The Kelp DAO incident was rooted in a vulnerability in one specific contract — why did it spread to other protocols with no direct exposure? What's the actual mechanism of contagion?
The key lies in the nature of the liquid Restaking Token (LRT) itself — a certificate representing an equivalent underlying asset, widely integrated across other DeFi protocols as collateral or a trading pair. Once the market starts doubting whether the assets backing a given LRT are genuinely fully backed — even if that doubt originates from an entirely different contract — holders of that LRT tend to rush to redeem it first, to avoid being left holding a certificate that's become worthless. Once that redemption rush grows large enough, it directly hits the lending protocols that had accepted that LRT as collateral, triggering cascading liquidations — even though those lending protocols may never have had any direct interaction whatsoever with the contract that actually got exploited.
The underlying mechanism is fundamentally similar to a traditional bank-run dynamic: the problem doesn't need to have actually happened to you personally. As long as the market becomes suspicious of others holding the same asset as you, you get pulled into the redemption rush too, because no one wants to be the last person still holding a certificate that's already become worthless by the time they try to cash out.
EigenLayer holds roughly 94% of the Restaking market — why is that fact itself considered a risk? Doesn't high market share usually indicate a more mature, more trusted protocol?
High market share genuinely does usually reflect market trust — but in the specific context of shared security infrastructure, high market share simultaneously represents extreme risk concentration. That's not a contradiction; it's two sides of the same fact. Because the overwhelming majority of AVSs choose to rely on the same security foundation, those AVSs are superficially independent from one another while actually sharing the exact same single point of failure underneath. If EigenLayer's own core contracts suffer a serious vulnerability, the impact wouldn't be confined to any one AVS — it would ripple through nearly every downstream service that depends on it, spanning critical infrastructure across the entire ecosystem, including data availability layers, oracles, and cross-chain bridges.
This structure has a corresponding concept in traditional finance called "systemic importance": once an institution or piece of infrastructure grows large enough that the functioning of an entire system depends on it, a failure there stops being just that entity's problem and becomes a risk the whole ecosystem shares. There isn't yet a competitive landscape in restaking with enough alternatives to meaningfully dilute this concentration — which is exactly why the market-share figure itself is one of the more important indicators to watch when assessing systemic risk in this space.
If I've only staked ETH at the base Ethereum layer without actively participating in any Restaking or AVS, am I still affected by incidents like this?
If your assets remain entirely at the plain, native Ethereum Staking layer — never redeployed through EigenLayer into any AVS, and holding no liquid restaking Token — your assets theoretically aren't directly exposed to the contract-level risk behind incidents like Kelp DAO. That's a deliberate boundary built into restaking's design: whether to participate in restaking is inherently the user's own active choice, and not opting in means not directly carrying that additional layer of contract risk.
Worth noting, though: "no direct exposure" and "completely unaffected" are two different things. If the broader restaking ecosystem experiences a large-scale redemption rush following a major incident, that could still spill over into the Ethereum network itself — an unusual spike in on-chain transactions or gas prices, for instance — or affect other assets you hold that have indirect ties to the restaking ecosystem, such as mainstream DeFi protocols that themselves hold a given LRT as a significant reserve asset. That's also why understanding this ecosystem's risk structure remains worthwhile even if you're not directly restaking yourself — it helps you assess your portfolio's indirect exposure more accurately.
If I'm already Restaking or holding a liquid restaking Token, what specific steps can reduce the risk I'm actually carrying?
First, actually find out how many AVSs the operator you delegate to serves simultaneously. The more AVSs a single operator supports, the wider the fallout if that operator makes a mistake on any one of them — that's the exact structural pattern behind how risk spread in the Kelp DAO incident. Choosing an operator with relatively focused AVS coverage, rather than one spread thin across a large number of AVSs, is generally the more conservative approach.
Second, if you've layered a liquid restaking token into a lending protocol for extra Leverage, be aware you've turned what was originally a simple Staking position into a compound position spanning multiple independent contract layers — each additional layer of leverage is one more point where someone else's mistake can become your loss, and whether that extra yield is worth the corresponding compound risk deserves a fresh look rather than just eyeballing the stacked APY figure. Third, actually check how long your chosen redemption path (native, LST, or LRT) genuinely takes to return your assets under market stress conditions, rather than relying on the expected timing under normal market conditions — when you actually need the money, paper liquidity and real, usable liquidity are often two very different things.
Restaking's core pitch is simple: assets you've already staked on Ethereum don't need to be unlocked before they can also secure other services in exchange for additional yield. It sounds like a natural upgrade in capital efficiency — but the April 2026 Kelp DAO hack gave the entire industry its first real look at the other side of that design. When the same asset simultaneously backstops multiple systems, a failure in just one of them tends to ripple out well beyond the people who directly touched it, catching users who thought they'd never gone anywhere near the affected protocol.
Restaking's underlying logic rests on protocols like EigenLayer: ETH a user has already staked on Ethereum (or a liquid Staking Token like stETH) can be "reused" through EigenLayer to provide cryptoeconomic security for a category of systems called Actively Validated Services (AVSs) — data availability layers, oracles, cross-chain bridges, or other infrastructure requiring distributed verification. This lets users stack an additional layer of AVS rewards on top of their original Ethereum staking yield. The cost is that the same asset is now simultaneously exposed to each of those systems' individual risks: if the operator a user delegates to makes a mistake or triggers a penalty condition on any one of those AVSs, that same staked position can be affected.
In April 2026, the Kelp DAO ecosystem suffered a major security incident totaling roughly $300 million, rooted in a single link within the broader restaking stack — a stack that, fully unpacked, can span six or seven independent Smart Contract systems: Ethereum staking contracts, EigenLayer's core contracts, individual AVS contracts, a liquid restaking token (LRT) issuer's contracts, the LRT itself, and — if a user layered on additional Leverage by depositing that LRT into a lending protocol — the lending contract and the Price Oracle used for Liquidation on top of all that. What made this incident genuinely notable wasn't the dollar figure — it was that it demonstrated a bug in one link of the stack could trigger a run on withdrawals across other protocols that had no direct exposure to the exploited code whatsoever. In other words, even if you had never directly interacted with the specific contract that got exploited, holding an asset connected to any layer of that stack was enough to get pulled in.
EigenLayer currently holds roughly 94% of the entire restaking market — a number worth pausing on. If a single protocol carrying a massive volume of assets is itself the shared security foundation for the overwhelming majority of AVSs, then a serious vulnerability in that protocol doesn't just hit its own users; the impact radiates through the entire downstream ecosystem that depends on it for security — including the data availability layers used by several major rollups. This structure — a single piece of infrastructure carrying the security assumptions of an entire ecosystem — closely mirrors the "too big to fail" systemic-risk logic familiar from traditional finance, with the key difference being that what's carried here is cryptoeconomic security rather than clearing and settlement functions.
Withdrawal liquidity is another piece that's easy to underestimate. Unstaking from EigenLayer isn't instant — actual wait times vary depending on the delegation path (native restaking, liquid staking tokens, or liquid restaking tokens), ranging from days to weeks. Under market stress, liquid restaking tokens can also temporarily depeg from underlying ETH as secondary-market liquidity thins out and the primary redemption queue lengthens — meaning that even when the underlying asset itself hasn't been directly damaged, the actual timing and price at which a user can retrieve it can diverge sharply from what they'd normally expect.
If you're restaking or holding a liquid restaking token, the practical question isn't just "is my chosen AVS safe" — it's how many independent smart contract layers sit between your original stake and your actual exposure, since each additional layer (an LRT issuer, a lending protocol you looped into for extra yield, an Oracle feeding liquidation prices) is a separate point where someone else's mistake becomes your loss. Before restaking or looping an LRT for extra yield, check specifically how the operator you're delegating to is exposed across AVSs — a single operator serving multiple AVSs concentrates risk in exactly the way that let one exploit cascade across supposedly unrelated protocols in the Kelp DAO incident — and factor in realistic withdrawal timing under stress, not just the advertised APY, since that gap between paper liquidity and actual liquidity is where real losses tend to surface first.