Coin Bureau's Lewis breaks down why the co-founder of OpenZeppelin, the firm behind the code securing most of DeFi, just declared the entire space unsafe and told his own family to pull their money out.
Key Points
Key Highlights:
- Manuel Aros built the security infrastructure underneath roughly $250 billion in protocols, yet he is now privately telling friends and family to exit blue chip names like MakerDAO and Compound entirely
- AI agents from Anthropic and OpenAI successfully reproduced 51% of real world exploits in a benchmark of 405 hacked contracts, even cracking 19 of 34 contracts they had never seen before
- April 2026 was the worst month for DeFi exploits in four years, with hacks landing on 27 of 30 days and $630 million drained, an outcome Certik called only possible with AI
- The Kelp DAO hack stole $292 million through a bridge misconfiguration, not a flaw in Aave's own code, yet it still triggered an $8.45 billion bank run and wiped out 45% of Aave's total value locked in 30 days
- Defenders argue loss rates as a percentage of total value locked have actually dropped from 7.24% in 2022 to a projected 1.49% in 2026, suggesting DeFi is getting safer not more dangerous
- The fix everyone is quietly adopting is centralized oversight, security councils with admin keys that can freeze funds, which is exactly the kind of trusted third party DeFi was built to eliminate
Takeaway The asymmetry has not changed, attackers only need one win while defenders need to be perfect everywhere. AI just made finding that one win dramatically cheaper and faster. The industry's answer so far is adding humans back into the loop, which does not close the gap, it just moves it somewhere else.