Original | Odaily Planet Daily (@OdailyChina)
Author | Azuma (@azuma_eth)
"I believe all DeFi is no longer secure."
This assertion left by Manuel Aráoz, founder of OpenZeppelin, on X yesterday is like a depth charge, once again shaking the already stagnant DeFi market.
Manuel even stated that he has started advising friends and family to withdraw funds from major DeFi protocols, including blue-chip protocols like Aave, MakerDAO, and Compound, which were once considered low-risk.
This is not alarmist talk from an outsider. On the contrary, Manuel himself is one of the core builders of the DeFi security ecosystem, and OpenZeppelin is one of the industry's most mainstream security auditing firms. Its contract libraries, security standards, and auditing frameworks have permeated almost the entire DeFi world.
The reason for Manuel's complete change in attitude lies in AI. Manuel pessimistically believes that the capability of AI Coding Agents to identify and exploit smart contract vulnerabilities is increasing exponentially.
This means that issues which previously took top white-hat teams weeks to discover might now be scanned by AI in minutes; where hackers needed to study protocol logic extensively, AI can now automatically analyze attack paths; where DeFi's "openness and transparency" was once an advantage, it has now become the best training corpus for attackers.
Manuel also mentioned a more fatal problem: smart contract security is essentially an extremely asymmetric game — defenders must patch all vulnerabilities, while attackers only need to find one to steal funds. As AI begins to exponentially enhance attack efficiency, this asymmetry is rapidly tilting out of balance.
The Icy Reality: DeFi Has Become a Hacker's ATM
Looking back at DeFi security incidents over the past few months, you'll find Manuel's concerns are not exaggerated.
April was arguably one of the worst months in DeFi history.
- On April 1st, April Fool's Day, Drift Protocol suffered a theft of $280 million due to a manager privilege hijacking and multisig execution vulnerability (see April Fool's Joke? Drift Protocol Hacked for Over $280 Million, Possibly Becoming Solana Ecosystem's Second Largest DeFi Heist).
- Subsequently on April 19th, Kelp DAO lost $292 million due to a breached bridge protocol (see Another $292 Million Stolen from DeFi, Is Even Aave Unsafe Now?). The hacker later escaped via lending protocols like Aave, casting a shadow of bad debts and their ripple effects over the entire DeFi space.
And since entering May, incidents have not decreased but rather further proliferated.
- On May 15th, THORChain was attacked. A newly added node operator exploited a vulnerability in the GG20 threshold signature scheme (TSS) to reconstruct the vault's private key and directly execute outbound transactions, causing a loss exceeding $10 million.
- On May 18th, Verus's bridge protocol was attacked. The attacker forged cross-chain import payloads to bypass verification and extract assets from the Ethereum reserves, stealing approximately $11.58 million.
- On May 19th, Echo Protocol on Monad was attacked due to a private key leak. The attacker minted 1,000 eBTC (worth $76.7 million) and extracted funds via a previously tested attack path through Curvance.
- On May 24th, StablR, a compliant stablecoin issuer under the MiCA regulatory framework, was attacked. The hacker profited over $2.8 million by minting EURR and USDR, causing EURR and USDR to depeg.
- On May 25th, the SquidRouter module was attacked, resulting in the theft of approximately $3 million in assets from 86 Gnosis Safe wallets.
- On May 27th, the StakeDAO deployer's private key was leaked on Arbitrum. The attacker minted about 5.45 trillion vsdCRV and partially exchanged them for 43.7 ETH to escape.
Frequently occurring security incidents have sounded the alarm. From on-chain code to off-chain management, DeFi seems to be losing ground across the board.
AI Has Become the Hacker's Nuclear Weapon
Why has the DeFi offensive-defensive balance suddenly collapsed this summer? Beyond the evolution of traditional hacking techniques, the rapid advancement of AI large language model capabilities is becoming the ultimate factor tipping the scales.
In the past, finding a complex smart contract vulnerability (especially one involving cross-chain interactions, multi-layer nesting, or extremely hidden reentrancy logic) required top-tier hackers weeks or even months of code analysis. However, with the maturation of AI agents possessing ultra-long context, strong logical reasoning, and autonomous tool-calling abilities, this has undergone a qualitative change.
- Second-level Scanning and Global "Zero-day Vulnerability" Mining: Attackers only need to feed open-source code repositories to new-generation AI reasoning models, and AI can, within seconds, deduce hundreds of extreme interaction scenarios like a seasoned security expert, precisely identifying boundary conditions that human auditors might miss due to fatigue.
- Automated Attack Script Generation: AI can not only discover vulnerabilities but also automatically write, test, and deploy "hacker smart contracts" designed to extract funds.
- Perfect Orchestration of Off-chain DevOps and Social Engineering: AI can impersonate a perfect developer for phishing or monitor a DeFi team's GitHub commits 24/7. Once the team uploads code containing sensitive information or unverified fixes, AI can launch an attack within seconds—far faster than any human security personnel can respond.
In this AI-augmented security war, hackers, armed with AI, possess nearly unlimited ammunition and attack speeds measured in seconds. In contrast, DeFi, constrained by slow-paced governance voting, multisig confirmations, and delayed security audits, struggles to mount a corresponding defense.
Last month, Anthropic, the AI development company behind Claude, officially announced its new-generation model, Mythos (see Anthropic Develops the Most Powerful AI Model in History, But Dares Not Release It...). This is the first model in human history to exceed ten trillion parameters (in contrast, current mainstream models range from hundreds of billions to one trillion parameters), with a staggering training cost of $10 billion.
However, due to Mythos's specialized capabilities in cybersecurity (Anthropic disclosed that they identified thousands of zero-day vulnerabilities using Mythos in just a few weeks), the company even dares not release the model publicly directly, fearing malicious use by hacker groups. Instead, they plan to allow leading tech giants to test it first through a "Project Glasswing" to patch potential vulnerabilities in advance.
If the current DeFi security landscape is already this severe, it's hard to imagine what new threats industry security defenses will face once Mythos is publicly released.
The Biggest Problem: The Risk-Reward Ratio Has Long Been Out of Balance
For ordinary DeFi participants, liquidity providers (LPs), and whales, the most important issue now is to sit down and do the math.
For a long time, the reason users chose to deposit funds into DeFi was the pursuit of annualized yields several times higher than those in traditional finance. During bull markets or frenzied periods of liquidity mining, yields of 10%, 20%, or even higher were enough to cover people's psychological expectations for "potential technical risks."
But today, this underlying logic has long been shaken, even overturned. The risk-reward ratio of DeFi is already out of balance. On the reward side, as the market enters a phase of stock game competition and security cushions thicken, the real yields of most mainstream, relatively reliable DeFi protocols have fallen back to single-digit percentages. On the risk side, users' principal is exposed to a black box that could be breached by AI at any moment, emptied by flash loans in an instant. Once a protocol is hacked, token prices plummeting to zero and liquidity pools being drained often happen within minutes, with no legal recourse, insurance, or central bank to cover the losses.
The gamble of risking 100% principal loss for an annualized return of around 5% is clearly not a worthwhile bet.
Manuel's words may be somewhat absolute, but they tear off DeFi's final fig leaf. In the face of the reality where hackers have made AI a conventional weapon and security incidents keep erupting in the industry, if you are not mentally prepared to risk losing 100% of your principal for a certain return, then "withdrawing funds as soon as possible and securing profits" might be the most rational, most risk-control-compliant choice in the current market cycle.







