S&P Global buys OpenZeppelin to expand crypto security and onchain risk infrastructure

Daily Feed
S&P Global buys OpenZeppelin to expand crypto security and onchain risk infrastructure

S&P Global is buying its way deeper into crypto’s plumbing, agreeing to acquire OpenZeppelin, one of the best-known names in smart contract security and open source blockchain tooling.

  • S&P is building a crypto risk stack
  • OpenZeppelin stays open source
  • Security is shifting from audits to ongoing monitoring
  • Institutional finance wants onchain data, not just exposure

The announcement came on Sept. 17. Financial terms were not disclosed, and the deal is still subject to closing conditions. S&P Global said the acquisition is not expected to have a material effect on its financial results, corporate shorthand for “this is strategic, not a giant bet-the-farm swing.”

The bigger signal is clear enough: S&P Global is no longer treating digital assets like a side quest. It is assembling a stack that includes crypto market data, stablecoin risk assessments, tokenization work, and now blockchain security. In plain English, it wants to be a trusted provider of the boring but crucial infrastructure that institutional crypto actually runs on.

OpenZeppelin is a serious piece of that puzzle. Founded in 2015, the company is widely known for its Security Standard for Onchain Finance, a reusable toolkit developers use to build blockchain applications without writing every basic function from scratch. It has also completed more than 900 security engagements, and OpenZeppelin says those reviews identified over 10, 000 vulnerabilities before projects reached production.

That matters because blockchain security is not just about flashy exploits and headline-grabbing hacks. Sometimes the real failure is a bad key, a sloppy deployment, a weak signer setup, or a bridge that looked fine right up until it wasn’t. Crypto has a talent for turning “small” mistakes into very expensive lessons.

S&P Global’s logic here is straightforward. If more financial activity is moving onchain, then data, benchmarks, risk scoring, and security review become valuable products, not just back-office chores. OpenZeppelin gives S&P a stronger foothold in the part of the market that actually keeps systems alive.

The company already showed where this was headed. On Sept. 14, S&P Global led a strategic investment in Kaiko, the crypto market data provider. The round was extended to $110 million, with participants including BNP Paribas, Coinbase Ventures, Nasdaq Ventures, Royal Bank of Canada, Stellar and others.

Kaiko provides data across more than 150 exchanges and protocols. S&P Global and Kaiko also launched the S&P Kaiko Digital Asset Indices earlier in September, and in April S&P Dow Jones Indices and Kaiko said they planned to tokenize the iBoxx U.S. Treasuries index on Canton Network.

That is the real pattern here: market data on one side, security on another, and tokenization in the middle. It is a fairly classic incumbent-finance move, take something familiar, wrap it in blockchain infrastructure, and make it look acceptable to institutions that would normally run from anything with a wallet address attached.

OpenZeppelin’s value is not limited to audits. Its smart contracts have supported more than $37 trillion in transferred value, according to the company, and its tooling has been used in infrastructure supporting major stablecoins and tokenized funds. That cumulative figure is best read as a broad usage metric, not a claim that OpenZeppelin itself moved all that value. Still, it tells you how deeply embedded the company is in onchain development.

Open source is the other big reason this deal drew attention. S&P Global said OpenZeppelin will operate as a separate business unit and keep its existing name. CEO Demian Brener will remain in charge and report to Yann Le Pallec, president of S&P Global Ratings. The company also said OpenZeppelin’s open source products, including its Contracts libraries, will remain available, and every released version will remain open source permanently.

That is the right move if S&P wants to avoid wrecking the very thing it is buying. Developers are not stupid. When a major company acquires a key open source project, people immediately ask whether the free stuff will slowly get squeezed, neglected, or turned into a sales funnel. That suspicion is healthy. Crypto has seen enough bait-and-switch behavior to justify it.

Le Pallec framed the acquisition as part of a broader push, saying:

“Our digital assets strategy centers on bringing trusted data, benchmarks and transparent risk assessment to markets as they move onchain, ”

That is not just a nice line for a press release. It gets to the business model. If assets, payments, and financial products are increasingly represented on blockchains, then someone has to score the risk, validate the data, and understand the security posture. S&P clearly wants to be that someone.

Brener echoed the same theme, saying OpenZeppelin’s technology already supports infrastructure behind “stablecoins, tokenized funds, DeFi protocols and other onchain markets.”

That claim is believable, but it also highlights the uncomfortable truth underneath all the institutional enthusiasm: security onchain is no longer just about finding bugs in code. The bigger losses often come from operational failures, compromised keys, weak signer setups, broken infrastructure, and other avoidable human messes.

Crypto.news cited a Blockaid report saying crypto security losses reached $1.1 billion across 212 verified incidents in the first half of 2026. Blockaid said 74% of stolen funds came from operational security failures rather than exploited smart contract code. That distinction matters. A perfect audit does not save a team that mishandles keys like they are office snacks.

A July research report pointed in the same direction, finding investors were increasingly looking for continuous monitoring rather than one-time smart contract audits. The same research said compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter, while only 4% of tracked projects combined audits, active bug bounty programs and third-party monitoring.

That is a brutal stat. It suggests many teams still treat security like a box to check before launch, then act shocked when the system falls apart later. One audit is a snapshot. It is not a shield, and it definitely is not a substitute for ongoing monitoring.

This is where OpenZeppelin becomes more than a developer brand. For S&P Global, it is a way to move deeper into continuous risk assessment for onchain markets, the kind of product institutions can actually use. That is a much more defensible business than just slapping “blockchain” on a slide deck and calling it strategy.

S&P Global has already been translating traditional risk frameworks into crypto terms. Its Stablecoin Stability Assessments evaluate stablecoins using reserve assets, governance, liquidity and regulatory considerations. Through a partnership with Chainlink announced in October 2025, those assessments became available onchain, initially through Coinbase’s Base network. The ratings use a scale from 1, or strong, to 5, or weak.

That may sound dry, but it is a meaningful step. If a risk assessment can be consumed directly onchain, it becomes more useful to applications, not just human analysts reading a PDF. That is the sort of thing institutions like because it turns a report into an input.

S&P Global has also been applying its framework to tokenized finance. In August, S&P Global Ratings assigned an AAAm principal stability fund rating to BlackRock’s tokenized money market fund. The fund held $50 million and maintained a $1 net asset value shortly after launch.

That does not make tokenized funds magically safe or revolutionary. It does show that traditional finance is willing to place formal ratings on blockchain-based wrappers around familiar assets. In other words, some of the biggest institutions on Earth are now comfortable putting old-school trust mechanisms in a new onchain jacket.

There is a downside to all this, of course. Corporate ownership can be good for funding and scale, but it can also dull the edge of an open source project if priorities drift toward enterprise sales and away from the broader developer ecosystem. S&P says the open source commitments remain intact. That is encouraging. The market will still watch closely to see whether the promise holds up once the lawyers, roadmaps and revenue targets start doing their thing.

OpenZeppelin’s own warnings about security make the stakes even clearer. In May, co-founder Manuel Aráoz said advances in coding agents had changed the balance between attackers and developers. He also said he had advised friends and family to exit DeFi positions, including exposure to established lending protocols, because of smart contract security concerns.

That is a harsh counterpoint to the usual “everything is fine, just keep yield farming” nonsense. DeFi still offers real innovation, but it also remains a place where technical risk, governance risk and operational risk can stack up fast. Sometimes the smartest trade is simply not pretending the risk vanished because the interface looks polished.

Jefferies is serving as S&P Global’s financial adviser on the deal, with Clifford Chance as legal adviser. FT Partners is acting as OpenZeppelin’s exclusive financial and strategic adviser, and Cooley is serving as its legal adviser.

The broader takeaway is simple: the winners in crypto are not always the loudest token issuers or the flashiest chains. Often it is the companies that make the system safer, more legible and more usable. Data, security and risk controls may not make for sexy marketing copy, but they are what institutions actually pay for.

S&P Global looks like it understands that. OpenZeppelin gives it a foothold in the code that underpins onchain markets, while Kaiko and its other crypto moves fill in the data and benchmarking side. That is not random dealmaking. It is a deliberate attempt to own the infrastructure layer of institutional crypto.

Key takeaways

What is S&P Global really buying with OpenZeppelin?
It is buying blockchain security expertise, a respected developer brand, and a major open source toolkit used across onchain infrastructure. That also strengthens S&P’s broader push into crypto risk, data and benchmarks.

Will OpenZeppelin’s open source tools stay free?
S&P Global says yes. OpenZeppelin’s open source products, including its Contracts library, will remain publicly available, and every released version will stay open source permanently.

Why does this deal matter for crypto builders?
Because it shows security is becoming a core part of institutional blockchain infrastructure, not an afterthought. The market is shifting from one-off audits toward continuous monitoring and broader risk assessment.

Is S&P Global just chasing a trend?
Not really. The OpenZeppelin acquisition fits alongside S&P’s Kaiko investment, stablecoin assessments, tokenized index work and onchain risk products. That looks more like a strategy than a fad.

Does this mean crypto is now safe for institutions?
No. It means institutions are getting more serious about managing risk. Smart contract bugs, compromised keys and operational failures still cause serious losses, and that problem is not going away because a legacy giant got interested.

What’s the biggest risk in onchain security today?
Operational failures. A lot of losses come from compromised keys, weak signer setups and infrastructure mistakes, not just code exploits. That’s why continuous monitoring matters.

Where does S&P Global’s crypto strategy go from here?
It is already moving across market data, tokenization, stablecoin ratings and now security. This looks like a push to become a core infrastructure provider for institutional onchain finance.

How serious is the tokenization push?
Very. With products like S&P Global Predicts $850 Billion Bank Credit Losses in and its work with Kaiko, S&P is treating tokenized markets as a real business line, not a novelty.

Why are people linking this to crypto regulation and youth risks?
Because institutional adoption and public scrutiny are moving together. Crypto is getting more mainstream while regulators keep pressure on risky behavior, as seen in pieces like Elizabeth Warren Slams MrBeast Over Teen Crypto Risks at. That tension is not going away.

Further reading

A bit more background on the security stack behind onchain finance:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog