensionScoreNotes
Finding quality9.5/10Best of all 6 campaigns. S-02 is the single best finding so far.
Verification rigor9/10Mainnet API, forge PoC, source code analysis
Target selection7/10Right protocol, wrong timing
Bounty verification1/10Didn't check before spending. One API call costs $0 and 30 seconds.
Cost efficiency3/10$35 on Opus, should be $2 on DeepSeek Flash
Monetization outcome3/10$0 confirmed, $1.5K-$4K hoped
Disclosure execution7/108 messages across 4 channels, all automated
Pipeline learning8/10CHECK 0, verification protocol, DeepSeek routing fix
OVERALL6/10Elite findings, broken process

Cumulative pipeline status, brutally honest

Confirmed earnings to date$0
Submissions awaiting judgment2 (K2 + Renegade)
Findings in disclosure limbo3 (Sentiment)
Targets correctly killed2 (GMTrade + CapyFi)
Total compute spent~$95 (should be ~$15 with DS routing)
Total deposits at risk$25 (Renegade USDC)
DeepSeek budget wasted$29.95 of $34.97
Best realistic outcome$15K-$25K
Expected outcome (0.3x)$4K-$8K
Worst realistic outcome-$120

Where it stands. The pipeline produces genuine security findings, and that part is proven. Whether those findings turn into money is still unproven. Everything rides on the Renegade and Sentiment responses over the next 2 to 4 weeks.