S&P Global has agreed to acquire OpenZeppelin, bringing a smart contract audit provider and open-source developer library maker into its digital asset risk business. The companies said OpenZeppelin will keep its name and continue operating as a separate business unit.
OpenZeppelin CEO Demian Brener will remain in charge and report to Yann Le Pallec, president of S&P Global Ratings, according to the announcement. Financial terms were not disclosed, and the transaction remains subject to closing conditions.
S&P moves closer to the code layer
The deal takes S&P Global closer to the code that sits beneath stablecoins, tokenized funds and DeFi protocols. S&P said the acquisition would extend its risk-assessment capabilities into onchain technology and support new security assessments and benchmarks.
“Our digital assets strategy centers on bringing trusted data, benchmarks and transparent risk assessment to markets as they move onchain,” Le Pallec said in the announcement.
What OpenZeppelin brings
Founded in 2015, OpenZeppelin combines security assessments and secure development services with open-source smart contract libraries. According to figures cited by S&P, the company has conducted more than 900 security engagements, and its Contracts libraries underpin more than $37 trillion in value transferred.
OpenZeppelin Contracts provides developers with tested implementations of common standards, including ERC token standards, for Ethereum and other EVM-compatible blockchains. Projects can reuse those components instead of writing each function from scratch.
OpenZeppelin also runs a blockchain code audit business. Its audit page lists clients including Uniswap, Aave, Coinbase, the Ethereum Foundation and DTCC, covering both DeFi protocols and traditional financial infrastructure.
The company said its audits, engineering work and ecosystem programs will continue with the same team. It also said released and future versions of its Contracts libraries and other open-source tools will remain open source, free and publicly maintained on GitHub.
Defender shutdown and migration path
OpenZeppelin’s documentation says it disabled new sign-ups for Defender on June 30, 2025 and scheduled the platform’s final shutdown for July 1, 2026. The company said it is focusing on open-source versions of tools including Relayer and Monitor.
The same documentation directs users to migration guides for moving away from Defender Monitor and Defender Relayer.
Defender bundled tools for coding, auditing, deploying, monitoring and operating blockchain applications. The migration path points users to OpenZeppelin Monitor, which watches for specified onchain activity and can trigger notifications through services including Slack, email and webhooks.
Ratings business extends into code risk
S&P Global Ratings already evaluates financial risks in crypto products. In November 2025, for example, it lowered its stability assessment for Tether’s USDT to 5, or “weak,” from 4, or “constrained,” citing an increase in higher-risk assets in the stablecoin’s reserves.
OpenZeppelin provides security assessments and secure development services. The company says its security engagements have surfaced more than 10,000 vulnerabilities before production.
If the acquisition closes, DeFi teams that hire OpenZeppelin will be buying security work from a company owned by S&P Global. OpenZeppelin said ownership will change without changing the audit team, the brand or the open-source status of the tools developers use.

