Top Audit Expert Warns: All DeFi is Unsafe, Withdraw Now!

marsbitPublié le 2026-05-28Dernière mise à jour le 2026-05-28

Résumé

A leading DeFi security expert has issued a stark warning: all DeFi is now unsafe. Manuel Aráoz, founder of major security audit firm OpenZeppelin, stated on X that he is advising friends and family to withdraw funds from major protocols like Aave, MakerDAO, and Compound. The core reason for this drastic shift is the rise of AI. Aráoz argues that AI-powered coding agents can now identify and exploit smart contract vulnerabilities at an exponentially faster rate. This turns DeFi's transparency into a liability, providing a vast training dataset for attackers. The fundamental asymmetry of security—where defenders must patch every flaw, but attackers need only find one—is being catastrophically unbalanced by AI. Recent months provide chilling evidence. April saw massive exploits, including a $280 million loss at Drift Protocol and a $292 million theft from Kelp DAO. The trend continued into May with multiple high-value attacks on protocols like THORChain, Verus, Echo Protocol, and StakeDAO, demonstrating vulnerabilities across both on-chain code and off-chain management. AI acts as a force multiplier for hackers, enabling near-instantaneous vulnerability scanning, automated exploit script generation, and sophisticated social engineering. The recent development of ultra-powerful AI models like Anthropic's Mythos—so advanced its public release was delayed over security fears—signals even greater threats ahead. The article concludes that the risk-reward calculus for DeFi partic...

Original | Odaily Planet Daily(@OdailyChina)

Author | Azuma(@azuma_eth)

“I believe all DeFi is now unsafe.”

This assertion left by OpenZeppelin founder Manuel Aráoz on X yesterday, like a depth charge, once again rocked the already stagnant DeFi market.

Manuel even stated that he has started advising friends and family to withdraw funds from major DeFi protocols, including blue-chip protocols like Aave, MakerDAO, and Compound, which were once considered low-risk.

This is not alarmism from an outsider. On the contrary, Manuel himself is one of the core builders of the DeFi security system, and OpenZeppelin is one of the industry's most mainstream security auditing firms. Its contract libraries, security standards, and audit frameworks have permeated nearly the entire DeFi world.

The reason for Manuel's complete shift in attitude lies in AI. Manuel pessimistically believes that the ability of AI Coding Agents to identify and exploit smart contract vulnerabilities is increasing exponentially.

This means that issues which previously required top-tier white-hat teams weeks to discover might now be scanned by AI in minutes; where hackers once needed long-term study of protocol logic, attack paths can now be analyzed automatically by AI; the "open and transparent" nature of DeFi, once an advantage, has now become the best training corpus for attackers.

Manuel also raised a more fatal problem: Smart contract security is essentially an extremely asymmetric game — the defense must patch all vulnerabilities, while the attacker only needs to find one to steal funds. As AI begins to exponentially enhance attack efficiency, this asymmetry is rapidly becoming unbalanced.

The Cold Reality: DeFi Has Become a Cash Cow for Hackers

Looking back at DeFi security incidents over the past few months, you'll find that Manuel's concerns are not exaggerated.

April was almost the worst month in DeFi's history.

  • On April 1st, April Fool's Day, Drift Protocol lost $280 million due to manager privilege hijacking and multi-signature execution vulnerabilities (details in "An April Fool's Joke? Drift Protocol Hacked for Over $280M, Potentially Becoming Solana Ecosystem's Second-Largest DeFi Heist").
  • Subsequently, on April 19th, Kelp DAO lost $292 million due to a bridge protocol breach (details in "DeFi Hacked Again for $292M, Is Even Aave Unsafe Now?"). The hacker later escaped via lending protocols like Aave, casting the shadow of bad debt and its cascading effects over the entire DeFi sector.

Entering May, incidents not only didn't decrease but further proliferated.

  • On May 15th, THORChain was attacked. A newly joined node operator exploited a vulnerability in the GG20 Threshold Signature Scheme (TSS), reconstructed the vault private key, and directly executed outbound transactions, causing over $10 million in losses.
  • On May 18th, Verus's bridge protocol was attacked. The attacker forged cross-chain import payloads, bypassed verification to extract assets from the Ethereum reserve, stealing approximately $11.58 million.
  • On May 19th, Echo Protocol on Monad was attacked due to a private key leak. The attacker minted 1,000 eBTC (worth $76.7 million) and extracted funds via Curvance using a previously tested attack path.
  • On May 24th, StablR, a compliant stablecoin issuer under the MiCA regulatory framework, was attacked. The hacker profited over $2.8 million by minting EURR and USDR, causing EURR and USDR to depeg.
  • On May 25th, the SquidRouter module was attacked, resulting in approximately $3 million in assets stolen from 86 Gnosis Safe wallets.
  • On May 27th, the StakeDAO deployer private key was leaked on Arbitrum. The attacker minted about 5.45 trillion vsdCRV and exchanged part of it for 43.7 ETH to escape.

The frequently occurring security incidents have sounded the alarm. DeFi seems to be collapsing across the board, from on-chain code to off-chain management.

AI Has Become the Hackers' Nuclear Weapon

Why has the DeFi offense-defense dynamic suddenly accelerated towards collapse this summer? Beyond the evolution of traditional hacking techniques, the rapid advancement of AI large language models is becoming the ultimate factor tipping the balance.

In the past, finding a complex smart contract vulnerability (especially those involving cross-chain, multi-layer nesting, or extremely hidden reentrancy logic) required top hackers weeks or even months of code review. However, with the maturity of AI agents possessing ultra-long context, strong logical reasoning, and autonomous tool-calling capabilities, this has changed fundamentally.

  • Second-Level Scanning and Global "Zero-Day" Vulnerability Mining: Attackers only need to feed the open-source codebase to the new generation of AI reasoning models. The AI can, within seconds, deduce hundreds of extreme interaction scenarios like a seasoned security expert, accurately pinpointing edge cases missed by human auditors during fatigue.
  • Automated Attack Script Generation: AI can not only discover vulnerabilities but also automatically write, test, and deploy the "hacker smart contracts" used to extract funds.
  • Perfect Orchestration of Off-Chain DevOps and Social Engineering: AI can impersonate perfect developers for phishing or monitor DeFi teams' GitHub commit logs around the clock. Once a team uploads code containing sensitive information or unverified fixes, the AI will launch an attack within seconds—far faster than any human security team's response time.

In this security warfare augmented by AI, hackers, armed with AI, possess nearly infinite ammunition and second-level attack speed. DeFi, however, is constrained by slow-paced governance voting, multi-signature confirmations, and lagging security audits, making it difficult to mount a corresponding defensive response.

Last month, Anthropic, the AI development company behind Claude, officially announced its next-generation model, Mythos (details in "Anthropic Creates the Most Powerful AI Model Ever, But Dares Not Release It..."). This is the first model in human history to break the hundred-trillion parameter threshold (in contrast, mainstream models currently range from hundreds of billions to one trillion parameters), with a staggering training cost of $10 billion.

However, due to Mythos's specialized capabilities in cybersecurity (Anthropic disclosed that using Mythos, they identified thousands of zero-day vulnerabilities in just a few weeks), Anthropic even dares not publicly release the model directly, for fear of malicious use by hacking groups. Instead, they plan to first allow leading large companies to test and preemptively patch potential vulnerabilities through a "Glasswing" initiative.

With the DeFi security situation already so severe at this stage, it's hard to imagine what new threats the industry's security defenses will face once Mythos is publicly released.

The Biggest Problem: Risk-Reward Ratio Has Long Been Unbalanced

For ordinary DeFi participants, liquidity providers (LPs), and whales, the most important question now is to sit down and calculate.

For a long time, the reason users chose to deposit funds into DeFi was to pursue annualized yields several times higher than those in traditional finance. During bull markets or the frenzy of liquidity mining, yields of 10%, 20%, or even higher were enough to cover people's psychological expectations for "potential technical risks."

But today, this underlying logic has long been shaken and even overturned. The risk-reward ratio of DeFi is already unbalanced. On the reward side, as the market enters a game of limited players and safety margins thicken, the real yields of most mainstream, relatively reliable DeFi protocols have fallen back to single-digit ranges. On the risk side, users' principal is exposed to a black box that could be breached by AI at any moment and emptied by a flash loan in an instant. Once a protocol is hacked, token prices plummeting to zero and liquidity pools being drained often happen within minutes, with no legal recourse, insurance, or central bank to provide coverage.

The risk of losing 100% of principal to chase roughly 5% annualized yield is clearly not a good deal.

Manuel's words may be somewhat absolute, but they tear off DeFi's last fig leaf. In the face of the reality where hackers have made AI a conventional weapon and security incidents continue to erupt in the industry, if you are not prepared for the psychological expectation of losing 100% of your principal for a certain yield, then "withdrawing funds as soon as possible and realizing profits" might be the most rational and risk-control-principled choice in the current market cycle.

Questions liées

QAccording to the article, what is the main reason Manuel Aráoz gives for his statement that all DeFi is unsafe?

AThe main reason is the exponential enhancement of AI Coding Agents in identifying and exploiting vulnerabilities in smart contracts, making it easier and faster for attackers to find and exploit flaws.

QWhat does the article highlight as the fundamental asymmetry in smart contract security?

AThe fundamental asymmetry is that defenders must fix all vulnerabilities to be secure, while attackers only need to find a single vulnerability to steal funds.

QWhy is the AI model 'Mythos' from Anthropic mentioned as a particular concern in the context of DeFi security?

AMythos is a concern because it has demonstrated a powerful specialization in cybersecurity, being able to identify thousands of zero-day vulnerabilities in a short time, which could be weaponized by hackers if publicly released.

QWhat is the article's conclusion about the risk-reward ratio for users participating in DeFi protocols currently?

AThe article concludes that the risk-reward ratio is imbalanced. The potential risk of losing 100% of principal now outweighs the relatively low single-digit percentage annual yields offered by many protocols.

QWhich two major DeFi protocols were specifically mentioned as examples from which Manuel Aráoz is advising friends and family to withdraw funds?

AAave and Compound were specifically mentioned as examples of previously considered low-risk blue-chip protocols from which he advises withdrawal.

Lectures associées

Bulletin de financement | Crypto.com obtient 400 millions de dollars d'investissement, les secteurs de la CeFi et des stablecoins continuent d'attirer des capitaux

**Résumé des Investissements Hebdomadaires (13-19 Juillet)** Le marché du financement crypto a connu une nette accélération la semaine dernière, avec 17 transactions totalisant plus de 812 millions de dollars, soit un doublement en nombre et en volume. Les secteurs de la finance centralisée (CeFi) et des stablecoins ont dominé les investissements. L'échange **Crypto.com** a levé 4 milliards de dollars auprès de Citadel Securities, portant sa valorisation à 200 milliards de dollars. **Alpaca** (infrastructure de courtage API) a levé 135 millions de dollars, tandis que **Flex** (plateforme bancaire transfrontalière basée sur des stablecoins) a obtenu 70 millions de dollars. **Velocity** (solutions de règlement par stablecoins) a sécurisé 38 millions de dollars. **Tether** a investi 20 millions de dollars dans la banque numérique argentine Ualá. Dans l'infrastructure financière, **ADI Chain** (règlement de stablecoins) a levé 50 millions de dollars, **Cyclops** (infrastructure de paiement par stablecoins) 20 millions de dollars, et **Pact Labs** (intégration de l'USDT dans les salaires) 7 millions de dollars dirigés par Tether. Le secteur DeFi a annoncé deux levées, dont **Quote Trade** (DEX axé sur l'IA) avec 4 millions de dollars. Un tour de table notable est celui de la plateforme de marché prédictif **Pascal**, qui a levé 9 millions de dollars. Parallèlement, le secteur IA/robotique reste très actif. L'entreprise de cloud IA **Fireworks** (soutenue par Nvidia) a levé 1.5 milliard de dollars, la startup de robots humanoïdes **Walden Robotics** (filiale de Toyota) 300 millions de dollars, et le fabricant chinois de robots humanoïdes **逐际动力 (Climber Robotics)** près de 200 millions de dollars dans un tour Pre-IPO. Enfin, plusieurs acquisitions ont eu lieu, notamment celle de l'échange singapourien **Coinhako** par le japonais SBI Holdings, et de la startup de dépôts crypto **Glide** par **MoonPay**.

marsbitIl y a 1 h

Bulletin de financement | Crypto.com obtient 400 millions de dollars d'investissement, les secteurs de la CeFi et des stablecoins continuent d'attirer des capitaux

marsbitIl y a 1 h

Le bear market le plus doux ? Les vendeurs de BTC délaissent le marché, ARK et Bitwise affichent un optimisme collectif

La volatilité demeure sur le marché des cryptomonnaies. Le bitcoin (BTC) évolue autour de 75 000 USD, tandis que l'ether (ETH) lutte pour maintenir 1 900 USD. Les liquidations à court terme ont principalement affecté les positions vendeuses. Les perspectives des institutions sont mitigées mais montrent des signes de retour de l'optimisme prudent. Polymarket estime à 33% la probabilité que le BTC passe sous 50 000 USD cette année. ARK Invest relève des signaux de tension vendeuse, avec une part historiquement élevée des BTC détenus à long terme. Bitwise qualifie ce ralentissement de "baissier structurellement le plus doux" jamais enregistré, notant que les creux de cycle sont de plus en plus hauts et que les investisseurs institutionnels voient les baisses comme des opportunités. D'un point de vue technique, Bit estime que le creux de la vague baissière (C) est probablement formé, une zone de fond idéale se situant entre 50 000 et 55 000 USD. Cependant, un analyste de Glassnode met en garde : si le BTC ne dépasse pas durablement 66 000 USD, un risque de sommet à court terme subsiste. L'analyste Darkfost identifie quant à lui une bande de soutien cruciale entre 59 000 et 70 000 USD. Signe notable d'un changement de sentiment, le trader Doctor Profit a annoncé avoir fermé toutes ses positions vendeuses sur les cryptos, réalisant d'importants bénéfices, et a recommencé à accumuler du BTC au comptant depuis 64 000 USD. Il estime que le marché anticipe trop uniformément un creux vers 40 000-50 000 USD à l'automne, ce qui pourrait ne pas se matérialiser.

Foresight NewsIl y a 1 h

Le bear market le plus doux ? Les vendeurs de BTC délaissent le marché, ARK et Bitwise affichent un optimisme collectif

Foresight NewsIl y a 1 h

Évolution de l'ordre à l'ère de l'IA et du Web3 : Dimensions concurrentielles et voies d'exploration de m&W

Nous traversons une ère de transformation profonde, passant de l'amélioration de la productivité à la refonte des relations de production. Les agents IA (intelligents) libèrent une capacité de production inédite. À l'avenir, les tâches seront de moins en moins accomplies par des individus isolés et de plus en plus par des réseaux collaboratifs mêlant humains et agents IA. Une question fondamentale émerge : comment établir des relations de confiance, évaluer des contributions complexes et créer des mécanismes de répartition de la valeur stables et équitables entre des humains et des agents IA étrangers en collaboration à long terme ? Si Web3 a posé les bases techniques pour les actifs, l'identité et l'organisation, l'ère des agents IA exige un système d'ordre nouveau intégrant identité, crédit, collaboration et incitations économiques. L'article analyse le positionnement de m&WDAO par rapport aux principales voies d'exploration actuelles : * **Colony** : se concentre sur la gouvernance et la collaboration **humaines** basées sur la contribution. * **SingularityNET (ASI)** : se concentre sur l'échange et la découverte **ouvertes des capacités de l'IA**. * **Gitcoin Passport / Verax** : se concentrent sur la **vérification de l'authenticité de l'identité** et la résistance aux sybils. * **Farcaster & Lens Protocol** : se concentrent sur les **réseaux d'information et d'identité ouverts**. Contrairement à ces approches, m&W explore une voie complémentaire et plus fondamentale : **comment construire un réseau de collaboration crédible entre humains et agents IA**. Son cheminement se structure en trois phases évolutives : 1. **m&W 1.0 : Ancrage du Crédit** – Sélection de "Builders" de haute qualité via un mécanisme d'impact ("proton collision"). Leurs contributions continues sont transformées en actifs de crédit non transférables (SBT), posant les bases d'une identité et d'une réputation fiables pour leurs futurs "doubles numériques" (agents IA). 2. **m&W 2.0 : Économie de la Collaboration (EcoFi)** – Le protocole EcoFi connecte les nœuds crédibles à des tâches réelles. Il utilise un système de vérification à plusieurs niveaux (pré-analyse par IA, jugement de valeur complexe par des Builders, arbitrage final par un réseau OG) pour évaluer, rémunérer et liquider les contributions, créant une boucle de valeur fermée qui renforce en retour le système de crédit. 3. **m&W 3.0 : Ordre Intelligent** – Le crédit humain accumulé (SBT) sert de base de confiance pour les agents IA (doubles numériques) lorsqu'ils entrent dans le réseau économique. Cela facilite l'émergence d'une "économie de collaboration homme-machine", où les agents ne sont plus de simples outils mais des participants actifs et crédibles. Ce parcours ambitieux présente des défis techniques et économiques majeurs, comme le démarrage à froid dû à une sélection exigeante, l'équilibre délicat entre vérification par IA et gouvernance humaine, et la stabilité à long terme de l'économie du jeton $CMW. En résumé, m&W ne cherche pas à être une plateforme de modèles IA, un marché d'algorithmes ou un outil de service Agent de plus. Son ambition est de répondre à une question structurelle de l'ère de l'IA : **comment établir un nouvel ordre économique - incluant crédit, collaboration et répartition de la valeur - pour un futur où humains et agents IA co-créeront de la valeur**. Il s'agit d'explorer les nouvelles relations de production à l'ère de l'intelligence artificielle.

链捕手Il y a 1 h

Évolution de l'ordre à l'ère de l'IA et du Web3 : Dimensions concurrentielles et voies d'exploration de m&W

链捕手Il y a 1 h

2026 IMO : la Chine truste les scores parfaits, le lycée de Shanghai domine, GPT-5.6 rejoue le moment AlphaGO

Félicitations à l'équipe chinoise ! L'équipe de Chine a remporté la première place aux Olympiades Internationales de Mathématiques (IMO) 2026 à Shanghai, avec une performance historique : les six membres de l'équipe ont tous obtenu une médaille d'or et un score total de 232 points, devançant les États-Unis (2e) de 25 points. Trois étudiants, Deng Leyan et Zhang Bolun du Shanghai High School, et Liu Che de la High School Affiliated to East China Normal University, ont réalisé un score parfait de 42/42. Cet événement marque la 26e victoire de la Chine depuis sa première en 1989. Le Shanghai High School, hôte de cette 67e édition (une première pour une école secondaire), a vu ses anciens élèves devenir des mathématiciens renommés. L'article souligne également un développement parallèle majeur : l'intelligence artificielle. Alors que les prouesses des étudiants humains représentent la "perfection sans erreur", il est rapporté que le modèle GPT-5.6 Pro aurait résolu les six problèmes de l'IMO 2026 dès sa première tentative, sans guidance humaine. Si cela est confirmé, cela pourrait indiquer que l'IA franchit une nouvelle étape, passant de la résolution par essais à une précision immédiate, évoquant un "moment AlphaGo" pour les olympiades de mathématiques. Les États-Unis et la Russie ont terminé respectivement deuxième et troisième du classement par équipes.

marsbitIl y a 2 h

2026 IMO : la Chine truste les scores parfaits, le lycée de Shanghai domine, GPT-5.6 rejoue le moment AlphaGO

marsbitIl y a 2 h

Trading

Spot
活动图片