Hacks keep landing, DeFi TVL keeps sliding, and OpenZeppelin’s CEO is pointing to one new accelerant. In a CoinDesk report, the OpenZeppelin security executive warned that AI coding agents have made smart contracts “fatally vulnerable.”

The core claim from CoinDesk is blunt. As these AI agents get better at writing code, they also get better at finding weaknesses and producing exploit-ready output. That changes the threat model. Attackers no longer need as much manual engineering time to reach a working attack, and defenders face the same problems with less slack.

CoinDesk ties the warning to the last year of thefts. The report says more than USD 1 billion was hacked from DeFi during that period. It also frames the current moment as an environment where failures compound, not just accumulate. When TVL falls “fast,” there is less margin to absorb losses, fewer resources to patch slowly, and more pressure to ship riskier upgrades to keep liquidity.

Why it matters

In DeFi, “security” is not a vibes check. Money sits behind code paths, permissioning, and assumptions that can fail under adversarial inputs. If AI coding agents can turn vulnerabilities into exploitation faster, then the gap between discovery and damage shrinks.

That matters even if a given protocol’s fundamentals look fine. An attacker only needs one weak link. An AI-accelerated attacker can probe and iterate across many variants until one breaks. CoinDesk’s warning lands at that exact pain point: smart contracts that were once robust against human-scale mistakes may be exposed to machine-speed testing.

Market impact

The CoinDesk piece connects two signals. First, the hack totals. Second, the fall in DeFi TVL. Even without protocol-by-protocol details in the source text, the direction is clear. When the market watches repeated thefts, liquidity providers demand higher risk compensation or step aside.

Falling TVL then affects more than returns. It can concentrate liquidity into fewer pools, increase price impact, and leave smaller protocols with less runway to fix issues. Security lapses stop looking like isolated accidents and start looking like a category risk.

Snapshot from the CoinDesk report

ItemWhat CoinDesk says
DeFi hacks in the last yearOver USD 1 billion hacked from DeFi
Security warning sourceOpenZeppelin security executive via CoinDesk
Claimed causeAI coding agents make smart contracts fatally vulnerable
Market signal referencedDeFi TVL falling fast

What to watch next

CoinDesk’s report does not list specific countermeasures, but it points to an unavoidable shift in defenses. Expect more scrutiny on how contracts are tested and verified when attackers can generate exploit code quickly.

Watch for three categories of responses. First, more formal verification and stronger invariants in critical modules. Second, tighter review pipelines for upgrades and “agent-assisted” code changes. Third, faster patch cycles and improved incident handling when AI-powered exploitation compresses timelines.

If the threat model now includes AI coding agents, then security becomes less about proving a contract “looks correct” and more about proving it stays safe under stress, adversarial iteration, and unexpected call sequences.

The newsroom takeaway is simple. If CoinDesk’s warning is directionally right, DeFi teams will face less time to react when something breaks. Assets in DeFi still carry smart contract risk, and that risk can evolve quickly when the toolset changes.