Sentry Labs Advisories← Back to site
Sentry Labs // Security Bulletin

Advisories

Advisories, Sentry Labs bulletins on the security and integrity of automated trading systems: risk controls, kill-switches, credential hygiene, tenant isolation, market-data integrity, and audit trails. Educational, not investment advice.

Critical High Moderate Advisory Informational
SL-2026-010 Informational Compliance

Audit trails and reconciliation for trading systems

When something goes wrong at machine speed, the record is all you have. Building tamper-evident audit trails and reconciliation that prove what your system did.

FILED 01 AUG 2026 · 6 MIN READ
Audit trails and reconciliation for trading systems
SL-2026-020 High Intellectual Property

Protecting the strategy: your real intellectual property

A trading edge is stolen more often through leakage than espionage. Guarding the strategy, its parameters, and its footprint, from the code repo to the order book itself.

FILED 28 JUL 2026 · 6 MIN READ
Protecting the strategy: your real intellectual property
SL-2026-009 Moderate Data Integrity

Market-data integrity: stale, spoofed, and dropped

A strategy is only as good as the prices it believes. Guarding the market-data path against staleness, gaps, and manipulation before it drives a single order.

FILED 26 JUL 2026 · 6 MIN READ
Market-data integrity: stale, spoofed, and dropped
SL-2026-008 High Isolation

Tenant isolation in a multi-strategy platform

When many strategies and clients share one execution platform, isolation is a security control, not a convenience. How to stop one tenant from harming another.

FILED 19 JUL 2026 · 6 MIN READ
Tenant isolation in a multi-strategy platform
SL-2026-019 Critical Incident Response

Incident response for a compromised account

The worst time to design your response is during the incident. A calm, ordered playbook for the first hour of a suspected account compromise, contain, preserve, recover.

FILED 17 JUL 2026 · 7 MIN READ
Incident response for a compromised account
SL-2026-007 Critical Resilience

Engineering a kill-switch you can trust

A halt button is worthless if it fails in the one moment you need it. What it takes to build a kill-switch that flattens risk reliably, even when the system is broken.

FILED 12 JUL 2026 · 6 MIN READ
Engineering a kill-switch you can trust
SL-2026-018 Moderate Change Management

Change management for live trading systems

Most trading incidents are self-inflicted, a deploy gone wrong, not an attacker. How staged rollout, canaries, and fast rollback keep a code change from becoming a loss.

FILED 05 JUL 2026 · 6 MIN READ
Change management for live trading systems
SL-2026-006 High Credentials

Securing API keys and exchange credentials

An automated trading system lives or dies by the keys it holds. Scoping, storing, and rotating exchange credentials so a leak cannot become a liquidation.

FILED 05 JUL 2026 · 6 MIN READ
Securing API keys and exchange credentials
SL-2026-005 Informational Foundations

What separates institutional algos from retail bots

The gap between a hobby trading bot and an institutional execution system is not the signal, it is everything around it. A look at what actually distinguishes the two.

FILED 28 JUN 2026 · 7 MIN READ
What separates institutional algos from retail bots
SL-2026-004 Moderate Market Microstructure

Latency, slippage, and why microseconds matter

Latency is not vanity engineering, it is a direct input to fill quality and cost. How microseconds turn into slippage, adverse selection, and real P&L.

FILED 14 JUN 2026 · 6 MIN READ
Latency, slippage, and why microseconds matter
SL-2026-003 Advisory Research

Backtesting that survives live markets

Most backtests are optimistic fiction. What it takes to build a simulation whose results actually track live trading, order-book replay, queue position, and honest costs.

FILED 30 MAY 2026 · 7 MIN READ
Backtesting that survives live markets
SL-2026-002 Critical Risk Controls

Risk controls every trading system needs

Automated trading turns a small bug into a large loss at machine speed. The pre-trade gates, kill-switches, and monitoring that any serious system should enforce.

FILED 16 MAY 2026 · 6 MIN READ
Risk controls every trading system needs
SL-2026-001 Informational Execution

Execution algorithms explained: TWAP, VWAP and beyond

How large orders actually get worked into a market without moving it. A plain-language tour of TWAP, VWAP, POV, and implementation-shortfall execution algos.

FILED 29 APR 2026 · 7 MIN READ
Execution algorithms explained: TWAP, VWAP and beyond
SL-2026-017 High Custody

Withdrawal whitelists and secure payouts

Trading limits protect the position. Withdrawal controls protect the exit. Why the payout path deserves its own defences, allow-lists, delays, and out-of-band approval.

FILED 13 MAR 2026 · 6 MIN READ
Withdrawal whitelists and secure payouts
SL-2026-016 Moderate Cryptography

Signing orders: message authentication on the wire

An order is an instruction to move money. What stops one from being forged, altered, or replayed in flight, and why authenticity is a separate problem from encryption.

FILED 27 FEB 2026 · 6 MIN READ
Signing orders: message authentication on the wire
SL-2026-015 High Supply Chain

Supply-chain risk in your trading stack

Your system is only as trustworthy as the code you did not write. How a poisoned dependency or build pipeline becomes a position in your book, and how to close it.

FILED 23 JAN 2026 · 7 MIN READ
Supply-chain risk in your trading stack
SL-2025-014 High Insider Risk

The insider threat on a trading desk

The most dangerous access is the access you granted on purpose. How firms contain the trusted insider, malicious or merely careless, without grinding to a halt.

FILED 19 DEC 2025 · 6 MIN READ
The insider threat on a trading desk
SL-2025-013 High Access Control

Multi-factor authentication that actually holds

Not all second factors are equal. Why SMS and app codes still fall to a good phishing page, and what phishing-resistant authentication changes for a trading account.

FILED 14 NOV 2025 · 6 MIN READ
Multi-factor authentication that actually holds
SL-2025-012 Moderate Social Engineering

Phishing and social engineering against traders

The most reliable way into a trading operation is not the network, it is a person having a busy day. How targeted deception works, and the habits that defeat it.

FILED 03 OCT 2025 · 6 MIN READ
Phishing and social engineering against traders
SL-2025-011 High Threats

How trading accounts actually get drained

Accounts are rarely lost to some cinematic zero-day. They are drained through a mundane chain of small failures. A field guide to the real path an attacker takes.

FILED 22 AUG 2025 · 7 MIN READ
How trading accounts actually get drained