S&P Global, the company behind one of the world’s most famous credit rating agencies, has agreed to acquire OpenZeppelin — the firm whose open-source code quietly guards a large share of the DeFi world — in a deal that signals Wall Street now sees smart contract security as core financial infrastructure.
By Jordan Lee | September 17, 2026
The Hook: The Rating Agency Buys the Code Auditors
According to S&P Global’s Sept. 17 announcement, the acquisition expands the financial data and ratings provider’s digital asset business into smart contract and onchain technology risk assessment. Financial terms were not disclosed, and the deal remains subject to closing conditions. S&P Global said it does not expect a material effect on its financial results.
If you have ever used a major stablecoin, a tokenized fund or a popular DeFi protocol, there is a good chance OpenZeppelin’s work was involved behind the scenes. Founded in 2015, the company develops open-source smart contract software — think of it as pre-built, battle-tested building blocks that developers use instead of writing risky code from scratch — and provides security audits that check protocols for holes before hackers find them.
The Numbers Behind the Deal
- More than 37 trillion USD in value has been transferred across infrastructure using OpenZeppelin’s smart contracts, including systems supporting major stablecoins and tokenized funds.
- Over 900 security engagements completed for blockchain protocols and financial institutions.
- More than 10,000 vulnerabilities identified before projects reached production.
OpenZeppelin will keep operating under its own name as a separate S&P Global business unit. CEO Demian Brener stays in charge and will report to S&P Global Ratings President Yann Le Pallec. Critically for developers, the company committed that its open-source Contracts library — the free toolkit relied on across the industry — will remain open source permanently, with future versions released under the same model.
Why Security Is Suddenly So Valuable
The purchase price may be undisclosed, but the motivation is not. Crypto security losses reached 1.1 billion USD across 212 verified incidents in the first half of 2026, according to a Blockaid report, which described the number of incidents as a record. Even more telling: roughly 74 percent of stolen funds came from operational security failures rather than exploited smart contract code.
Institutional attitudes are shifting accordingly. Research cited in a July report found that compromised keys, signers and infrastructure accounted for 88.3 percent of approximately 764 million USD stolen in the second quarter, while only 4 percent of tracked projects combined audits, active bug bounty programs and third-party monitoring. Investors are increasingly demanding continuous monitoring instead of one-time audits — exactly the expertise S&P Global is buying.
The acquisition also follows a warning from within the company itself. OpenZeppelin co-founder Manuel Aráoz said in May that advances in AI coding agents had tipped the balance toward attackers, and that he had advised friends and family to exit DeFi positions as exploit concerns intensified. For context, Bitcoin trades around 76,600 USD and Ethereum near 2,464 USD at the time of writing, per CoinGecko data — a market where institutional inflows depend heavily on trust in the underlying code.
Part of a Bigger Digital Asset Push
The OpenZeppelin deal is not an isolated move. On Sept. 14, S&P Global led a strategic investment in Paris-based crypto market data provider Kaiko, extending its Series B round to 110 million USD with participation from BNP Paribas, Coinbase Ventures, Nasdaq Ventures, Royal Bank of Canada and Stellar. The two companies had already launched co-branded S&P Kaiko Digital Asset Indices, and earlier work extended to tokenizing the iBoxx U.S. Treasuries index on Canton Network.
S&P Global has also been building its own crypto risk products. Its Stablecoin Stability Assessments score stablecoins on reserves, governance, liquidity and regulation, and through a Chainlink partnership announced in October 2025 those scores were made available onchain, starting with Coinbase’s Base network. In August, S&P Ratings assigned its top AAAm principal stability fund rating to a BlackRock tokenized money market fund.
What This Means For You
For everyday investors, the signal is bigger than one acquisition. The same firm that grades corporate bonds and national debt is buying the tools to grade smart contracts. That is a step toward the kind of independent, trusted risk assessment that traditional finance has relied on for a century — now aimed at the protocols holding your stablecoins and tokenized funds.
The open-source commitment matters too. If OpenZeppelin’s free libraries stay public and well-maintained under new ownership, smaller developers keep access to secure building blocks, raising the safety floor across the entire DeFi ecosystem. If institutions get better security tools, retail users benefit from the same protected infrastructure by default. On both counts, this deal is quietly bullish for trust in onchain finance.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
s and p could not rate the assets so they bought the auditors instead. most wall street move of the year
The open source library staying permanently free is the only part that matters here. Half of DeFi would have a supply chain problem overnight if that changed
agreed on the library point, and Brener staying as ceo reporting into the ratings president tells you oss is the strategic asset here
The free Contracts library is the loss leader here. Defender and the audit pipeline are where S&P will actually extract margin, watch those subscription prices creep
Defender price creep is basically guaranteed. first year its unchanged, year two its enterprise tiers
year two enterprise tiers is generous, id say mid year one. s&p does not buy recurring revenue to leave it flat
defender creep is the obvious play but bundling contract scores into credit ratings is the real one. imagine a bond spread priced partly on openzeppelin audit history lol
contract risk scores showing up inside bond spreads is the endgame. ratings desks have priced worse information for decades lol
permanently free until a product manager finds a growth lever in it. MIT license protects the fork but not the maintenance
a fork without maintenance is a graveyard tho. half the OZ forks on github died at v4. the library staying alive IS the product, MIT license or not
half those forks died at v4 because nobody paid the maintainers. under s&p the team actually gets fed, the repo probably outlives everything else in defi
^ exactly. security was always the real product, wall street just finally priced it
undisclosed price for the firm guarding 37 trillion in contracts. someone did that math at s and p and decided we never see it lol
if the number ever leaks it probably rivals a mid tier exchange acquisition. 900 audits of recurring clients is a cash machine
900 audits and 10k vulnerabilities caught before production. s and p just bought the closest thing defi has to a UL certification
openzeppelin contracts sit inside basically every major stablecoin deployment and the price of that critical infrastructure is a state secret. cool cool
S&P buying the shop that guards 37 trillion in smart contracts. the auditors got acquired by the raters, wild timeline
OpenZeppelin going from open source guardian to S&P subsidiary makes me nervous. What happens to the Contracts library now?
^ real question. if the oss repo gets paywalled or stagnates, half of defi inherits that risk silently
Brener reporting into the ratings president answers some of this. You do not put an OSS library under the ratings org unless you plan to feed it deal flow
putting brener under the ratings president also builds a conflict, s&p would be auditing protocols its own parent scores. that part nobody wants to discuss
Terms not disclosed and no material impact on results. So either pocket change for S&P or they just dont want us doing the math on what security talent costs these days.
security acquisitions never get disclosed. if OZ revenue is mostly Defender subs the multiple would make every founder cry anyway
wall street slowly buying up every piece of crypto plumbing, one quiet acquisition at a time. notes taken
37 trillion guarded and the price stays secret. the only number S&P ever refused to rate lmao
S&P just bought the pipeline that caught 10k vulnerabilities before production. bundle security ratings with credit ratings and print
Deal lands the same week the SEC hands tokenized stock venues a five year runway. S&P just bought the inspection layer for that entire market before it even scales.