OpenZeppelin AI Exploit Threat Vector
Summary
On May 26, 2026, Manuel Aráoz, co-founder of smart contract security firm OpenZeppelin, issued a public warning on X declaring that he considers 'all of DeFi unsafe,' citing the emergence of AI coding agents that are 'superhuman' at discovering and weaponizing smart contract vulnerabilities. The warning coincided with more than $1.1 billion lost to DeFi hacks in the prior 12 months and was substantiated by Anthropic research published in late 2025 demonstrating that frontier AI models can autonomously exploit known smart contract vulnerabilities at scale. This entry tracks the AI-assisted DeFi exploit surface as a forward-looking threat category, documenting the evidence base, industry response, and structural security asymmetry that Aráoz and corroborating researchers describe.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2025-12-02
MATS/Anthropic Fellows researchers publish SCONE-bench findings showing frontier AI models achieve greater than 51% autonomous exploitation rate on real-world smart contracts, with simulated exploit revenue doubling every 1.3 months.
OECD.AI / Anthropic Red Team2026-01-31
Step Finance confirms $27.3 million treasury theft via compromised executive device and private key exposure. Protocol subsequently shuts down operations.
CoinDesk2026-04-01
Drift Protocol suffers $285 million exploit on Solana, attributed to a six-month DPRK social engineering campaign. Attackers obtained pre-signed transactions from Security Council members to gain admin control.
Bloomberg / TRM Labs2026-04-08
Anthropic releases Claude Mythos Preview to a restricted set of security partners via Project Glasswing. Internal and UK AI Security Institute evaluations document 181 working exploit scripts produced autonomously versus 2 for predecessor model.
Anthropic Red Team2026-04-18
KelpDAO bridge exploit drains 116,500 rsETH (approximately $292 million) via LayerZero message spoofing, traceable to a social engineering compromise of a developer that began March 6, 2026. Attributed to Lazarus Group / TraderTraitor.
CoinDesk / Chainalysis2026-05-26
Manuel Aráoz posts on X declaring 'all of DeFi unsafe,' citing AI coding agents as 'superhuman' at finding smart contract vulnerabilities and referencing Anthropic's Claude Mythos. Advises friends and family to exit all DeFi positions including Aave, MakerDAO, and Compound.
CoinDesk / The Block2026-05-27
OpenZeppelin current leadership under CEO Demian Brener distances company from Aráoz's remarks, stating his views do not represent OpenZeppelin's position. Marc Zeller of Aave Chan Initiative publicly disputes the thesis, arguing fewer than 10% of 2025-2026 DeFi losses stemmed from code-level vulnerabilities.
CoinDesk / BeInCryptoDecision Log
- hash: ENBQrEjMjrC6GYFhc9gPXrE2cvr398Y19pX6LHrdHJzP
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-code-investigator
generated: 5/28/2026, 3:07:09 PM
last updated: 5/28/2026, 3:34:11 PM
avoid.net — verified advice for a post-truth world