Short answer: Restaking risk is the danger that comes from pledging the same staked capital to secure more than one protocol at once. Instead of one set of slashing rules watching your stake, you now answer to several: the base chain, the restaking layer itself, and every individual service (an “Actively Validated Service,” or AVS) your operator has opted into. A fault in any one of those layers, or a liquidity shock in the token wrapping your position, can cost you principal even if you never interacted with the offending protocol directly. Since EigenLayer activated live slashing on Ethereum in 2025, this is no longer a theoretical footnote; it is an active, enforced condition of holding a restaked or liquid-restaked position.
Who Actually Carries This Risk, and What Sets It Off
Restaking risk does not sit with one type of user. It spreads across a chain of participants, and each one is exposed differently depending on where they sit in that chain.
At the bottom is the staker, the person or treasury that deposits ETH, a liquid staking token like stETH or rETH, or increasingly other assets, into a restaking protocol such as EigenLayer or a competitor like Symbiotic or Karak. The staker rarely runs infrastructure themselves. Instead they delegate to an operator, a node runner who decides which AVSs to opt into on the staker’s behalf. That single decision, which services an operator chooses to secure, is the fork in the road that determines how much slashing surface a staker is quietly exposed to.
Above the operator sits the AVS itself: an oracle network, a data availability layer, a cross-chain bridge, a keeper network, a rollup sequencer, or any other service that needs cryptoeconomic security but doesn’t want to bootstrap its own validator set from zero. For a broader look at how this stack fits into Ethereum’s wider shift toward yield-bearing infrastructure, see this overview of Ethereum’s proof-of-yield era, which covers base staking, liquid staking tokens, and restaking as parts of one continuum. Each AVS writes its own slashing conditions into its own contracts. A staker delegating through an operator that runs five AVSs is, whether they realize it or not, now subject to five separate rulebooks for how their principal can be cut.
Then there is the fourth participant, and arguably the one most exposed to a risk they didn’t sign up for: the holder of a liquid restaking token (LRT), such as eETH, ezETH, or rswETH. LRT holders often never read a single AVS’s terms. They bought a token on a decentralized exchange or deposited it into a lending market as collateral, and the token’s peg to ETH is now a function of restaking mechanics happening several layers removed from where they interact.
The trigger for a loss event can be any of the following, alone or in combination: a bug or downtime fault at an AVS that meets its slashing threshold; a correlated failure where one operator’s misconfiguration affects several AVSs it secures simultaneously; a governance or liquidity event at the LRT protocol layer that breaks the 1:1 assumption baked into DeFi price feeds; or simply a spike in withdrawal demand that a restaking protocol’s exit queue cannot absorb quickly enough, forcing LRT holders to sell at a discount on the open market rather than redeem at par.
Risk Factor One: Slashing Exposure Multiplies With Every AVS You Secure
Plain proof-of-stake validation has one slashing rulebook. You misbehave on the base chain (double-sign a block, go offline past a fault threshold) and the protocol penalizes you according to one set of rules you can read in full before you ever stake. Restaking breaks that clean one-to-one relationship on purpose. The entire value proposition of shared security is that a single pool of staked capital can back several services at once, which is efficient for the services and can be lucrative for the staker, but it means the same dollar of collateral is now standing behind multiple, independently written commitments.
EigenLayer’s own design documentation has always been explicit that restaking does not create new capital; it creates new claims on existing capital. Before mid-2025 this was mostly theoretical, because EigenLayer’s slashing mechanism had not yet been switched on for most AVSs; operators opted in, but the actual penalty rails were dormant. That changed with the rollout of live, permissionless slashing, which moved the ecosystem from “slashing exists on paper” to “slashing can execute automatically the moment an AVS’s contract determines a fault occurred.” Numbers on total value restaked and total value locked in liquid restaking tokens across the ecosystem have moved into the tens of billions of dollars in aggregate at various points since 2024, most of it concentrated in a fairly small number of large operators, which is precisely the kind of concentration that makes correlated slashing a systemic concern, not just an individual one.
The chart below illustrates the point using slashing conditions as a rough proxy for exposure surface. A solo validator answers to one rulebook. A restaker delegating to an operator running a handful of AVSs answers to several, and a liquid restaking token that pools deposits across multiple operators and AVS sets compounds that further because the token’s value depends on the aggregate health of everything underneath it, not just one clean validator key.
Slashing rulebooks a position is exposed to, by structure
Illustrative count of independent slashing conditions a position must satisfy simultaneously to stay whole
Dashed red line marks the single-rulebook baseline of standalone staking. Every bar to the right of it represents additional, independently-triggered ways the same principal can be penalized.
Notice what does not change in that chart: the amount of capital at risk. It is the same ETH, or the same claim on ETH, throughout. What changes is the number of independent doors through which that capital can be taken away from you. A staker who compares restaking yield only against solo-staking yield, without pricing in that expanded surface, is comparing two different risk categories as if they were the same instrument.
Correlated Operator Failure Is the Sharper Edge of This Risk
The scarier version of multiplied slashing exposure isn’t independent, unrelated faults happening to line up by coincidence. It’s correlated failure through a shared operator. If one operator runs the client software for six different AVSs and that operator misconfigures a server, gets hit by a DDoS attack that knocks their validators offline past a liveness threshold, or ships a buggy update, every AVS relying on that operator can trigger its own slashing condition in the same incident. From the staker’s point of view, one operational mistake at one company just became several separate penalty events stacked on top of each other. This is structurally similar to the “wrong-way risk” concept in traditional derivatives markets, where a single counterparty failure hits you through more than one exposure channel at once.
Risk Factor Two: Liquid Restaking Tokens Add a Peg-Risk Layer on Top of Slashing Risk
Slashing is a protocol-level mechanism. Depegging is a market-level one, and liquid restaking tokens sit exactly where those two risks meet. An LRT is meant to trade at, or very close to, a 1:1 backing ratio with the ETH it represents. That peg holds as long as three things stay true: the underlying restaked ETH is fully solvent (no unresolved slashing), the protocol’s redemption mechanism can actually process exits in a timely way, and secondary-market liquidity is deep enough that panic selling doesn’t detach the trading price from the redemption value.
All three assumptions can break independently, and the most instructive case so far is Renzo Protocol’s ezETH in April 2024. Renzo announced a token unlock and airdrop-adjacent liquidity change that the market misread as an imminent large sell pressure event. There was no slashing, no hack, and no insolvency; the underlying collateral was fine. But ezETH’s price on secondary markets fell sharply, trading as low as roughly 0.80 to 0.95 ETH per ezETH within hours, even though the protocol’s actual redemption backing remained close to 1:1 the entire time. The mismatch between “what the token is worth if you can redeem it” and “what the token is worth if you need to sell it right now” is the entire mechanism of a liquidity-driven depeg, and it is a risk that exists independently of whether the restaking layer itself ever gets slashed.
The second-order damage came from where ezETH was used, not just where it was held. Lending markets and structured-yield vaults across decentralized finance had accepted ezETH as loan collateral, often priced through oracles with some lag relative to the thinnest, most volatile trading venues. When ezETH’s market price dropped faster than those oracles updated, borrowers using ezETH as collateral for leveraged ETH positions found themselves suddenly undercollateralized on paper, triggering a wave of liquidations that had nothing to do with ETH’s own price and everything to do with a wrapper token around a restaking position losing its footing for a few volatile hours.
| Event | Root cause | Approx. low print | Was collateral actually impaired? |
|---|---|---|---|
| Renzo ezETH, April 2024 | Miscommunicated token unlock triggered panic selling | ~0.80–0.95 ETH | No — liquidity mismatch, not slashing |
| stETH, June 2022 | Withdrawal delay collided with a credit-crunch deleveraging wave (Celsius/3AC era) | ~0.94–0.95 ETH | No — no redemption path open at the time |
| Generic AVS slashing incident (structural pattern) | Operator fault meets an AVS’s on-chain slashing condition | Varies by AVS penalty schedule | Yes — principal is actually cut, not just mispriced |
The distinction in that last column matters more than almost anything else in this article. A liquidity-driven depeg is frightening and can force real losses on anyone who sells or gets liquidated during the dip, but the underlying claim usually heals once markets calm down. A genuine slashing event is different: the collateral itself is smaller afterward. No amount of patience brings back principal that a protocol’s contract has already burned or redirected. Anyone assessing restaking risk needs to know which of these two categories they are looking at, because the right response, holding through volatility versus recognizing a permanent loss, is completely different.
Risk Factor Three: Withdrawal Queues Keep You Exposed Longer Than You Think
Exiting a restaked position is not instant, and the delay itself is a risk factor rather than a mere inconvenience. EigenLayer’s standard unstaking process has historically involved a queuing period measured in days, and any AVS-specific slashing dispute window can extend the effective time before a withdrawal is finalized as slash-free. During that window, a staker who has already decided they want out is still fully exposed to a fault occurring at any AVS their operator continued to secure while the exit was pending.
Liquid restaking tokens were built partly to solve this: you can sell the token on the open market instead of waiting in a protocol queue. But that “solution” simply relocates the risk from queue-delay risk to market-liquidity risk. Selling into a thin market during a stress event, as ezETH holders learned, can cost more than the queue delay would have. There is no version of restaking where the exit is both instant and free of any secondary risk; the friction shows up somewhere.
The Real-World Consequence: Walking Through the ezETH Liquidation Cascade
It’s worth reconstructing the ezETH episode in sequence, because it shows how a non-slashing event still produces real, permanent losses for a specific group of people even while the “big picture” collateral was fine.
- Setup: A trader deposits ETH, receives ezETH, and then deposits that ezETH as collateral in a lending market to borrow more ETH, using the borrowed ETH to buy more ezETH, a leveraged loop that was extremely common across the restaking yield-farming ecosystem in early 2024, chasing points-based airdrop incentives on top of base staking yield.
- Trigger: Renzo’s token allocation announcement is interpreted by the market as a signal of imminent sell pressure from insiders and early depositors, and ezETH begins trading below its redemption value on decentralized exchanges.
- Oracle lag: The lending market’s price oracle for ezETH, sourced partly from thin on-chain liquidity pools, reflects the falling market price faster than the trader’s position can be topped up or unwound manually.
- Liquidation: The trader’s loan-to-value ratio breaches the protocol’s liquidation threshold. Automated liquidators seize and sell the collateral, often at exactly the worst moment, into the same thin, panicked market that caused the depeg in the first place.
- Outcome: The trader realizes a permanent loss on the spread between where their collateral was seized and where ezETH eventually stabilized once Renzo and market makers restored confidence and liquidity within roughly a day. The underlying restaking position, notably, was never slashed. The loss was entirely a function of leverage and liquidity mechanics layered on top of a restaking wrapper.
That sequence is the clearest illustration available of why restaking risk cannot be evaluated by looking only at slashing tables. The instrument that failed the trader wasn’t the AVS layer at all; it was the interaction between a liquid restaking token’s market price and a lending protocol’s collateral rules. Layered risk, in other words, doesn’t just mean “more layers of slashing.” It means more layers of financial plumbing, each with its own failure mode, stacked on top of the same underlying stake.
Red Flags Reference Table
| Red flag | Why it matters | What to check |
|---|---|---|
| Operator secures many AVSs with no published diversification limit | One operational failure can trip multiple slashing conditions at once | Operator dashboards or restaking protocol explorer for AVS count per operator |
| LRT’s largest liquidity pool is thin relative to its market cap | Small sell orders can move the price far from the redemption value | On-chain pool depth versus total LRT supply outstanding |
| Lending market prices the LRT from a single, thin-liquidity oracle source | A depeg on that one venue can trigger unnecessary liquidations elsewhere | Oracle documentation: number and type of price sources used |
| AVS slashing conditions are undocumented or described only in a forum post | You cannot price a risk you cannot read | Whether the AVS publishes audited slashing contract code and conditions |
| Advertised APY is far above base staking yield with no breakdown of source | Extra yield is compensation for extra, specific risks — it should be traceable | Whether the protocol itemizes AVS rewards, points programs, and base yield separately |
| Withdrawal queue length has been quietly extended or paused before | A history of extended exits signals liquidity or governance stress | Protocol governance forum and past incident post-mortems |
How to Mitigate or Respond: A Practical Checklist
- Map your actual slashing surface before you deposit. Ask, or look up, exactly which AVSs your chosen operator secures. Treat each one as a separate line item of risk, not a bundled footnote.
- Separate liquidity risk from solvency risk in your own head. If an LRT trades below peg, check first whether any AVS has actually been slashed. A liquidity dip with no slashing event is a very different problem than an impaired underlying claim.
- Avoid stacking leverage on top of a restaking wrapper unless you have modeled the oracle lag. The ezETH cascade happened to borrowers, not to plain holders. If you must borrow against an LRT, keep loan-to-value well below the liquidation threshold specifically to absorb depeg-style volatility, not just ETH price volatility.
- Check whether the AVS’s slashing mechanism is actually live, or only opted-in. “Slashing enabled” and “slashing code deployed and tested in production” are not the same claim, and protocols have historically been slow and cautious about turning live penalties on for good reason.
- Diversify across operators, not just across AVSs. Concentration at the operator level is the fastest way to turn one bad server into five simultaneous incidents.
- Size restaked and liquid-restaked positions as a satellite allocation, not a core holding. The additional yield over base staking generally reflects additional, stacked risk; position sizing should reflect that trade-off explicitly rather than treating restaking yield as a free upgrade to staking yield.
- Read the exit mechanics before you need them. Know the withdrawal queue length, whether it has ever been extended, and whether secondary-market selling is a realistic alternative at the size of your position.
- Watch protocol governance forums, not just price charts. Depeg events are often preceded by governance proposals, token unlock schedules, or operator changes that are visible days before the market reacts.
Key Takeaways
- Restaking multiplies the number of independent slashing rulebooks a single deposit answers to. The collateral doesn’t grow; the number of ways it can be penalized does.
- Correlated operator failure is the sharpest version of this risk: one operator’s mistake can trigger faults across every AVS that operator secures at once.
- Liquid restaking tokens add a second, distinct risk category, peg risk driven by liquidity and market structure, that can produce real losses even with zero slashing anywhere in the system.
- The April 2024 ezETH episode shows the actual failure mode in practice: a liquidity-driven depeg fed into a thin oracle, which triggered forced liquidations for leveraged borrowers, even though the underlying restaked collateral was never impaired.
- Withdrawal queues and dispute windows mean your exposure often outlives your decision to exit; plan for that lag rather than assuming an instant off-ramp.
- The extra yield restaking and LRTs offer over base staking is compensation for a specific, stackable set of risks, not a free enhancement to a familiar product.
Frequently Asked Questions
What is restaking, in plain terms?
Restaking is the practice of using already-staked assets, such as ETH or a liquid staking token, as security backing for additional protocols beyond the base blockchain. Instead of that stake only protecting the base chain’s consensus, it also stands behind services like oracles, bridges, or data availability layers, which pay extra yield in exchange for that added security.
Is restaking riskier than plain ETH staking?
Generally yes, because restaking adds independent slashing conditions on top of the base staking rules, along with liquidity and operator-concentration risks that plain staking doesn’t have. The extra yield is meant to compensate for that added risk, not eliminate it.
How does slashing actually happen in a restaking system?
Each AVS defines its own on-chain conditions for what counts as a fault, such as downtime past a threshold, double-signing, or submitting invalid data. When an operator’s behavior trips one of those conditions, the AVS’s contract can automatically cut a portion of the restaked collateral delegated to that operator.
Why did liquid restaking tokens depeg in 2024, and could it happen again?
The most notable case, Renzo’s ezETH in April 2024, depegged because of a liquidity-driven panic tied to a token unlock announcement, not because of any slashing event. Similar mechanics — thin secondary-market liquidity meeting a sudden shift in sentiment — could recur with any LRT, since the risk lives in market structure rather than in a one-time bug.
Can I lose money on a restaked position even if I never touch an AVS directly?
Yes. Holding or borrowing against a liquid restaking token exposes you to that token’s market price and peg stability, which can move against you due to liquidity conditions or lending-market liquidations even when the underlying restaked collateral is never slashed.
What’s the difference between restaking risk and traditional rehypothecation risk?
Both involve the same collateral being used to back more than one obligation, which is why the comparison to traditional finance’s rehypothecation is common. The key difference is transparency and automation: restaking’s rules are written into public smart contracts that execute penalties automatically, while rehypothecation risk in traditional finance typically depends on counterparty solvency and disclosure that isn’t always visible to the end client until a crisis exposes it.
References
- EigenLayer protocol documentation — restaking mechanics and slashing design
- Renzo Protocol post-incident communications, April 2024 — ezETH liquidity event
- Lido Finance market data archives — stETH secondary-market pricing during the 2022 deleveraging period
- Public DeFi lending market liquidation data, April 2024 — ezETH-collateralized position liquidations
