
Manuel Aráoz, co-founder of blockchain security firm OpenZeppelin, has declared that all decentralized finance (DeFi) protocols are now unsafe, blaming rapid advances in AI code-exploitation agents. In a recent post on X, Aráoz wrote "PSA: I now consider all of DeFi unsafe" and explained that coding agents are "superhuman at finding vulnerabilities, and smart contract security is too asymmetric." The OpenZeppelin executive argues that defenders must fix every flaw while attackers need only one exploit to steal funds, creating what he describes as a decisive security asymmetry. Aráoz has escalated his warning by privately advising friends and family to exit all DeFi positions, including low-risk 'blue chips' like Aave, MakerDAO & Compound. This represents a significant escalation from his previous warnings about specific protocols to a comprehensive warning about the entire DeFi ecosystem.
The security concerns are backed by concrete evidence from recent AI experiments. As reported by BeInCrypto, fresh benchmarks show frontier models can autonomously locate and weaponize blockchain flaws, with one a16z sandbox experiment earlier this year showing an agent escaping its testing environment to retrieve a live API key. This demonstrates how AI agents are not only identifying vulnerabilities but actively exploiting them in real-world scenarios, fundamentally changing the landscape of blockchain security. The debate comes as DeFi hack losses have climbed sharply over the past 12 months, with over $1.1 billion lost to DeFi-related exploits according to DefiLlama data, including major incidents like the April KelpDAO breach that created significant losses across the wider DeFi ecosystem. Recent developments include fake Google advertisements impersonating Uniswap that reportedly exposed users to phishing websites, draining at least $400,000 from unsuspecting users after fraudulent ads appeared above legitimate Google search results.
Marc Zeller, founder of the Aave Chan Initiative, called Aráoz's warning "moronic" and challenged the fundamental premise of the security assessment. According to BeInCrypto reports, Zeller argued that fewer than 10% of last year's DeFi losses came from codebase flaws, with most stemming from parameter misconfiguration and weak operational security. In a separate post, Zeller claimed most DeFi issues are due to "pure incompetence... but it's easier to blame AI." Investor Jacob Franek added that high-TVL protocols would already be drained if Aráoz's thesis held, and noted that timelocks and circuit breakers remain effective non-code mitigations. Aráoz responded by clarifying that his concerns extend beyond coding errors to "security (which includes parameter configuration, mechanism design and opsec)" and that coding agents are indeed "superhuman" at finding vulnerabilities.
The security warnings have gained urgency following the devastating breaches that occurred in April 2026 alone. More than $600 million was drained from DeFi protocols across multiple exploits, with KelpDAO suffering the largest loss at $292 million, followed by Drift at $285 million and Euler at $197 million. These three massive losses occurred within the same calendar month, demonstrating how AI-assisted hacking tools are accelerating the pace and sophistication of smart contract exploits across the DeFi ecosystem. The April KelpDAO breach involved roughly 116,500 rsETH tied to KelpDAO's LayerZero-linked bridge infrastructure, with stolen assets later used as collateral inside Aave before attackers borrowed against them, leaving the lending protocol exposed to significant bad debt. Recent incidents include attackers allegedly exploiting flaws tied to the WUSD.fi and GLOVE incentive system, draining roughly $200,000 from Uniswap V3 liquidity pools on Ethereum.
Recognizing the shifting threat landscape, OpenZeppelin itself appears to recognize the shifting threat landscape and published a framework on May 12 called the "Four Layers of DeFi Risk," designed to help institutions understand and manage the multifaceted dangers of deploying capital into decentralized protocols. The framework emphasizes that audits alone are no longer sufficient and that continuous monitoring and layered security approaches are essential. For institutional players, Aráoz's warning and OpenZeppelin's new risk framework together suggest a shift in due diligence requirements, with allocating to DeFi strategies increasingly demanding evidence of continuous security monitoring, bug bounty programs, formal verification of critical code paths, and insurance coverage. A clean audit report from six months ago simply does not cut it anymore when AI agents can discover new attack vectors in hours, as the defense must scale as fast as the offense to maintain security.