OpenZeppelin Co-Founder Warns All DeFi Unsafe, AI Makes Aave Vulnerable

OpenZeppelin Co-Founder Warns All DeFi Unsafe, AI Makes Aave Vulnerable

N
News Editor 01
2026-07-24 09:20:17
OpenZeppelin co-founder Manuel Araoz says all DeFi is unsafe, advising family to exit Aave, MakerDAO, and Compound. AI coding agents give attackers asymmetric advantage. Nearly $630M stolen in April, TVL down 14%, over 40 protocols closed.

The co-founder of OpenZeppelin, the most widely used smart contract security framework, now says every DeFi protocol is unsafe. Manuel Araoz has publicly advised friends and family to exit all DeFi positions, including blue-chip protocols like Aave, MakerDAO, and Compound.

Araoz argues that AI coding agents have become exceptionally powerful at discovering vulnerabilities in smart contracts. This capability inherently favors attackers: defenders must patch every single hole, while attackers only need to find one to drain funds. This structural asymmetry, he says, puts even the most established DeFi protocols at risk.

OpenZeppelin's contract libraries are used by the vast majority of Solidity developers, and its audit team has reviewed countless DeFi projects. Araoz's warning carries significant weight in the industry.

AI Upends the Balance Between Attackers and Defenders

Araoz's core thesis is that AI gives attackers a massive efficiency advantage in finding vulnerabilities. Traditional security audits rely on manual reviews and experience; AI agents can scan hundreds of contracts in parallel, quickly identifying weak points. Defenders cannot possibly fix all issues at the same speed. An attacker only needs one unremediated flaw to empty a pool. Fixes often require pausing protocols and deploying upgrades, a process that can take days or weeks, while an attack can be launched at any moment.

That this warning comes from the founder of a company dedicated to making contracts safer underscores the severity of the situation.

$630 Million Lost in April, North Korean Ties Surge

Data supports Araoz's concerns. In April alone, DeFi protocols lost nearly $630 million, the heaviest monthly toll since the $1.5 billion Bybit theft in February 2025. The two largest incidents — Drift ($285 million) and Kelp DAO ($293 million) — have been attributed to the North Korean-backed Lazarus Group. Kelp DAO announced full recovery of rsETH five weeks later, but the damage was done.

Market confidence has eroded. Total value locked (TVL) in DeFi dropped about 14% from mid-April, falling from approximately $172 billion to $148 billion, signaling capital flight. May has already seen 25 security incidents; the Verus Network cross-chain bridge was exploited for $11.6 million, and Polymarket’s UMA CTF Adapter lost about $570,000. Combined, these two incidents account for over $12 million.

Over 40 Protocols Shut, Trust Crisis Spreads

More than 40 protocols have announced closures or entered liquidation in the first five months of this year. Statistics show that North Korea-linked attackers accounted for 76% of global crypto hack losses in 2026, up from 64% in 2025. The crisis of confidence in DeFi continues to deepen.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.