Loading article…
Manuel Aráoz of OpenZeppelin warns that all decentralized finance is unsafe due to AI-driven exploits and rising security asymmetry.
Manuel Aráoz, the co-founder of crypto security firm OpenZeppelin, has declared that he now considers "all of DeFi" unsafe due to escalating security risks. In a May 26 post on X, Aráoz advised friends and family to exit positions in major protocols like Aave and MakerDAO, arguing that the imbalance between attackers and defenders has become untenable [1]. His warning comes as the sector faces a surge in exploits and a significant drop in total value locked [1].
Key takeaways
Aráoz framed his warning around a structural disadvantage in smart contract security, noting that defenders must catch every flaw while attackers need only one opening to succeed [1]. He attributed this shifting landscape to advanced technology, stating that "coding agents are superhuman at finding vulnerabilities" [1]. This perspective carries weight given Aráoz's history as a co-founder of OpenZeppelin, a firm established in 2015 to secure crypto systems [3]. The comments follow warnings from Anthropic regarding its Claude Mythos AI model, which can autonomously uncover software vulnerabilities and create exploits [2].
The backdrop to Aráoz's statement is a series of high-value exploits. In April 2026, nearly $630 million was drained from DeFi protocols, with Kelp DAO losing around $293 million, Drift suffering roughly $285 million in losses, and Euler losing about $197 million [1]. Exploits continued into May, including an $11.6 million loss at Verus Network and a $573,200 breach at Polymarket [1]. CoinDesk reports that more than $1.1 billion has been lost to DeFi hacks since the previous year [2]. Consequently, the market has seen capital flight, with total value locked dropping by more than $20 billion since the start of the year [2].
The declaration from a leading security figure highlights a potential crisis of confidence in decentralized finance. As trust erodes, the industry faces pressure to evolve beyond traditional security models. OpenZeppelin responded to these threats on May 12 by releasing its "Four Layers of DeFi Risk" framework, which emphasizes that audits are no longer enough and calls for continuous threat monitoring and layered defenses [1]. For institutional players, this shift suggests that due diligence must now include evidence of live monitoring and insurance, rather than relying solely on historical audit reports [3]. The tension between the need for open, interoperable systems and the demand for institutional-grade security remains a central challenge for the sector's future [2].
Coverage is mostly measured — 3 of 3 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
Crypto agility is the capacity of a system to rapidly swap encryption algorithms, keys, or certificates without requiring physical hardware replacement.
The CA Browser Forum has established new rules that will reduce public TLS certificate lifespans to 47 days by 2029 to improve security and authentication.
Slow transaction speeds create financial risk because users are locked into a quote while market prices continue to fluctuate, potentially leading to price drift.
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Jun 12, 2026 · How we report
Custodial exchanges typically screen and vet the assets they list to reduce risk, while non-custodial platforms often provide access to a much wider range of tokens across many blockchains.