S&P Global announced on September 17 that it has agreed to acquire OpenZeppelin, the smart contract security firm behind the open-source contract libraries most of DeFi is built on. The business will operate as its own unit reporting to S&P Global Ratings. Financial terms were not disclosed.

The announcement — S&P's press release, OpenZeppelin's own post, and Unchained's reporting — puts code auditing and risk assessment inside the same division that already rates digital-asset issuers. S&P Global Ratings downgraded the stability rating on Tether's USDT to "weak," the lowest grade on its scale, in November 2025.

What Changes and What Does Not

OpenZeppelin keeps its name and operates as a distinct business unit. Founder Demian Brener stays on as chief executive and will report to Yann Le Pallec, president of S&P Global Ratings. "Our digital assets strategy centers on bringing trusted data, benchmarks and transparent risk assessment to markets as they move onchain," Le Pallec said in the release.

The company addressed the question its developer base was most likely to ask: "Every released version remains open source permanently and cannot be withdrawn by anyone, and future versions stay open source."

S&P put no price on the transaction and said it "is not expected to have a material impact on the financial results of S&P Global." No Form 8-K had been filed as of Thursday, per SEC EDGAR — public companies have four business days to report material definitive agreements. The deal remains subject to closing conditions, with no expected closing date given. Jefferies is advising S&P Global; FT Partners is advising OpenZeppelin.

The Asset Being Bought

OpenZeppelin, founded in 2015, maintains the open-source libraries of audited smart contract components that developers reuse instead of writing their own. The company says those contracts have underpinned more than $37 trillion in value transferred, and that it has run more than 900 security engagements — both figures are the company's own, and both describe exactly what a ratings division would want under its roof: a security track record attached to the code layer of the market it rates.

Those engagements are human-reviewed audit work — the kind that produces findings, remediation and a published report — as distinct from automated scanning products that analyze code without a reviewer signing the result. The distinction matters more, not less, after this deal: an S&P-branded audit carries the ratings firm's liability posture and methodology discipline with it.

Why a Ratings Firm Wants an Audit Shop

The consolidation logic is straightforward. On-chain finance makes the contract the counterparty: an issuer's creditworthiness and its code's correctness are no longer separable assessments. A ratings division that can read the audit trail of the contracts behind a token — and eventually attach that evidence to a graded score — has a product a traditional rating alone is not.

For the audit market itself, the deal prices assurance at the infrastructure layer. Independent security firms have been the de facto rating agencies of DeFi; their reports move capital decisions today. The open question is whether institutional ownership of one of the largest library and audit providers concentrates trust in a single standard — the same question the ratings industry has faced since 2008.

TrustGrade's own thesis has been that code-level security evidence should roll up into independent, registry-backed scores rather than live inside any single vendor's walled garden. The S&P–OpenZeppelin deal is the legacy-finance version of that same bet.

TrustGrade tracks security posture with verified, registry-backed scores. trustgrade.ai.