# Security Pioneer Warns All DeFi Is Unsafe

**Published:** 2026-06-12T12:20:25.850Z  
**Topic:** Crypto Security  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/6a0931e5-3cd1-4e66-813d-97400570bd5d

Manuel Aráoz of OpenZeppelin warns that all decentralized finance is unsafe due to AI-driven exploits and rising security asymmetry.

Manuel Aráoz, the co-founder of crypto security firm OpenZeppelin, has declared that he now considers "all of DeFi" unsafe due to escalating security risks. In a May 26 post on X, Aráoz advised friends and family to exit positions in major protocols like Aave and MakerDAO, arguing that the imbalance between attackers and defenders has become untenable [1]. His warning comes as the sector faces a surge in exploits and a significant drop in total value locked [1].

**Key takeaways**
*   Aráoz cites "superhuman" AI coding agents that make smart contract security too asymmetric for defenders [1].
*   Nearly $630 million was stolen from DeFi protocols in April alone across 27 exploit cases [1].
*   OpenZeppelin released a "Four Layers of DeFi Risk" framework, arguing that audits alone are no longer sufficient [1].
*   Total value locked in DeFi dropped by about 14% since mid-April, falling from nearly $172 billion to around $148 billion [1].

## AI and the Asymmetry of Defense

Aráoz framed his warning around a structural disadvantage in smart contract security, noting that defenders must catch every flaw while attackers need only one opening to succeed [1]. He attributed this shifting landscape to advanced technology, stating that "coding agents are superhuman at finding vulnerabilities" [1]. This perspective carries weight given Aráoz's history as a co-founder of OpenZeppelin, a firm established in 2015 to secure crypto systems [3]. The comments follow warnings from Anthropic regarding its Claude Mythos AI model, which can autonomously uncover software vulnerabilities and create exploits [2].

## A Brutal Month for Protocol Security

The backdrop to Aráoz's statement is a series of high-value exploits. In April 2026, nearly $630 million was drained from DeFi protocols, with Kelp DAO losing around $293 million, Drift suffering roughly $285 million in losses, and Euler losing about $197 million [1]. Exploits continued into May, including an $11.6 million loss at Verus Network and a $573,200 breach at Polymarket [1]. CoinDesk reports that more than $1.1 billion has been lost to DeFi hacks since the previous year [2]. Consequently, the market has seen capital flight, with total value locked dropping by more than $20 billion since the start of the year [2].

## Why it matters

The declaration from a leading security figure highlights a potential crisis of confidence in decentralized finance. As trust erodes, the industry faces pressure to evolve beyond traditional security models. OpenZeppelin responded to these threats on May 12 by releasing its "Four Layers of DeFi Risk" framework, which emphasizes that audits are no longer enough and calls for continuous threat monitoring and layered defenses [1]. For institutional players, this shift suggests that due diligence must now include evidence of live monitoring and insurance, rather than relying solely on historical audit reports [3]. The tension between the need for open, interoperable systems and the demand for institutional-grade security remains a central challenge for the sector's future [2].

## Sources
1. En — [DeFi security risks: OpenZeppelin co-founder warns “all of DeFi”](https://en.cryptonomist.ch/2026/05/27/defi-security-risks-all-defi-unsafe/)
2. Pymnts — [Security Chief Warns of AI’s Outsized Threat to DeFi | PYMNTS.com](https://www.pymnts.com/cybersecurity/2026/security-chief-warns-of-ais-outsized-threat-to-defi/)
3. Crypto Briefing — [OpenZeppelin founder warns all of DeFi is unsafe amid security breaches](https://cryptobriefing.com/openzeppelin-founder-defi-unsafe-warning/)

---
Cite as: TrendWatcher, "Security Pioneer Warns All DeFi Is Unsafe", https://www.trendwatcher.in/article/6a0931e5-3cd1-4e66-813d-97400570bd5d
