The co-founder of OpenZeppelin, the most widely used smart contract security framework, now says every DeFi protocol is unsafe. Manuel Araoz has publicly advised friends and family to exit all DeFi positions, including blue-chip protocols like Aave, MakerDAO, and Compound.
Araoz argues that AI coding agents have become exceptionally powerful at discovering vulnerabilities in smart contracts. This capability inherently favors attackers: defenders must patch every single hole, while attackers only need to find one to drain funds. This structural asymmetry, he says, puts even the most established DeFi protocols at risk.
OpenZeppelin's contract libraries are used by the vast majority of Solidity developers, and its audit team has reviewed countless DeFi projects. Araoz's warning carries significant weight in the industry.
AI Upends the Balance Between Attackers and Defenders
Araoz's core thesis is that AI gives attackers a massive efficiency advantage in finding vulnerabilities. Traditional security audits rely on manual reviews and experience; AI agents can scan hundreds of contracts in parallel, quickly identifying weak points. Defenders cannot possibly fix all issues at the same speed. An attacker only needs one unremediated flaw to empty a pool. Fixes often require pausing protocols and deploying upgrades, a process that can take days or weeks, while an attack can be launched at any moment.
That this warning comes from the founder of a company dedicated to making contracts safer underscores the severity of the situation.
$630 Million Lost in April, North Korean Ties Surge
Data supports Araoz's concerns. In April alone, DeFi protocols lost nearly $630 million, the heaviest monthly toll since the $1.5 billion Bybit theft in February 2025. The two largest incidents — Drift ($285 million) and Kelp DAO ($293 million) — have been attributed to the North Korean-backed Lazarus Group. Kelp DAO announced full recovery of rsETH five weeks later, but the damage was done.
Market confidence has eroded. Total value locked (TVL) in DeFi dropped about 14% from mid-April, falling from approximately $172 billion to $148 billion, signaling capital flight. May has already seen 25 security incidents; the Verus Network cross-chain bridge was exploited for $11.6 million, and Polymarket’s UMA CTF Adapter lost about $570,000. Combined, these two incidents account for over $12 million.
Over 40 Protocols Shut, Trust Crisis Spreads
More than 40 protocols have announced closures or entered liquidation in the first five months of this year. Statistics show that North Korea-linked attackers accounted for 76% of global crypto hack losses in 2026, up from 64% in 2025. The crisis of confidence in DeFi continues to deepen.

