A recent debate across the crypto industry has reignited questions about the safety of decentralized finance (DeFi) after OpenZeppelin co-founder Manuel Aráoz warned that DeFi remains fundamentally unsafe for everyday users.
His comments sparked strong reactions from industry leaders, many of whom argue that while security risks remain real, portraying the entire DeFi ecosystem as unsafe ignores the significant progress made over the past several years.
Security Concerns Trigger Industry-Wide Discussion
The discussion comes at a time when blockchain exploits continue to make headlines.
Recent research from blockchain security firm PeckShield revealed that cross-chain protocol attacks alone resulted in more than $328 million in losses between the beginning of the year and mid-May. These incidents have renewed concerns about vulnerabilities across decentralized applications, bridges, and smart contracts.
Aráoz argued that the threat landscape has evolved dramatically, particularly with the rise of artificial intelligence-powered tools capable of scanning open-source code and identifying vulnerabilities at unprecedented speed. According to him, AI-driven attackers could make even established DeFi protocols more vulnerable than many investors realize.
His warning was strong enough that he reportedly advised friends and family to reduce or exit their exposure to major DeFi platforms.
Industry Leaders Say The Data Tells a Different Story
Not everyone agrees with that assessment.
Several industry executives argue that while security challenges persist, DeFi has become substantially safer compared to its early years.
Michael Heinrich, CEO of 0G Labs, noted that DeFi lending security has improved by roughly 98% since 2020. He pointed to dramatically lower loss rates across major lending protocols and stronger security practices adopted throughout the industry.
According to Heinrich, leading protocols such as Aave and Maker now operate with risk profiles that are significantly different from the experimental platforms that dominated DeFi during its early growth phase.
Similarly, Leo Fan, founder of Cysic, believes broad statements suggesting that users should abandon DeFi altogether create unnecessary fear and fail to reflect the industry’s current reality.
He argued that security discussions should focus on measurable risks and data-driven analysis rather than worst-case scenarios.
The End of Traditional Security Audits
One area where industry leaders largely agree is that security practices must evolve.
Historically, many protocols relied on periodic smart contract audits as their primary line of defense. However, experts increasingly believe that annual or one-time audits are no longer sufficient in a world where attackers can leverage advanced automation and AI.
Instead, security is moving toward a continuous monitoring model.
This modern approach combines:
- AI-assisted code reviews
- Human security audits
- Real-time threat monitoring
- Bug bounty programs
- Formal verification systems
- Automated vulnerability detection
Rather than treating security as a one-time event before launch, protocols are beginning to adopt ongoing defense systems designed to operate continuously after deployment.
Insurance Remains an Underserved Sector
Another major topic in the discussion is decentralized insurance.
While DeFi has expanded rapidly, insurance solutions designed to protect users from hacks and exploits remain relatively small compared to the broader market.
Current coverage pools represent only a fraction of the total value locked across DeFi protocols.
Industry leaders argue that insurance adoption could become one of the most important developments for improving user confidence and reducing systemic risk.
Some analysts project the decentralized insurance market could grow nearly fivefold by 2029 as demand for on-chain protection products increases.
Future insurance models may include automated payouts triggered by verifiable blockchain events, reducing claims processing delays and improving transparency.
Operational Security Is Becoming the Real Battleground
Many experts believe that the biggest risks facing crypto users today extend beyond smart contract code.
According to Fan, some of the largest losses in the industry stem from operational failures rather than technical flaws.
Areas of concern include:
- Private key management
- Multisignature wallet security
- Cross-chain bridge infrastructure
- Governance systems
- Incident response procedures
He argues that regulators and industry participants should focus more attention on these operational layers, as they often represent the points where funds are actually compromised.
Advanced Cryptography Could Play a Larger Role
Another emerging area of focus is cryptographic verification.
Experts believe technologies such as zero-knowledge proofs could provide stronger assurances than traditional audit reports by mathematically proving that code behaves as intended.
Rather than relying solely on trust or manual reviews, future compliance and security systems may increasingly depend on cryptographic guarantees that can be independently verified on-chain.
The Bigger Picture
The debate highlights a growing divide between those who view DeFi as fundamentally vulnerable and those who see it as a rapidly maturing financial sector.
While hacks, exploits, and security risks remain genuine concerns, many industry leaders argue that the ecosystem has evolved significantly since the early DeFi boom.
Their message is straightforward: DeFi is not risk-free, but neither is it the lawless environment it was often portrayed as several years ago.
As security infrastructure, insurance products, continuous monitoring systems, and advanced cryptographic tools continue to develop, the conversation is gradually shifting away from whether DeFi can be safe toward how much safer it can become.

