S&P Global Enters Agreement to Acquire OpenZeppelinRead the announcement

Secure your protocol for the capital that is coming onchain

Institutional liquidity is starting to flow into DeFi through tokenized funds, stablecoins, and permissioned markets. OpenZeppelin secures every release of your protocol, and develops the risk frameworks, standards, and institutional integrations that bring that capital to it.

Trusted by leading DeFi protocols and financial institutions

  • Aave
  • Uniswap
  • coinbase
  • Fidelity Digital Assets
  • WisdomTree

The capital moving onchain will choose the protocols it can trust

$150B+
in value locked across DeFi protocols
$300B+
in stablecoins in circulation
$3.4B
lost to onchain exploits in 2025

Sources: DefiLlama (2026); rwa.xyz (Sept 2026); Chainalysis 2026 Crypto Crime Report.

DeFi protocols run in the most adversarial environment in finance: permissionless, always on, and composable with code you did not write. Every integration that grows your TVL also extends your risk perimeter, from the oracles you price against to the assets you accept as collateral and the keys and pipelines that operate the protocol. As tokenized funds and institutional allocators start routing capital onchain, their risk teams will ask for evidence your protocol's current tooling may not produce: comparable risk assessments, operational controls, and a deployment path their own systems can integrate with.

Get the foundations right, and institutional-grade becomes a feature of your protocol.

Liquidation thresholds, oracle design, interest-rate curves, and governance powers decide how your protocol behaves under stress. Design and economic assumptions are among the hardest risks to catch in code review, and the hardest to change once liquidity is deposited.

Stacked layered diagram showing four overlapping sections labeled Architecture, Governance, Upgrade path, and Key-management in isometric view.

Institutions and larger allocators deploy where they can evaluate risk, satisfy their own controls, and integrate with their custody and compliance systems. Protocols that can provide that evidence and integration path are the ones positioned to compete for that capital as it moves onchain.

Two horizontal bars comparing a proven path in blue and an unproven path in coral, from start to production.

Many of the costliest incidents in recent years started outside a protocol's smart contracts: compromised keys and signers, frontends, deployment pipelines, and upstream dependencies. An audit of your core contracts covers only part of the surface users' funds depend on.

Token contract hexagon inside dashed rings labelled Oracles, Keys, Bridges and Operational Systems.

Governance proposals, parameter changes, new markets, and new chain deployments change the protocol continuously. The audit you launched with covers a version of the protocol that may no longer exist.

Line graph from issuance: exposure keeps rising while assurance levels off.

Where OpenZeppelin helps, from every release to institutional scale

From the security audit your next release needs to the frameworks and integrations that bring institutions to your protocol, here is what OpenZeppelin does with you.

Security Audits & Continuous Security

Ship every release with independent review

Engage us for a defined-scope security audit of a launch or upgrade, or through the Continuous Security Program for coverage on every commit. A team that already knows your codebase carries context from one review to the next, so audit windows stop gating your releases and threat models stay current as the protocol changes.
Offchain & Operational Security

Secure the perimeter outside your smart contracts

Keys, signers, multisigs, deployment pipelines, frontend integrity, and oracle feeds all affect user funds. We assess them together with your contracts, the way an attacker would, and develop the operational playbooks your team and the operators running vaults and markets on your protocol need, from key management to monitoring.
Risk Frameworks & Transparency

Give depositors and integrators risk evidence they can compare

Institutions want to compare markets, vaults, and the teams operating them before they allocate. We develop risk assessment methodologies for your protocol, covering governance, collateral, oracle, allocation, dependency, and operational risk, and apply them to produce standardized, independent outputs your users and partners can evaluate side by side.
Standards, Libraries & Custom Development

Develop complex features on standards the industry already uses

Start from OpenZeppelin's security-audited implementations, including ERC-4626 vaults and our open-source library of Uniswap hooks, and work with our engineers on the features your roadmap needs next: new market types, compliance-ready modules, and reference implementations for patterns such as permissioned vaults and real-world asset lending.
Institutional Deployments

Help institutions go live on your protocol

Institutions choosing your protocol still need it integrated with their custody, compliance, and risk systems. OpenZeppelin architects and engineers work with those institutions to design and implement the deployment, develop any customizations on top of your protocol, and carry it through security review and production rollout, so your team stays focused on the protocol itself.

Across all of the above

Security at Every Layer of Your Protocol
Core contracts, offchain operations, risk frameworks, custom components, and institutional deployments can all run through OpenZeppelin's security team. The team operates independently from our development team, so even the components we develop for you receive an independent review, from the researchers behind 900+ security engagements and 10,000+ vulnerabilities surfaced before production.
Uniswap Foundation
“OpenZeppelin's solutions simplify the implementation of complex features, making life significantly easier for developers working on advanced protocols like Uniswap v4”
— Saucepoint, Protocol Engineer, Uniswap Foundation
Across Protocol
“OpenZeppelin has long been a partner for us when venturing into new territory. They match our pace of innovation stride for stride, enabling us to grow without sacrificing safety. For Solana, they had a purpose-built team ready to audit our program and support the rollout.”
— Matt Rice, Chief Technology Officer, Across

Support for the whole life of your protocol, from design to every upgrade

A DeFi protocol keeps changing after launch through mechanism design, integrations, governance proposals, and new deployments, and every change alters what needs securing. OpenZeppelin researchers and engineers work across all four stages, scaled by OpenZeppelin AI and calibrated to your protocol's TVL, release cadence, and governance model.

Validate the design before code is written

  • Architecture Review
  • Threat Modeling
  • Standards & Regulatory Review
  • Governance Design
  • Cryptographic Design Review
  • Applied Research

Reach production with secure foundations

  • Blockchain Library Development
  • Custom Platform & Solution Development
  • Reference Implementations
  • Standards Development

Catch vulnerabilities across code, infrastructure, and operations

  • Smart Contract Security Audit
  • Blockchain Infrastructure Audit
  • Zero-Knowledge Proof Audit
  • Technical Risk Assessment (TRA)
  • Penetration Testing
  • Operational Security Assessment
  • Deployment Verification

Keep production systems secure over time

  • Continuous Support & Maintenance
  • Dedicated Blockchain Architect
  • Custom Monitoring Solution
  • Security Training & Enablement

From a single security audit to a strategic engagement

Start with a defined-scope security audit for your next launch or upgrade, move to the Continuous Security Program for coverage on every commit, or combine security with risk frameworks, development, and institutional deployments in a larger engagement shaped around your roadmap.

See the full service breakdown on Security Services →

The standards behind the stablecoins and funds your protocol integrates

The stablecoins and tokenized funds flowing into DeFi already run on OpenZeppelin. The libraries behind 9 of the top 10 stablecoins and 10 of the top 10 tokenized money market funds by market cap are OpenZeppelin Contracts, so the assets you integrate and the code you ship can share one foundation.

Every engagement pairs OpenZeppelin researchers and engineers with OpenZeppelin AI, with risk assessment and monitoring running throughout, so issues surface early, while they are still cheap to fix.

  • 9 of the top 10 stablecoins

    by market cap build on OpenZeppelin Contracts

    • Stablecoin issuer logo
    • Stablecoin issuer logo
    • Stablecoin issuer logo
    • Stablecoin issuer logo
    • Falcon USDf
    • Stablecoin issuer logo
    • Ripple RLUSD
    • Stablecoin issuer logo
    • USD1
  • 10 of the top 10 tokenized money market funds

    by market cap build on OpenZeppelin Contracts

    • BlackRock
    • Tokenized fund issuer logo
    • Tokenized fund issuer logo
    • Janus Henderson JTRSY
    • Tokenized fund issuer logo
    • OpenEden thBILL
    • Tokenized fund issuer logo
    • Tokenized fund issuer logo
    • Tokenized fund issuer logo
    • Tokenized fund issuer logo

The security standard for onchain finance

Talk to an Expert