On May 26, 2026, Manuel Aráoz — co-founder and former CTO of OpenZeppelin, the firm that practically wrote the book on smart contract auditing — posted a message that sent shockwaves through the decentralized finance community. “I now consider *all* of DeFi unsafe,” he wrote. “Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds.” He went further, advising friends and family to exit positions in blue-chip protocols like Aave, MakerDAO, and Compound. With Bitcoin trading near $76,000 and the total value locked in DeFi having fallen from $172 billion in mid-April to $148 billion, the warning landed at a moment of acute market stress.
The Threat Landscape
The numbers backing Aráoz’s warning are stark. Over the past year, more than $1.1 billion has been lost to DeFi exploits. April 2026 alone accounted for $635 million across 28 reported hacks. The Verus DeFi protocol lost $11.58 million through a bridge exploit on Ethereum, where an attacker funded their wallet through Tornado Cash before draining tBTC, ETH, and USDC. But the real concern is not any single exploit — it is the structural shift in how vulnerabilities are discovered and weaponized.
Research from venture capital firm a16z validates the accelerating offensive capability of AI agents, noting that they have consistently identified core vulnerabilities in historical DeFi exploits. Even when agents failed to complete an exploit end-to-end, they often reached the stage that gives attackers a starting point. The implication is clear: a tool that reliably identifies weak points dramatically reduces the expertise barrier to launching an attack.
Anthropic has taken the extraordinary step of restricting public access to its unreleased Claude Mythos model precisely because of its capacity to autonomously discover and weaponize software flaws. When one of the world’s leading AI companies voluntarily limits its own product, the threat level speaks for itself.
Core Principles
The asymmetry Aráoz describes is fundamental. DeFi protocols are open-source by design — their code, governance structures, and integrations are publicly auditable. This transparency is a feature, not a bug, but it also means that AI agents can study every line of code around the clock, at machine speed, for near-zero marginal cost. Human auditors, no matter how skilled, cannot match that coverage.
However, OpenZeppelin itself has pushed back on the most alarmist reading of Aráoz’s warning. The security firm noted that most large losses in recent months have stemmed from operational failures rather than flaws in audited contract code — stolen private keys, bridge spoofing, social engineering, and access control breakdowns. This distinction matters enormously for how individual investors should respond.
The first core principle, then, is separating protocol risk from operational risk. A flawlessly audited smart contract is useless if the deployer key is compromised. A battle-tested bridge is meaningless if the team falls for a social engineering attack. Defense must be holistic.
Tooling & Setup
For investors who choose to remain active in DeFi despite the elevated threat environment, a layered security approach is essential. Start with hardware wallets from established manufacturers — never sign transactions from a hot wallet holding significant funds. Enable multi-signature governance on any protocol treasury you control. Use hardware security keys for two-factor authentication on every exchange and DeFi dashboard.
For protocol operators, the tooling requirements have escalated. Continuous monitoring platforms that flag unusual transaction patterns in real time are no longer optional — they are baseline infrastructure. Bug bounty programs need to offer competitive rewards that match the potential haul from an exploit. Formal verification of smart contract logic, once a nice-to-have, should now be standard for any protocol managing more than nine figures of TVL.
The emergence of AI-powered defense tools offers a potential counterweight. Several security firms now deploy adversarial AI agents that continuously probe their clients’ own contracts, simulating attack vectors before malicious actors can discover them. This red team approach at machine speed represents the most promising path toward restoring equilibrium between attackers and defenders.
Ongoing Vigilance
The Crypto Fear and Greed Index sits at 34 as of May 26, deep in Fear territory. Bitcoin’s implied volatility has fallen to 36 percent, an eight-month low, suggesting the market expects range-bound price action in the near term. But low volatility often masks accumulating leverage — current derivatives data shows that a break above $80,447 would trigger $1.245 billion in cumulative short liquidations across major centralized exchanges, while a drop below $73,416 would liquidate $739 million in longs.
This leverage backdrop means that any security incident — a major exploit, a governance attack, a bridge failure — can cascade through the market far faster than in previous cycles. Maintaining reduced exposure, setting strict stop-losses, and keeping emergency exit plans updated are not paranoid precautions; they are prudent risk management.
For those following Aráoz’s advice and reducing DeFi exposure, consider that Bitcoin itself, held in self-custody, eliminates smart contract risk entirely. The trade-off is opportunity cost — you miss yield — but in an environment where AI agents can find and exploit vulnerabilities faster than human auditors can patch them, capital preservation deserves a higher weighting in the risk-reward calculus.
Final Takeaway
The debate between Aráoz and his critics is not really about whether DeFi is safe or unsafe — it is about the rate of change in the threat landscape. The tools available to attackers have improved dramatically in 2026, and the defensive ecosystem is racing to catch up. Whether you choose to exit DeFi entirely or stay active with enhanced precautions, the worst possible response is complacency. The security assumptions that held in 2024 do not hold today. Recalibrate accordingly.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making investment decisions.
araoz says all defi unsafe and honestly hard to argue. ai agents finding vulns at superhuman speed
1.1B lost past year. april alone was 635M across 28 hacks. the numbers are getting worse
verus lost 11.58M through a bridge. defi tvl down to 148B from 172B in weeks
araoz built openzeppelin and even hes saying get out. thats not fud thats the guy who wrote the security standards telling you the game changed
manuel built the tools everyone uses and hes calling it. when the person who wrote the audit framework says get out, maybe listen
bruno_dev_ Manuel wrote the framework and hes still saying AI agents will outpace auditors. if the guy who built OpenZeppelin is pulling his friends out of Aave and MakerDAO thats a signal not noise
araoz wrote the OpenZeppelin audit standards and hes pulling his own money out. when the architect leaves the building you should probably leave too
$635 million in April alone across 28 hacks. that number should be the headline on every crypto site, not the BTC price
Katrin J. $635M in April across 28 hacks and BTC price still gets more headline space. priorities in this space are completely backwards
Araoz built the audit tools everyone uses and still says get out. defenders fix every bug, attackers need one. thats not a risk model thats a countdown
defenders need to fix every bug, attackers need one. thats the whole problem in one sentence tbh
defenders need to fix every bug, attackers need one. that asymmetry existed before AI agents. AI just made finding the one bug 100x faster
Noa R. the asymmetry existed before AI but now defenders literally cannot keep up. a human auditor finds 80% of bugs, an AI agent finds 99.9% and the 0.1% is what attackers use
1.1 billion lost in a year and people still ape into unaudited protocols. the asymmetry araoz describes is exactly why
Tilde N. when the person who co-founded OpenZeppelin and literally built the audit tools everyone uses says get out of DeFi you listen. $1.1B lost in a year is not a drill
araoz_right_ the guy who literally wrote the OpenZeppelin audit checklist saying get out is the loudest signal in DeFi history. defenders cant keep up with AI powered exploit discovery
advising friends and family to exit Aave and MakerDAO is a big deal coming from someone at that level
the verus exploit using tornado cash to fund the wallet is just the standard playbook at this point. mixers gonna mixer
hash_viper_ Verus losing $11.58M through a bridge exploit funded by Tornado Cash is the standard playbook now. mix in, drain tBTC and ETH and USDC, mix out. bridges remain the weakest link
Verus losing 11.58M through a Tornado Cash funded wallet is the same pattern as every bridge exploit since 2021. mixers are the escape hatch that makes prosecution impossible
635M in April across 28 hacks and BTC price still dominates headlines. araoz built the audit standards everyone uses and hes pulling his own money out. thats not fud
fork_auditor_ the Verus exploit funded through Tornado Cash is the part that should scare people. the attack tooling is mature and the defense side is still catching up
Liesl B. Tornado Cash funding is the standard pre-exploit step now. the defense side cant even track incoming attacks because mixers are legally contested
1.1B lost in a year and AI agents are only getting started. formal verification is the only real defense but fewer than 20 protocols actually use it
Rasmus B. formal verification catches invariant bugs but the Verus exploit was a bridge logic flaw not an invariant. different attack class entirely