S&P Global Buys OpenZeppelin, Behind $37T Transfers
S&P Global agreed on Sept. 17, 2026 to buy OpenZeppelin, whose contracts underpin $37 trillion in transfers. Terms undisclosed; no material impact on results.
Summarize with
Prompt · remember Payney
More than $37 trillion in cumulative value has moved through smart contracts built on OpenZeppelin's open-source library, according to the September 17, 2026 press release announcing that S&P Global has agreed to buy the company. S&P Global did not disclose what it is paying, said the transaction remains subject to closing conditions, and stated it is not expected to have a material impact on its financial results.
What S&P Global announced, and what it withheld
The announcement, distributed via PR Newswire, says S&P Global (NYSE: SPGI) has entered into an agreement to acquire OpenZeppelin, which the release describes as "the security standard for onchain finance." Founded in 2015, OpenZeppelin provides onchain security assessments and secure development services alongside its open-source smart contract library. The release states that OpenZeppelin Contracts underpin over $37 trillion in value transferred, including the majority of the largest stablecoins and tokenized funds, and that the firm has run more than 900 security engagements surfacing over 10,000 vulnerabilities before production. Jefferies LLC is S&P Global's financial advisor and Clifford Chance its legal advisor, per the release.
On structure: The Block and Securities.io both report that OpenZeppelin will operate as its own business unit under the OpenZeppelin name, with chief executive Demian Brener continuing to lead it and reporting to Yann Le Pallec, president of S&P Global Ratings. Cointelegraph reports OpenZeppelin said its contracts library and other open-source applications will remain free and publicly maintained on GitHub.
One discrepancy is worth flagging. Some secondary aggregators recirculating the news, including a KuCoin news flash citing Huoxing Finance, described OpenZeppelin as having "protected over $3.7 trillion in value" — a figure one order of magnitude below the primary release, and framed as value protected rather than value transferred. The primary S&P Global release is the governing document here: $37 trillion, describing cumulative transfers through contracts built on the library. No source we found discloses a purchase price.
The verified numbers
| Metric | Value | Source |
|---|---|---|
| Purchase price | Not disclosed | S&P Global release (PR Newswire) |
| Value transferred via OpenZeppelin Contracts | Over $37 trillion (cumulative) | S&P Global release (PR Newswire) |
| Security engagements / vulnerabilities found | 900+ / 10,000+ | S&P Global release (PR Newswire) |
| S&P Global Q2 2026 pro forma revenue | $3.678 billion, up 11% year over year | S&P Global investor relations, July 28, 2026 |
| Kaiko Series B extension led by S&P Global | $110 million, announced Sept. 14, 2026 | Business Wire via Morningstar |
| Crypto hack losses, first half of 2026 | $972 million across a record 207 incidents | TRM Labs, July 1, 2026 |
What $37 trillion does and does not measure
The headline number is throughput, not size. It counts the cumulative dollar value of transfers executed by contracts that use OpenZeppelin's code — a measure closer to gross payment volume than to assets under custody, and not comparable to revenue, market capitalisation or the amount of money OpenZeppelin has insured or reimbursed. Because the library is free and open source, a project can use it without OpenZeppelin ever auditing that project. The $37 trillion figure therefore establishes how widely the code is deployed; it does not establish that $37 trillion was reviewed, secured or guaranteed by the company.
The comparison that is valid is against S&P Global's own scale. The company reported pro forma revenue of $3.678 billion in the second quarter of 2026, up 11% year over year, according to its investor relations release of July 28. Against that base, its own statement that the acquisition will not materially affect results is consistent with a small transaction — though without a disclosed price, readers cannot calculate a multiple of anything, and no valuation multiple should be inferred.
Why a ratings firm is buying code auditors
CoinDesk notes this extends work S&P has been building for over a year: it publishes stablecoin stability assessments and in 2025 issued the first credit rating of a DeFi protocol. Cointelegraph reported at the time that S&P Global Ratings assigned Sky Protocol, formerly Maker, a 'B-' issuer credit rating — speculative grade — with the agency's separate stablecoin assessment scoring USDS's peg-maintenance ability at 4, "constrained," on a five-point scale. CoinDesk frames OpenZeppelin as extending that from rating the entity to rating the code it runs on. The deal also follows S&P Global leading a strategic investment three days earlier that extended crypto data provider Kaiko's Series B to $110 million, alongside BNP Paribas, Nasdaq Ventures, Coinbase Ventures and Royal Bank of Canada, per the Business Wire announcement.
The threat data complicates the simple story that better code audits fix crypto losses. TRM Labs reported on July 1, 2026 that the first half of the year saw a record 207 incidents but $972 million in losses, less than half the $2.3 billion stolen in the same period of 2025. Critically, TRM found infrastructure and operational compromises accounted for only about 15% of incidents but roughly 76% of total losses — far exceeding the impact of more than 100 smaller smart contract exploits. Two North Korea-linked thefts involving Drift and KelpDAO accounted for around $577 million alone. The inference readers should draw, stated as inference: contract-level security addresses the most frequent category of failure, not the most expensive one. Stolen private keys and compromised developer machines are not bugs an audit of contract logic would catch.
What the announcement leaves unresolved
Several things are simply not public. No purchase price, no earn-out structure, no revenue or headcount figure for OpenZeppelin, and — in the announcements we reviewed — no stated target closing date beyond the disclosure that customary closing conditions apply. Signing is not closing, and an agreement announced in September does not mean integrated products exist.
- Independence question: S&P Global Ratings would own a business that audits the code of entities it may rate. Neither company's announcement describes how conflicts between the security-services business and the ratings business will be walled off.
- Open-source commitment: OpenZeppelin says the library stays free on GitHub. That is a company statement about future intent, not a contractual term disclosed to the public.
- Product timing: S&P Global describes creating "the next generation of onchain security assessments, benchmarks" — a stated ambition, with no launch date, methodology or pricing published.
The next dated disclosure that could add substance is S&P Global's quarterly reporting, where acquisitions of this size typically appear only if material. Given the company's own guidance that it is not, readers should not expect a price tag to surface there.
- S&P Global Announces Agreement to Acquire OpenZeppelin · PR Newswire (S&P Global)
- S&P Global acquires OpenZeppelin to bridge credit ratings with onchain code security · CoinDesk
- S&P Global agrees to acquire OpenZeppelin in onchain security push · The Block
- H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion · TRM Labs
- S&P Global Leads Strategic Investment in Kaiko, Extending Series B to $110 Million · Business Wire via Morningstar
- S&P Global Reports Second Quarter Results · S&P Global Investor Relations
Sources used during research. Check their dates and original context before relying on a figure. How we report.