The Onchain Brief is here| Subscribe to our monthly newsletter

FAQs

OpenZeppelin

Common questions about who we are, what we do, and how we secure the infrastructure onchain finance runs on.

About OpenZeppelin

OpenZeppelin is the security standard onchain finance is built on. Since 2015, OpenZeppelin has secured the infrastructure behind the onchain economy, with more than $35 trillion in value transferred through OpenZeppelin Contracts and more than $250 billion in onchain value secured through its security work. Trusted by leading institutions and crypto-native innovators, including DTCC, Fidelity, WisdomTree, Coinbase, Uniswap, Aave, the Ethereum Foundation, Fireblocks, BitGo, and Stellar, OpenZeppelin helps organizations develop, secure, and operate mission-critical onchain systems. It delivers continuous security across architecture, build, security evaluation, and ongoing support, backed by industry-standard open-source libraries and a decade of applied research.

OpenZeppelin works with institutions and innovators across the financial system. Its customers include financial institutions, asset managers, and payment networks moving onchain, alongside crypto-native protocols and blockchain platforms. This dual base reflects the convergence of traditional finance and onchain finance, where the same security standard now underpins both.

OpenZeppelin has set the security standard for onchain systems since 2015 and conducted the industry's first smart contract security audit in 2016. That decade of continuity, with institutional pattern recognition built across 900+ security engagements, is a track record no newer security provider can replicate

OpenZeppelin's reach across the onchain economy is significant:

  • $35 trillion+ in total value transferred via OpenZeppelin Contracts
  • $250 billion+ in total value secured through OpenZeppelin's security work
  • $175 billion+ in total value locked in smart contracts using OpenZeppelin
  • 6 billion+ transactions processed via OpenZeppelin Contracts
  • 370 million+ active wallets have interacted with OpenZeppelin Contracts
  • 900+ security engagements completed since 2015
  • 10,000+ total issues uncovered, including 700+ critical and high-severity vulnerabilities
  • 9 of the top 10 stablecoins by market capitalization built with OpenZeppelin Contracts
  • 10 of the top 10 tokenized money market funds by market capitalization built with OpenZeppelin Contracts
  • Zero exploits in fully-remediated audited code

OpenZeppelin takes a security-first, AI-native approach that integrates risk management and compliance across the full smart contract lifecycle. World-class security researchers provide depth and judgment, while OpenZeppelin AI scales that expertise into continuous coverage. The result is continuous security that lets financial institutions and crypto-native teams deploy and operate onchain with confidence and in regulatory alignment.

OpenZeppelin is an active contributor to the open-source blockchain ecosystem. Key contributions include:

  • EIPs and ERCs: OpenZeppelin has authored and co-authored numerous Ethereum standards, including Account Abstraction (ERC-1271), Metatransactions (ERC-2771), and Upgradeability (ERC-7201, ERC-1967).
  • Ethernaut: A leading educational resource for smart contract security, with 140K+ plays across 5 networks and 10 languages.
  • Security standards: OpenZeppelin contributes to the widespread adoption of vulnerability detection and threat response best practices as a member of EthTrust and SEAL911.
  • RetroPGF recognition: OpenZeppelin's Contracts library and plugins were recognized for their value to the Ethereum ecosystem in RetroPGF 2 and 3.

Yes. Research is central to how OpenZeppelin operates. The team conducts cutting-edge security research and translates findings into actionable insights, tools, and open standards, contributing knowledge back to the broader blockchain ecosystem and helping define best practices across the industry.

Several factors distinguish OpenZeppelin as the security standard for onchain finance:

  • Battle-tested open-source libraries that underpin much of the onchain economy, including 9 of the top 10 stablecoins and 10 of the top 10 tokenized money market funds by market capitalization
  • Institutional-grade security aligned with SOC 2 Type II and the compliance and risk management needs of financial institutions
  • An AI-native methodology that enables continuous security across the full lifecycle
  • Full-lifecycle coverage across architecture, build, security evaluation, and ongoing support
  • A neutral partnership model, with no stake in the protocols or platforms it secures
  • A decade of continuity since 2015, with zero exploits in fully-remediated audited code

OpenZeppelin was founded by Demian Brener, who serves as CEO. An industrial engineer and tech entrepreneur, Demian was named to the MIT 35 Under 35 list of innovators in 2019 and sits on the board of directors of IRSA, one of Argentina's largest real estate companies listed on the New York Stock Exchange. He holds degrees from Instituto Tecnologico de Buenos Aires (ITBA) and Lund University School of Industrial Design, and brings prior experience from Quasar Ventures and Despegar (NYSE), Latin America's largest online travel agency.

The broader leadership team includes Barry Duplantis (COO), Steve Gant (CGO), Jonathan Alexander (CTO), John Neufeld (General Counsel), Natalia Roose (VP of Customer Operations), and Jota Carpanelli (VP of Professional Services).

OpenZeppelin brings AI-native security to organizations operating onchain. Rather than applying AI as a supplementary tool, OpenZeppelin integrates OpenZeppelin AI across the full security lifecycle, enabling continuous assessment, faster vulnerability detection, and security operations that scale with the pace of capital markets. Senior researchers remain the foundation, providing the depth and judgment that AI alone cannot. This combination lets institutions deploy and operate onchain with greater confidence and in regulatory alignment.
OpenZeppelin operates as a strategic, neutral partner with no stake in the protocols or platforms it secures. This neutrality is a deliberate and important part of how OpenZeppelin works. It means clients can trust that audit findings, security recommendations, and ongoing guidance are driven entirely by their best interests, not by commercial relationships with third parties. This approach makes OpenZeppelin a trusted partner to both crypto-native innovators and financial institutions navigating onchain transformation.
OpenZeppelin's open-source smart contract libraries reflect a foundational belief that security and trust in onchain financial systems are strengthened when the tools underlying them are transparent, peer-reviewed, and freely available. By maintaining open-source libraries that have been security-reviewed, battle-tested, and adopted across the ecosystem, OpenZeppelin raises the baseline security standard for the entire industry, not just for its direct clients. This commitment to open standards is central to OpenZeppelin's mission and its standing as the security standard for onchain finance.
 OpenZeppelin is trusted by leading institutions and crypto-native innovators, including DTCC, Fidelity, WisdomTree, Coinbase, Uniswap, Aave, the Ethereum Foundation, Fireblocks, BitGo, and Stellar. Its open-source libraries underpin 9 of the top 10 stablecoins and 10 of the top 10 tokenized money market funds by market capitalization. Across 900+ security engagements since 2015, OpenZeppelin's relationships are built on sustained trust and long-term partnership. 

Security Services & the Continuous Security Program

OpenZeppelin delivers security across the full lifecycle, organized into four pillars. Architect validates the design and identifies risks before code is written. Build helps teams reach production with secure foundations. Secure catches vulnerabilities across code, infrastructure, and operations. Support keeps production systems secure over time. These services are delivered either as discrete, project-based engagements or as an ongoing partnership through the OpenZeppelin Continuous Security Program, and every engagement is powered by a decade of OpenZeppelin standards and expertise, scaled continuously by OpenZeppelin AI.
The OpenZeppelin Continuous Security Program is an ongoing security partnership for institutions and enterprises operating onchain. It delivers continuous security coverage across architecture, build, security evaluation, and ongoing support, provided by world-class researchers and scaled continuously by OpenZeppelin AI. Rather than fixed packages, each engagement is bundled around the actual shape of an organization's needs and adapts as the system evolves. The program is aligned with MiCA, DORA, Basel, the GENIUS Act, and SOC 2 Type II, and produces the documented, auditable evidence base that risk committees, supervisors, and counterparties increasingly require.
A point-in-time audit validates a slice of a system at a single moment, which leaves coverage gaps as code and systems evolve and tends to surface issues late, when they are expensive to remediate. Continuous security extends across architecture, infrastructure, governance, and operations, and stays in place as the system changes. Feedback arrives on every change, every commit, and every upgrade, so issues are caught early when fixes are cheap, audit readiness becomes a continuous state rather than a pre-launch scramble, and each engagement compounds on the last. Point-in-time audits remain valuable, but they cover one slice of the system at one moment.
OpenZeppelin offers two engagement models designed for institutional procurement and compliance. Project-Based Engagements are structured for vendor evaluation, specific compliance requirements, or discrete initiatives such as security audits, technical risk assessments, penetration testing, or training, with fixed scope and pricing that allow for straightforward procurement. The Continuous Security Program is a subscription-based engagement that combines AI-powered continuous coverage with senior researcher expertise, bundled around an organization's actual needs, for those moving from point-in-time assessments to continuous security coverage.
A Dedicated Blockchain Architect is a senior OpenZeppelin expert embedded alongside an organization's engineering team as the single, accountable point of contact for security across the full product lifecycle, from architecture through development, deployment, and operations. The architect is backed by on-demand access to OpenZeppelin's full security organization, including cryptographers, specialists, and tooling engineers. Their priorities span proactive risk reduction, secure development and deployment oversight, governance and control maturity, operational and regulatory readiness, and team enablement and continuity. The Dedicated Blockchain Architect is part of the Support pillar of OpenZeppelin's services.
Reference Implementations are battle-tested, end-to-end blueprints for the highest-value institutional use cases, built on a decade of OpenZeppelin standards. They let teams skip the trial-and-error of greenfield development and ship faster with secure, reusable scaffolding for tokenization, stablecoins, institutional DeFi, and other primary use cases. Each Reference Implementation includes working reference code with onchain and offchain elements packaged together, architecture documentation, a demo front-end with reusable components, and a threat model and risk evaluation. They are designed for institutional composability, with compliance hooks, credential-based access, and multi-party attestation patterns built in. Reference Implementations are part of the Build pillar.

A Technical Risk Assessment is OpenZeppelin's methodology for evaluating technical, operational, and governance risk across any onchain target. It produces an evidence-based, reproducible foundation that institutions include in regulatory submissions, license applications, vendor due diligence, and internal risk reviews, designed to withstand scrutiny across jurisdictions including MiCA, DORA, and Basel. OpenZeppelin delivers Technical Risk Assessments across the full onchain stack: blockchain networks (Layer 1s, Layer 2s, and purpose-built institutional chains), infrastructure and middleware (bridges, oracles, indexers, validators, and RPC providers), DeFi protocols (lending, exchange, staking, and yield protocols), and digital assets (stablecoins, tokenized funds, and tokenized real-world assets evaluated at the instrument level). The output is regulator-ready, reproducible, and decision-grade.

OpenZeppelin AI is the agent-augmented capability that scales OpenZeppelin's security work across continuous coverage. It surfaces routine and lower-severity issues early so that senior researchers can focus their effort on the most complex, high-impact vulnerabilities, and it makes continuous coverage possible at the depth that institutions require. OpenZeppelin AI is the multiplier on senior researcher expertise, not a replacement for it. Every Continuous Security Program engagement is powered by a decade of OpenZeppelin standards and expertise, scaled continuously by OpenZeppelin AI.

This page is general information about OpenZeppelin, onchain security, and onchain financial system. For educational purposes only, not financial, investment, legal, tax, or regulatory advice. Consult your own qualified advisors before making decisions.