AI Hacking: Is DeFi Really Unsafe? - Manuel Aráoz's Warning (2026)

The world of decentralized finance (DeFi) is facing a critical juncture as the threat of AI-powered hacking looms large. Manuel Aráoz, a former CTO and co-founder of OpenZeppelin, has sounded the alarm, declaring all of DeFi unsafe due to the superhuman capabilities of coding agents in exploiting vulnerabilities. This stark warning comes at a time when DeFi's total value locked has plummeted by over $20 billion since the start of the year, with a steady stream of exploits further eroding confidence in the sector.

Aráoz's perspective contrasts sharply with that of OpenZeppelin, which has distanced itself from his views. The company, under the leadership of co-founder and CEO Demian Brener, maintains a commitment to securing on-chain finance and advocates for continuous, AI-augmented security measures rather than retreating from DeFi. This divide highlights the complex challenges faced by the industry as it navigates the evolving landscape of AI-driven risks.

The Rise of AI-Powered Hacks

The threat of AI-powered hacking is no longer a distant possibility but a present reality. Coding agents, with their superhuman capabilities, have become adept at identifying vulnerabilities in smart contracts, rendering DeFi's core security model obsolete. The asymmetric nature of smart contract security, where defenders must fix every bug while attackers need only one exploit to steal funds, has become a fatal weakness.

Aráoz's warning is further underscored by Anthropic's revelation that its restricted Claude Mythos AI model can autonomously discover software vulnerabilities and develop working exploits, surpassing existing automated tools. This raises serious concerns for DeFi, which was designed with the assumption of human attackers operating at human speed. The transparency of smart contract code, once seen as a strength, now becomes a liability as machine systems can scan and exploit weaknesses faster than they can be patched.

The Impact on DeFi

The consequences of AI-powered hacking are already evident in the DeFi space. Over $1.1 billion has been lost to DeFi hacks in the past year, with high-profile exploits such as the $292 million Kelp DAO incident and the $27 million Step Finance shutdown highlighting the vulnerabilities in cross-chain infrastructure. These incidents demonstrate how quickly exploits can spill over into the broader ecosystem, causing widespread damage.

A Call for Action

Aráoz's warning serves as a wake-up call for the DeFi community. The industry must confront the reality of AI-driven risks and develop robust strategies to mitigate them. Continuous, AI-augmented security measures, as advocated by OpenZeppelin, offer a potential path forward. However, the challenge is complex and requires a collective effort from developers, security experts, and the wider DeFi community.

Conclusion

The rise of AI-powered hacking poses a significant threat to the DeFi ecosystem, challenging its core security model and transparency. As coding agents become increasingly sophisticated, the industry must adapt and innovate to stay ahead of the curve. The future of DeFi depends on our ability to address these emerging risks and develop resilient security measures. The time to act is now, and the consequences of inaction could be devastating.

AI Hacking: Is DeFi Really Unsafe? - Manuel Aráoz's Warning (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Kieth Sipes

Last Updated:

Views: 6788

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.