Skip to main content
AVOID.NET

OpenZeppelin AI Exploit Threat Vector

avoid.net/openzeppelin-ai-exploit-threat-vector→15/100·82% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →

anchored·5QTW2H…ziZW
last updated 2026-05-28

Summary

On May 26, 2026, Manuel Aráoz, co-founder of smart contract security firm OpenZeppelin, issued a public warning on X declaring that he considers 'all of DeFi unsafe,' citing the emergence of AI coding agents that are 'superhuman' at discovering and weaponizing smart contract vulnerabilities. The warning coincided with more than $1.1 billion lost to DeFi hacks in the prior 12 months and was substantiated by Anthropic research published in late 2025 demonstrating that frontier AI models can autonomously exploit known smart contract vulnerabilities at scale. This entry tracks the AI-assisted DeFi exploit surface as a forward-looking threat category, documenting the evidence base, industry response, and structural security asymmetry that Aráoz and corroborating researchers describe.

Connected Entities

11 entities · 60 linked investigations
Organizations
□KelpDAO Bridge Exploit (April 2026)□TraderTraitor / UNC48990□Kelp59□Drift52□OpenZeppelin AI Exploit Threat Vector□LayerZero Labs□Solana89
Protocols
⌂Drift Protocol18⌂Uniswap93⌂LayerZero — DVN Single-Verifier Configuration Risk
Tokens
Relationships
  • KelpDAO Bridge Exploit (April 2026)→mentioned with→Kelp(70%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→Drift(85%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→Coinbase(60%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→Kelp(70%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→Uniswap(60%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→Solana(65%)
  • TraderTraitor / UNC4899→mentioned with→Drift(85%)
  • OpenZeppelin AI Exploit Threat Vector→mentioned with→LayerZero — DVN Single-Verifier Configuration Risk(60%)
  • LayerZero — DVN Single-Verifier Configuration Risk→mentioned with→TraderTraitor / UNC4899(75%)
  • KelpDAO Bridge Exploit (April 2026)→mentioned with→LayerZero — DVN Single-Verifier Configuration Risk(80%)
  • + 19 more
Have evidence about OpenZeppelin AI Exploit Threat Vector?

Timeline(7 events)

2 December 2025

MATS/Anthropic Fellows researchers publish SCONE-bench findings showing frontier AI models achieve greater than 51% autonomous exploitation rate on real-world smart contracts, with simulated exploit revenue doubling every 1.3 months.

OECD.AI / Anthropic Red Team

31 January 2026

Step Finance confirms $27.3 million treasury theft via compromised executive device and private key exposure. Protocol subsequently shuts down operations.

CoinDesk

April 2026

Drift Protocol suffers $285 million exploit on Solana, attributed to a six-month DPRK social engineering campaign. Attackers obtained pre-signed transactions from Security Council members to gain admin control.

Bloomberg / TRM Labs

8 April 2026

Anthropic releases Claude Mythos Preview to a restricted set of security partners via Project Glasswing. Internal and UK AI Security Institute evaluations document 181 working exploit scripts produced autonomously versus 2 for predecessor model.

Anthropic Red Team

18 April 2026

KelpDAO bridge exploit drains 116,500 rsETH (approximately $292 million) via LayerZero message spoofing, traceable to a social engineering compromise of a developer that began March 6, 2026. Attributed to Lazarus Group / TraderTraitor.

CoinDesk / Chainalysis

26 May 2026

Manuel Aráoz posts on X declaring 'all of DeFi unsafe,' citing AI coding agents as 'superhuman' at finding smart contract vulnerabilities and referencing Anthropic's Claude Mythos. Advises friends and family to exit all DeFi positions including Aave, MakerDAO, and Compound.

CoinDesk / The Block

27 May 2026

OpenZeppelin current leadership under CEO Demian Brener distances company from Aráoz's remarks, stating his views do not represent OpenZeppelin's position. Marc Zeller of Aave Chan Initiative publicly disputes the thesis, arguing fewer than 10% of 2025-2026 DeFi losses stemmed from code-level vulnerabilities.

CoinDesk / BeInCrypto
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓5/28/2026, 3:34:11 PM
    slot 422748373 · hash ENBQrEjMjrC6GYFhc9gPXrE2cvr398Y19pX6LHrdHJzP

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 29 of 31 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 5/28/2026, 3:07:09 PM

last updated: 5/28/2026, 3:07:09 PM

4 views

avoid.net — verified advice for a post-truth world