OpenZeppelin联合创始人警告:AI可能摧毁DeFi
The AI Exploit That Could Destroy DeFi
OpenZeppelin联合创始人的重磅警告,结合AI攻击实证数据,对DeFi安全格局有深远影响。建议所有DeFi从业者和投资者关注AI驱动的攻击风险,重新评估协议安全模型。
On May 26, 2026, Manuel Arios, the co-founder and former CTO of Open Zeppelin, posted a public warning that read less like a hot take and more like a man pulling his own family out of a burning building. His exact words were these. I now consider all of DeFi unsafe. Now, this is not some random perma bear shouting into the void. This is the person whose code secures roughly $250 billion in live protocol value, whose libraries sit underneath around $35 trillion in commulative onchain transactions and whose firm has run more than 900 audits across the entire industry.
And he confirmed he has been privately telling his own friends and family pull their money out of blue chip protocols entirely, naming a maker DAO and compound directly. The truly extraordinary part is the brutally simple logic underneath of it, backed by AI research that suggests he might actually be right. So today, I'm going to walk you through exactly why the man who secured DeFi no longer trusts it, dismantle whether the protocols holding your money are genuinely safer or just bigger targets, and lay out the uncomfortable question nobody in crypto wants to sit with.
My name is Lewis and you're watching the Coin Bureau. Now before we get into why AI changes everything, you need to understand who Arios actually is. Because his authority here is the entire reason this story matters. Open Zeppelin is the foundation of the industry. They build the open-sourced smart contract libraries that the vast majority of DeFi is constructed from. The re-entry guards, the access controls, the token standards, the governance modules.
Put simply, if Bitcoin is the foundation of crypto, Open Zeppelin's code is the rebar inside the concrete of DeFi. A uses it, Uniswap uses it, Compound, Maker Dow, Coinbase, even the Ethereum Foundation itself lean on the firm's work. Over the years, they have identified more than 10,000 vulnerabilities, and they hold their own code to test coverage above 99%. So when the person who wrote that rebar tells you the building is no longer safe, you don't dismiss it as noise.
You ask what he knows that you don't. And that brings us directly to the core of this argument, which is an idea security people have understood for decades. The asymmetry problem. Here is a thesis in plain terms. A defender has to find and fix every single bug in their code. An attacker only has to find one. That's it. That is the whole game. And in DeFi, this imbalance is sharpened to a razor's edge by three things that don't exist in traditional software.
First, the code is immutable, so a deployed contract often cannot be patched once it's live. Second, the code is fully public, meaning every attacker on Earth can read your defenses for free. And third, every protocol is sitting on a transparent, publicly advertised pile of money. We even have a hard number attached to this. A 2025 study by Jerves and Zho modeled the economics of it. And at a realistic vulnerability rate, attackers turn a profit at around $6,000 of exploit value, while defenders face roughly $60,000 in costs to achieve the same coverage.
That's a structural 10x cost imbalance that has always favored the attacker. Now, keep in mind this asymmetry has existed since the very first smart contract. So why is everyone panicking now? Well, because for years that imbalance was survivable. Finding a genuinely novel exploit in a complex protocol required elite human expertise, deep knowledge of solidity, of the EVM, of the specific quirks of each protocol's logic.
The skill ceiling was so high that it acted as a natural filter. The number of people on the planet who could actually do this was tiny and the ones who could were expensive and slow. The audit and launch model worked because attacks ran at human speed. But that filter just got vaporized. Which brings us to what AI agents actually change. In December 2025, Anthropic and its Matt's research program published something called scone bench, a benchmark of 405 real contracts that had been exploited between 2020 and 2025.
They pointed frontier models at it, Claude Opus, Claude Sonnet, GPT5, and the models successfully reproduced the exploits on 51% of the entire benchmark across all 405 contracts. The AI agents extracted $550 million in simulated funds. Now, you might assume these models were just regurgitating hacks they'd already seen in their training data, which would make this far less impressive. However, the researchers specifically tested contracts deployed after the model's knowledge cutoff.
Genuinely novel code the AI had never encountered. The result? Well, the agents cracked 19 of 34 of them, generating $4.6 $6 million in simulated exploit value out of code they were seeing for the very first time. And the cost of doing this is collapsing. Scanning for a single smart contract for vulnerabilities now cost roughly $122. In October 2025, models scanning nearly 2,850 contracts surfaced two completely novel zeroday vulnerabilities in code with no previously known flaws.
And here's a detail that should make every protocol team sweat. Potential exploit revenue from these agents was doubling roughly every 1.3 months throughout 2025. And there's also the hint factor. Researchers found that giving the agents a nudge towards where a vulnerability lived meaningfully boosted their success rates. Though the precise magnitude is still being studied across model generations. That matters because the only thing currently holding these agents back is the search problem.
And search is exactly what AI gets better at every single month. Unlike a traditional fuzzer that just throws random inputs at code, these agents reason through the logic, write an exploit, test it against live blockchain state, and iterate on the feedback. They operate autonomously, rewriting their own exploits until they break through. And this isn't theoretical anymore. Anthropic's own assessment was blunt. More than half of the blockchain exploits carried out in 2025 could have been executed autonomously by current AI agents.
So Arios's point is this. Defenders get those exact same tools, but defenders still have to be perfect and attackers still only need one win. Hand both sides an army and the side that only needs to get lucky once wins the arms race. Which brings us directly to the protocols that you actually use because this stopped being a thought experiment in April of 2026. Certic called April the worst month for DeFi exploits in 4 years with hacks landing on 27 of 30 days.
Their assessment of that surge was chilling. It quote could only be possible with AI. In a single month, around $630 million was drained across 27 separate exploits. And the headline event was the Kelp Dow hack, which is the perfect case study in everything that we've been talking about with one devastating twist. $292 million was stolen. And not one of those dollars came from a flaw in A's own code. The exploit lived in the bridge infrastructure connecting to a trust layer failure with a misconfigured verifier.
The kind of attack that standard smart contract audits simply do not catch. And yet the consequences for a were brutal. In the 48 hours after the exploit, $8.45 billion was withdrawn in a full-blown bank run. A's total value locked collapsed from around 26.4 4 billion to roughly 14.5 billion. That's a 45% wipeout in 30 days triggered by code that wasn't even a. So here's the uncomfortable answer to the question everyone asks.
Are bluechip protocols safer because of years of audits? A has been through more than 15 independent audits since 2020. It is about as battle tested as DeFi gets, but that $14.5 billion still sitting inside of it isn't a safety record. To an AI agent scanning DeFi Lama in real time is a publicly advertised bounty. The bigger the protocol, the bigger the prize, and the more compute it's worth throwing at finding the one bug everyone else missed.
And composibility means that you don't even have to break a to drain it. Y
原文超出正文长度上限,此处截断——上游还有内容,完整版见上方「原文 ↗」。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力