Home / History / After the Fires / Restaking & shared security
2023–Now

Restaking & shared security

EigenLayer sparks debates on risk and modular security.

After the Fires

Story beats & cast

RestakingAVSsSecurity assumptions
Events
  • EigenLayer growth
  • Risk frameworks emerge
Actors
  • EigenLayer team — Restaking builders

Restaking & shared security

EigenLayer and restaked security

Reusing the same shield

EigenLayer introduced a tempting idea: take staked ETH—already securing Ethereum—and let it secure other things for extra yield. Oracles, data availability layers, bridges, even new rollup sequencers could “rent” trust from Ethereum’s validator set. In theory, it birthed a market for shared security; in practice, it stacked risk. The same ETH could be slashed for misbehavior on multiple fronts (see EigenLayer’s docs ↗ for the pitch).

Stakers loved the pitch: turn one yield stream into several. Skeptics saw a new rehypothecation ladder. If one actively validated service (AVS) failed, could it nuke stake backing several others? Correlation went from abstract to glaring.

Actively validated services and the allowlist debate

AVSs could skip bootstrapping their own validators and tap into Ethereum’s pool. But someone had to curate which AVSs were “safe enough.” EigenLayer’s early model used allowlists: a council decided which services could tap restaked ETH. Purists balked at gatekeeping; pragmatists pointed to risk: one malicious AVS could slash everyone. The governance questions were gnarly: who decides, by what criteria, and can politics tilt the list?

Slashing conditions became the heart of the design. Each AVS needed crisp rules: when to slash, how much, what evidence counts. Stack too many AVSs and a single bug could cascade slashes. “Shared security” risked becoming “shared blast radius.”

Reuse, rehypothecation, and risk

Stacked slashing and correlated pain

Restaking’s superpower is also its nightmare: the same collateral can be punished for multiple offenses. A faulty oracle AVS could trigger slashing on stake that also backs a DA layer. Suddenly, honest stakers eat losses for someone else’s bug. Caps, insurance pools, and conservative slashing parameters emerged as safety valves. Some stakers opted out of spicy AVSs; others chased yield and accepted the blast radius.

Liquid restaking tokens (LRTs) added another layer. They promised liquidity and composability for restaked ETH, but they also abstracted risk. Holders might not grok which AVSs they were exposed to. A depeg could echo 3AC/UST vibes if one incident cascaded through pooled risk. Builders experimented with clearer disclosures and per-AVS tranching to avoid “mystery meat” risk; even LRT dashboards (e.g., community trackers ↗) emerged to spell out exposures.

“Yield is just risk wearing cologne. With restaking, make sure you like the scent.” — A validator, declining a spicy AVS

Governance tangles

Governance got thorny fast. If two AVSs demand conflicting actions, which wins? If a slashing dispute arises, who arbitrates? EigenLayer’s early governance leaned on multisigs and councils—practical, but a trust assumption. Large stakers (and LRT providers) risked outsized influence on AVS selection and slashing appeals. The dream of “marketplace for security” met the reality of “marketplace needs referees.”

Some proposed enshrining restaking in Ethereum itself; others warned that would import every AVS risk into the base layer. The compromise seemed to be modularity with strong fences: opt-in, with clear isolation, not an implicit default.

Governance and regulation

Policy and disclosures

Restaking blurred categories regulators care about: is it staking, lending, insurance, or all three? If a liquid restaking token pools risk across AVSs, does it look like a fund? Disclosures became critical: what services are you securing, what are the slashing terms, and what’s the legal wrapper? Some providers leaned into compliance; others stayed offshore and “experimental.”

Lawyers spotted familiar ghosts: correlated leverage, unclear consumer protections, and governance capture. Builders countered with transparency dashboards and opt-in per-AVS risk flags. The messaging shifted from “free extra yield” to “here’s the stack of risks you’re taking.”

Path forward: cautious composability

Done carefully, restaking could fund public goods: oracles with real budgets, DA layers without separate tokens, bridges with more eyes on keys. Done recklessly, it could recreate hidden leverage and slash honest stakers for someone else’s bug. The early playbook leaned conservative: allowlists, caps, slow onboarding of AVSs, insurance pools, and brutal transparency about exposures.

Ethos-wise, restaking tested Ethereum’s “don’t break the base layer” culture. The healthiest approach treated restaking as an opt-in side market with clear blast walls, not a default setting. The experiment is young; the scars, if any, will decide whether “shared security” becomes a feature or a cautionary tale.