S&P Global plans to acquire OpenZeppelin, a major smart contract security firm. The deal keeps OpenZeppelin's open-source code and leadership in place, while giving it access to S&P's institutional resources.
S&P Global is moving further into blockchain security. On September 17, 2026, S&P Global and OpenZeppelin announced an agreement for S&P to acquire the crypto security firm. The deal is still subject to standard closing conditions. Financial terms have not been disclosed, and S&P says the acquisition will not have a material impact on its financial results at this time, according to independent business press reports.
OpenZeppelin is known for its open-source Contracts library, which is widely used in the Ethereum ecosystem and supports many decentralized applications and protocols. Since 2015, software built on OpenZeppelin Contracts has handled more than $37 trillion in value transfers. The codebase is published under the MIT License, and OpenZeppelin has confirmed that all current and future versions of Contracts and related tools will remain open source and publicly available.
OpenZeppelin's Contracts library has processed more than $37 trillion in value transfers since 2015, making it one of the most widely used infrastructures in the Ethereum ecosystem.
S&P Global says the acquisition will help expand its digital asset risk assessment and ecosystem development offerings. The company plans to use OpenZeppelin's expertise to develop new onchain security assessments, benchmarks, and intelligence. OpenZeppelin will keep its name and operate as a separate business unit. CEO Demian Brener will continue to lead the company and report to Yann Le Pallec, president of S&P Global Ratings. The core team handling security audits, engineering, and ecosystem programs is expected to stay on, providing continuity for clients and developers.
For developers and organizations that rely on OpenZeppelin's open-source code, the acquisition does not change the public availability or licensing of the Contracts library. OpenZeppelin has stated that its code will remain under the MIT License, and future versions will stay accessible to the public. The company's terms of service do allow for changes to paid or hosted plans, such as pricing or usage limits, with notice periods depending on the change.
The most immediate effect of the deal will be OpenZeppelin's access to S&P Global's research, market data, and institutional distribution. This could bring smart contract security practices to more financial institutions and enterprises that already use S&P's risk and data services. While OpenZeppelin's core products remain open source, its team will now work within S&P's risk management and data operations, which may help spread stronger security standards across both traditional finance and digital asset markets.
OpenZeppelin's open-source smart contract libraries are a cornerstone of Ethereum development, widely adopted across DeFi, NFT, and enterprise blockchain projects. Their peer-reviewed code helps mitigate vulnerabilities, but even widely used libraries require careful implementation and ongoing audits to ensure security.
This deal is a notable step in connecting traditional financial infrastructure with blockchain security. S&P Global is not the first major institution to move into digital asset infrastructure, but acquiring a core crypto security provider signals a new level of involvement. Other financial players are also working to bridge legacy systems and decentralized technologies. For example, the European Central Bank has been running digital asset pilots, as reported earlier.
OpenZeppelin's audits and security services are used by protocols and organizations looking to reduce the risk of exploits in on-chain code. By joining S&P Global, OpenZeppelin may influence how institutions approach smart contract risk. Its commitment to open-source code and continuity for existing users will be watched closely by the developer community. For now, the acquisition shows S&P's view that blockchain security is becoming a core requirement for digital finance, not just a niche concern.
Open-source smart contract libraries like OpenZeppelin Contracts are central to the Ethereum ecosystem and beyond. Peer-reviewed code helps reduce the risk of vulnerabilities that can lead to major exploits or loss of funds. Still, open-source status does not guarantee security-developers must implement and audit code carefully, and even widely used libraries can have undiscovered bugs. As more institutions like S&P Global enter the space, the balance between open innovation and enterprise risk management will shape how blockchain infrastructure develops for both developers and end users.