# Is DeFi's Security Model Broken? *Author: David Christopher* *Published: May 27, 2026* *Source: https://www.bankless.com/de/read/is-defis-security-model-broken* --- > *"PSA: I now consider all of DeFi unsafe.Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds.I’ve been privately advising friends and family to exit all DeFi positions including low-risk "blue chips" like Aave, MakerDAO & Compound."* Manuel Aráoz, co-founder and former CTO of OpenZeppelin, [tweeted these thoughts yesterday](https://x.com/maraoz/status/2059413451265441990?s=20), and they set off uproar across the timeline. Of course, OpenZeppelin is the firm behind the most widely used Solidity libraries and boasts one of the largest smart contract audit practices in the industry. The company has since clarified that [Aráoz left in 2019](https://x.com/OpenZeppelin/status/2059662515039354972?s=20) and his views don't reflect *their *position. Still, I fully understand where Aráoz's coming from. Last month set a record for the most onchain exploits in crypto's history, at a pace of nearly one a day, totaling more than [$625M stolen](https://www.bankless.com/read/agents-and-x402-make-defi-safer). Drift and KelpDAO took the bulk, but the smaller hits spanned the full surface: lending pools, vaults, oracles, bridges, admin controls. The attack surface keeps widening, with AI helping attackers find routes *beyond *smart contract bugs alone. ## **The Asymmetry Is Real** There's a fundamental asymmetry at play. Defenders must patch every bug. Attackers just need one. If "supermodels" like Mythos can surface 1000s of high-severity bugs that lay dormant for decades, surviving millions of automated tests, imagine what they'll do to a language like Solidity, which has only existed for 12 years. DeFi has had less than half the time to battle-harden the language it's built on, and the tools doing the testing are getting rapidly stronger and cheaper. It only cost Mythos $50 to discover a 25-year old bug. > Anthropic Mythos taking a first look at DeFi protocols. [pic.twitter.com/ieHmLpuShb](https://t.co/ieHmLpuShb)— mattytay (@mattytay) [April 9, 2026](https://x.com/mattytay/status/2042286635128397912?ref_src=twsrc%5Etfw) ## **The Trajectory** When [Alpen Yukseloglu came on Bankless](https://www.bankless.com/read/3-takeaways-from-a-big-week-in-crypto-x-ai) to discuss EVMBench, the Paradigm/OpenAI benchmark on smart contract vulnerabilities, he shared how they found models jumping from 12-13% detection of fund-draining bugs to above 70% with 5.3 Codex over the course of six months. It’s been nearly three months since then and we're already at 5.5, a model so capable it prompted a mass exodus from Claude. There's no doubt it's being used for offense here, if only to some degree. And while 5.5 isn't Mythos-level, Anthropic has made clear it [wants to release Mythos publicly](https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596). That likely forces OpenAI to ship its own cybersecurity model, 5.5-Cyber, in response. [AI Now Finds 70% of Smart Contract Exploits | Alpin Yukseloglu on BanklessAI is getting dangerously good at smart contract security. Faster than crypto is ready for.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)BanklessBankless![](https://storage.ghost.io/c/e4/b7/e4b77544-5a37-4f0b-8824-8440aa348476/content/images/thumbnail/ai-now-finds-70-of-smart-contract-exploits-alpin-yukseloglu-1772710380-80f96bf4eefd8de6aeda77b37c1f8ef31c8b73e2ea63e896378f8a2e1eb02819.png)](https://www.bankless.com/podcast/ai-finds-70-of-smart-contract-exploits) ## **The Math Is Already Broken** It's happening less than it was, but people still treat "low-risk DeFi" products like vaults or Aave as equivalent to savings accounts. $11.8 billion sits in Morpho vaults earning 2-4% APY. Most of that capital arrived through Coinbase, Kraken, or similar interfaces. Consider the risk-reward profile. In the vast majority of these positions, people are risking total loss on their capital to earn single-digit returns. It's no wonder the market's turned to perps and memecoins. Degenerate, sure, but the risk-reward math vastly outperforms DeFi. Even *beyond* AI, we have the North Korea exploit engine who runs sophisticated attack campaigns, their D(rift)-Day “mission” for built up over six months, and the math on a 3% APY vault seems comical. [Can DeFi Survive Mythos? on BanklessThe existential threats facing DeFi, the risk users are taking on, and the nascent solutions.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)BanklessDavid Christopher![](https://storage.ghost.io/c/e4/b7/e4b77544-5a37-4f0b-8824-8440aa348476/content/images/thumbnail/can-defi-survives-mythos-1775842687-757a0287868d435696a392798dcb45bf745c375bddd525f39fe59d943e8a58e9.png)](https://www.bankless.com/read/can-defi-survives-mythos) ## **Tools Cut Both Ways** The case for staying is that these models cut the cost of defense as fast as they cut the cost of offense. [Agentic allocator Zyfai](https://www.bankless.com/read/agents-and-x402-make-defi-safer) is a live example. Their agents flagged the Aave and KelpDAO conditions early, rebalanced into safer pools, and held capital unallocated when nothing cleared their risk thresholds. That's a company self-report, so apply the appropriate grain of salt. But the architecture is right. An agent watches live data around the clock, enforces a predefined risk budget, and refuses to allocate when conditions don't qualify, all under smart account permissioning with session keys and spending caps. That's a defensive layer humans can't match on attention or speed. [Agents and x402 Make DeFi Safer on BanklessWhen used properly, agents can shrink DeFi’s attack surface while helping users react to live risk before it becomes damage.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)BanklessDavid Christopher![](https://storage.ghost.io/c/e4/b7/e4b77544-5a37-4f0b-8824-8440aa348476/content/images/thumbnail/agents-and-x402-make-defi-safer-1777734606-3bc8302f85d6a7c1eca2ba2f282e37a03b83e5d292b6a4a17235cd383487c31f.png)](https://www.bankless.com/read/agents-and-x402-make-defi-safer)The same logic extends to insurance. Onchain coverage has been a footnote for years. Nexus Mutual, the longest-running protocol, has paid only $18.6M in claims across its entire history while crypto lost $3.4B to hacks in 2025 alone. The product has been narrow, the premiums heavy, the friction high. New constructions are starting to fix that. [OpenCover's Covered Vaults](https://www.bankless.com/read/can-defi-survives-mythos) stream premiums out of yield rather than billing depositors separately, and a Vaults.fyi partnership now surfaces coverage data alongside risk metrics through the same endpoint. Tools like these are great and I expect a sharp rise in insurance protocols and coverage adoption from here. Aráoz's diagnosis is right, though a little trite. His prescription, exit everything, is certainly alarmist, though unfortunately reinforced by [another exploit today](https://t.me/ahboyashreads/22918). While I believe we more so need agents on defense and more comprehensive insurance protocols rather than to scrap the whole system, I'm personally sidelined on DeFi and expect to be for some time.  > AI is a real threat vector, but it is also one of the most powerful defensive tools we have, if used with rigor and expert human judgment.Our researchers use AI daily to catch more issues and edge cases. The answer to AI risk is not retreat from DeFi. It is better security.— OpenZeppelin (@OpenZeppelin) [May 27, 2026](https://x.com/OpenZeppelin/status/2059662538565161110?ref_src=twsrc%5Etfw)