3 Sources
[1]
Crypto Security Pioneer: 'I Now Consider All of DeFi Unsafe'
Crypto projects in the decentralized finance (DeFi) sector have faced a wave of security incidents lately, and now, one of the earliest figures in smart contract auditing has declared the entire DeFi space unsafe. This point of view was shared on X by Manuel Aráoz, co-founder of OpenZeppelin. He
[2]
DeFi Security Split Widens as AI-Linked Threats Fuel Debate
AI-linked threats in DeFi spark debate after major losses and ongoing exploits, with experts split on whether the sector is breaking or adapting to rapidly advancing attack capabilities. Warnings that artificial intelligence is reshaping decentralized finance (DeFi) security are dividing the
[3]
No DeFi Is Safe Anymore, Warns Top Crypto Security Executive -- Why Is He Urging Everyone To Exit Positions?
Aráoz said he has advised friends and family to exit even major DeFi protocols, including Aave, MakerDAO, and Compound. A growing debate over the role of AI in crypto security erupted this week after leading security developer Manuel Aráoz warned that decentralized finance may no longer be safe
Share
Copy Link
Manuel Aráoz, co-founder of OpenZeppelin, has declared all of DeFi unsafe, citing AI-powered coding agents that excel at finding smart contract vulnerabilities. His warning follows April's record-breaking month of crypto hacks and over $1.1 billion in DeFi losses in the past year. The claim has split the crypto community, with some arguing AI is reshaping security while others say most exploits stem from operational failures, not code flaws.
Manuel Aráoz, co-founder of OpenZeppelin and a pioneer in smart contract auditing, has sent shockwaves through the crypto community by declaring that he now considers all of DeFi unsafe
1
. In a stark warning posted on X, Aráoz revealed he has been privately advising friends and family to exit all DeFi positions, including what many consider low-risk blue chips such as Aave, MakerDAO, and Compound1
. His reasoning centers on advances in artificial intelligence that have fundamentally altered the DeFi security landscape. "Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds," he explained1
.
Source: Cointelegraph
The core of Aráoz's concern lies in the rapid advancement of AI agents finding vulnerabilities in crypto smart contracts. Late last year, Anthropic released data showing AI agents had become far more capable at spotting and potentially exploiting bugs in smart contracts
1
. The situation escalated with the release of Anthropic's Mythos model earlier this year, a system so powerful that Anthropic keeps it under tight restrictions and makes it available only to a limited group of partners1
. According to Anthropic, the Mythos model has uncovered critical bugs in software that had run in production environments for decades without anyone noticing the flaws1
. Due to the security implications for the crypto space, exchanges such as Coinbase have reportedly reached out to Anthropic to gain access to Mythos1
. Yu Xian, founder of blockchain security firm SlowMist, highlighted a "dual threat" from AI-empowered attackers, including black-hat hackers using AI tools and organized groups skilled in social engineering2
.The warnings come as DeFi hacks have surged dramatically, with April standing out as the worst month on record for the sheer volume of crypto hacks, with incidents occurring at a pace of nearly one per day
1
. According to DefiLlama data, over $1.1 billion has been lost to DeFi-related exploits during the past year alone3
. One of the largest incidents occurred in April when attackers exploited KelpDAO infrastructure involving roughly 116,500 rsETH tied to KelpDAO's LayerZero-linked bridge infrastructure3
. The stolen assets were later used as collateral inside Aave before attackers borrowed against them, leaving the lending protocol exposed to significant bad debt3
. Just this past weekend, stablecoin issuer StablR saw its system compromised when an attacker gained control of one key in a 1-of-3 multisignature wallet, minting roughly $13.5 million in unbacked stablecoins and walking away with around 1,115 ether, valued near $3 million at the time1
.
Source: CCN.com
Related Stories
Aráoz's declaration has sparked intense debate within the crypto community, with prominent figures pushing back sharply against his assessment. Marc Zeller, founder of the Aave Chan Initiative, called Aráoz's position "a moronic thing to say," noting that less than 10% of DeFi issues in the past year stemmed from the actual codebase
1
. According to Zeller, most recent failures have been tied to bad parameter configuration, collateral blow up, and poor opsec3
. Some critics went further and labeled Aráoz's comments as nothing more than fear marketing for the benefit of OpenZeppelin1
. It should be noted that OpenZeppelin took to X to clarify that Aráoz's comments do not match the company's official position on this matter, as Aráoz left the company in 20191
. Aave founder Stani Kulechov pointed out that the same AI tools being used by attackers can also be used for defense mechanisms, which should make these systems even more resilient and secure over time1
.Despite the controversy, security experts agree that the threat landscape has fundamentally changed. Meir Dolev, co-founder and chief technology officer of blockchain security platform Cyvers, told Cointelegraph that DeFi remains uniquely exposed because its code is public, funds move instantly, contracts are composable, and attackers "only need one mistake to succeed"
2
. However, Dolev says abandoning DeFi is not the practical answer, urging that the focus should shift away from periodic audits toward continuous, real-time security detection2
. He outlined measures such as AI-assisted code review, regular red-team exercises, DevOps hardening, stronger key management, real-time transaction simulation, and pre-signing risk scoring2
. Yu Xian from SlowMist said DeFi project teams should urgently adopt advanced AI tools to detect security risks in live code and DevOps processes, while also running regular checks covering both on-chain and off-chain attack paths2
. Uttam Singh, senior developer relations engineer at blockchain infrastructure provider Alchemy, called for circuit breakers, timelocks on changes, security councils with emergency halt powers, and rate limits on new asset listings1
. The fallout has been especially visible on Aave, where total value locked has fallen sharply since the April exploit, dropping from roughly $26.4 billion to around $14.6 billion within weeks3
.Summarized by
Navi
[2]
15 May 2026•Technology

02 Dec 2025•Technology

17 Apr 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology