S&P Global Agrees to Buy OpenZeppelin, the Code Behind $37 Trillion

S&P Global agreed on Thursday to buy OpenZeppelin, the firm whose open-source contract libraries sit underneath a large share of the code running on public blockchains. Neither side put a price on the deal. S&P Global said it does not expect the purchase to materially affect its financial results, which is how a large company says a purchase is small. OpenZeppelin keeps its name, its chief executive and its libraries. The figure both releases lead with is $37 trillion, the value transferred through contracts built on its code.
What is being bought
OpenZeppelin does two things. It maintains OpenZeppelin Contracts, a free library of audited building blocks that most token and stablecoin deployments start from, and it reviews other people's code for a fee. Both companies' releases carry the same three numbers: more than $37 trillion moved through contracts using the library, more than 900 security engagements completed, and more than 10,000 vulnerabilities found before the code reached production. The Block, Decrypt and PYMNTS repeat them without variation. Every one of those figures originates with OpenZeppelin. No outside party has verified them, and neither release explains how they were counted.
Ten years, or eleven
One small thing does not line up. The S&P Global release, Decrypt and The Block all date the company to 2015. Demian Brener's own quoted sentence opens "Ten years ago, we started OpenZeppelin", and Cryptopolitan describes the firm as ten years old. Ten years before 2026 is 2016. Neither side corrects the other, and nothing in either release settles which year the count starts from.
The libraries stay open, on paper
OpenZeppelin's release makes four commitments about what does not change. The libraries stay free and publicly maintained on GitHub, every released version stays open source permanently, audits and client work carry on, and the same team delivers them. Brener remains chief executive and reports to Yann Le Pallec, president of S&P Global Ratings. That reporting line is the part worth watching. A ratings business now owns a firm whose judgment decides whether a protocol ships, and such judgments miss: Cosmos Labs said it had misgraded the bug behind a $5.7 million hack across six chains in August, the same month an estimated $75 million exploit stopped the Cronos chain outright.
What the announcement leaves out
Price, closing date and the conditions the deal has to clear are all absent from both releases and from every outlet account read.
"Our digital assets strategy centers on bringing trusted data, benchmarks and transparent risk assessment to markets as they move onchain," Le Pallec said.
The strategy behind that sentence has been assembling in public. S&P Global runs the Digital Markets 50 index, 35 blockchain-linked stocks alongside 15 cryptocurrencies, and has an arrangement with Chainlink to publish index data onchain, both reported by Decrypt. PYMNTS alone adds a strategic investment in the crypto data firm Kaiko announced on 14 September, plus earlier stablecoin stability assessments and a credit rating issued to a DeFi protocol. On advisers the two accounts differ in coverage: OpenZeppelin's release names FT Partners as its financial adviser and Cooley as counsel, while Cryptopolitan alone puts Jefferies and Clifford Chance on the buyer's side. Cryptopolitan is also the only outlet to price the market's reaction, at 1.04% higher and $411 a share in premarket trading, which stands unverified elsewhere. The open question is not whether the libraries survive. It is whether a firm paid to audit code can keep issuing opinions inside a house that sells risk assessment to the same market.
Read also: PeckShield Counts 50 August Hacks, CertiK Puts Losses $79M Higher