Skip to content
TrustList
News

S&P Global agrees to buy OpenZeppelin; Contracts library to stay open source

Editorial

By TrustList Editorial

S&P Global agreed on 17 September 2026 to acquire OpenZeppelin; terms were not disclosed. OpenZeppelin says its Contracts library stays open source and audits continue with the same team. Clients should check contract terms.

About S&P Global agrees to buy OpenZeppelin; Contracts library to stay open source

S&P Global agrees to buy OpenZeppelin; Contracts library to stay open source

22 September 2026 — S&P Global and OpenZeppelin both announced on 17 September 2026 that S&P Global has agreed to acquire OpenZeppelin, the smart contract security company behind the widely used OpenZeppelin Contracts library. Financial terms were not disclosed, and the deal is subject to closing conditions. S&P Global says it does not expect the transaction to have a material impact on its financial results.

What changes

OpenZeppelin will run as its own business unit under the OpenZeppelin name. Chief executive Demian Brener will continue to lead it, reporting to Yann Le Pallec, president of S&P Global Ratings. S&P Global says the deal extends its risk assessment into the onchain technology layer, and Le Pallec said OpenZeppelin would complement its existing smart contract and onchain risk assessment work. Jefferies and Clifford Chance are advising S&P Global; FT Partners and Cooley are advising OpenZeppelin.

OpenZeppelin's own announcement adds two commitments that S&P Global's release does not repeat:

  • Open source: the Contracts libraries remain open source, free and publicly maintained on GitHub. Every released version stays open source permanently and cannot be withdrawn, and future versions will also be open source. OpenZeppelin says the same applies to its other open source tools.
  • Client work: security audits, engineering work and ecosystem programmes continue as they do today, delivered by the same team.

Neither announcement mentions Defender, OpenZeppelin's hosted operations platform. OpenZeppelin said in June 2025 that it had closed Defender to new sign-ups and planned to retire it on 1 July 2026, pointing users to its open source Relayer and Monitor tools.

What to do

  • Audit clients: check engagement letters for change-of-control, assignment and confidentiality terms, and ask who within the enlarged group will be able to see audit findings and code.
  • Ask about separation. OpenZeppelin will report into S&P Global Ratings, so ask how audit work will be kept apart from any ratings or risk assessments of the same protocols or issuers.
  • Library users: keep pinning the Contracts versions you depend on and watch the public repository and its licence. OpenZeppelin's stated commitment is that released versions cannot be withdrawn.
  • Former Defender users: confirm that monitoring and transaction relaying have moved to the open source tools or another provider.
  • Update your supplier records to show the new parent company once the deal closes.

What the announcements leave out

Neither party gives a price, an expected closing date or any change to audit pricing, and neither says whether OpenZeppelin's audit reports will carry S&P Global branding.

Sources