Restaking commits already staked capital as collateral for a second set of obligations, so the same ETH backs Ethereum's consensus and one or more separate services at once. Those services, commonly called actively validated services, each write their own slashing conditions, and a restaker opts into them by delegating to an operator that has opted into them. No new capital is created by any of this. The additional yield is the price of accepting additional ways to lose the same principal.
Restaking does not multiply capital. It multiplies claims on one pile of capital. Every service a position secures is another independent path by which the same ETH can be reduced, and the paths are not required to fire one at a time.
Scroll to see the full diagram
What is being reused, and what is not
The word people reach for is rehypothecation, and Consensys draws the distinction carefully: unlike rehypothecation, in restaking the original owner of the stake retains control, which keeps the arrangement inside the self-custody model.1 Nobody lends the ETH out. Nobody moves it into an omnibus account. Blockdaemon confirmed with the EigenLayer team that native restaked funds are not commingled, because each customer gets their own EigenPod contract.6
So what is actually being reused is not the asset. It is the slashable claim on the asset. One balance of ETH now stands behind Ethereum's consensus rules and, simultaneously, behind a set of conditions written by third parties who were not involved in the original deposit. In our view that is the sentence the category needs on the front of every explainer, because it is where the risk lives and it is not the same thing as leverage on a balance sheet.
Two entry paths exist. Native restaking points an Ethereum validator's withdrawal credentials at a restaking contract, which requires actually operating a validator. The other path deposits liquid staking tokens into the restaking protocol's contracts, which does not.1 The second path is why the liquid restaking token category exists at all, and it inherits every property of the liquid staking token underneath it.
Three parties, and only one of them is you
An AVS is a decentralized service that provides custom verification of off-chain work, built as on-chain contracts for verification plus an off-chain network of operators who execute the service and post evidence of that execution back to the contracts. If operators execute properly the service can distribute rewards autonomously; if they act maliciously their delegated stake can be slashed autonomously and the operator can be removed from the operator set.2 Worth noting for anyone reading older material: EigenLayer now expands AVS as Autonomous Verifiable Service, and current examples given are rollup services, co-processors, cryptography services and proof services.2 The term entered the vocabulary as actively validated service, which is still what most of the ecosystem says.
Operators sit in the middle. They run the software each service requires, opt into the services they choose, collect what those services pay, and share it with delegators net of commission. The restaker's role is narrower than most descriptions imply: on EigenLayer a staker must delegate their entire restaked balance to a single operator rather than spreading it.4 You pick one operator. That operator picks every service your capital ends up securing.
That structure has a name in every other industry: a two-step principal-agent problem with an all-or-nothing allocation at the first step. Design consequence for anyone building on it: the operator's service-selection policy is the actual risk document, and it is usually not published, not versioned and not governed. Whether that is acceptable depends on the size of the position, and it is a question we ask before we ask about the rate.
The layered slashing argument, stated properly
EigenLayer's own documentation puts the burden squarely on the delegator. Stake delegated to an operator becomes slashable once that operator opts into an operator set and allocates unique stake, and stakers are told they are responsible for understanding and confirming their risk tolerance for existing and future delegations, and for continuing to monitor their operator's allocations as those change across operator sets.3 Read that as a job description rather than a disclaimer, because that is what it is. The academic framing in the 2024 systematization of liquid staking and restaking is blunter, describing restaking as horizontally multiplying the stake by securing other services while multiplying the slashing risks, and noting the implicit leverage this exerts on restaked collateral.4
Work a concrete case. One validator holding 32 ETH, restaked and delegated to an operator serving three services. That balance now sits behind four independent sets of conditions: Ethereum's consensus rules plus three service-specific rule sets. If a single operator misconfiguration triggers penalties under several of them in the same incident, the loss is not the average of the four disclosed maximums. It is their sum, bounded only by the balance itself.
That correlation is the whole argument. Independent slashing surfaces that fail independently are a manageable actuarial problem. Independent slashing surfaces sharing one operator, one client stack, one cloud region and one on-call rotation are not independent in any sense that matters, and every disclosure that lists per-service maximum losses side by side is implicitly claiming they are.
Scroll to see the full diagram
The counterargument, which is also in the literature
The cascade story is not settled science, and the same systematization that raises the risk also surveys the work pushing back on it. Durvasula and Roughgarden characterize security by the buffer between attack costs and attack profits, derive explicit bounds on worst-case stake loss, and propose overcollateralization conditions that let participants prevent cascading attacks. Chitra and Pai extend that model with token incentives and strategic adversaries and conclude that restaking protocols can stay secure where incentive mechanisms are managed properly.4
Read together, the honest position is narrower than either camp's headline. Layered slashing is not automatically a cascade. It becomes one when the collateral securing a set of services is small relative to the profit available from corrupting them, which is a parameter question about a specific configuration and not a verdict on the category.
Our own view, labeled as opinion: the claim that restaking is structurally fragile is too strong, and the claim that it is free yield is considerably worse. The first is an argument about parameters that can be checked. The second is a marketing position that survives only until the first correlated incident, and it is the one we spend most of our time removing from client documentation.
The TVL number most people are carrying is out of date
As of 3 August 2026 at 13:48 UTC, DefiLlama's public data API reports EigenLayer's total value locked at $4,952,961,944, roughly $4.95 billion, under the Restaking category. The same record now lists the entity's current name as EigenCloud, with EigenLayer recorded as a previous name.5 Anyone writing about the protocol today should carry the rebrand.
Set that against the snapshot in the 2024 systematization, which recorded EigenLayer at $15.07 billion inside a restaking category totaling more than $25.2 billion and described restaking as the fourth largest category in DeFi at the time.4 The two figures come from different sources with different inclusion rules, so the comparison is an order of magnitude rather than an exact decline. Even read loosely, the direction is unambiguous.
The design consequence lands on the service side, not the depositor side. If your protocol's security is denominated in restaked collateral, your security budget is a rented number that reprices with market conditions and with whatever the next incentive program elsewhere is paying. Sizing a cost-to-corrupt argument against a peak-cycle TVL figure produces a security claim that quietly expired.
What a service is actually buying, and what it costs
EigenLayer is a marketplace between restakers looking for additional yield and services looking for cryptoeconomic security, and the mechanism it offers is pooled security: the same restaked ETH can back many services at once.1 For a service founder, that solves a genuine bootstrapping problem. Standing up an independent validator set means acquiring capital that has better-paying alternatives, and pooled security lets a new service rent what it would otherwise have to buy.
The rent is priced against the restaker's alternatives, which means it competes with base staking, with every other service in the set, and with whatever the rest of DeFi is paying. A slashing condition that is ambiguous, disproportionate, or capable of firing on operator error rather than genuine misbehavior gets declined by operators, and a declined condition means a smaller security budget, not a safer one.
The sizing test is the same one that governs any economic security argument: what does it cost to corrupt this service, and what is the profit from corrupting it. Restaking changes the numerator by letting you rent stake. It does not change the test, and it adds a term, because the collateral you rented is also answering to other people.
What we settle with founders on either side of the trade
If you are building a service that consumes restaked security, three things get written before launch. Define the slashing condition so the offense is objectively attributable onchain rather than adjudicated by a committee. State the cost-to-corrupt against a conservative collateral figure with the date of that figure attached. And name what happens to your security guarantee if restaked TVL halves, because on the evidence above that is not a tail case.
If you are building a product that puts depositor capital into restaking, count exposure surfaces rather than quoting a composite rate. The rate arithmetic belongs to the restaking yield entry. What belongs here is the reminder that the loss surface and the yield surface grow together by construction, and only one of them appears on the marketing page.
Underneath all of it sits the same question we anchor every engagement to. Rented security buys a new service time to build a business. It does not substitute for one. If the fee flow under the service never arrives, the restaking layer was a way of financing the wait. This page is reference material for design work, not investment advice, and not a recommendation about any protocol or asset.
Common questions
Is restaking the same as staking twice?
No. Staking twice would need twice the capital. Restaking keeps one balance and adds a second set of obligations against it, so the same ETH secures Ethereum and one or more separate services simultaneously.1 Nothing is lent out and the owner keeps control of the asset. What gets duplicated is the slashable claim on that asset, which is why the extra yield comes with extra ways to lose principal rather than a second income on a second position.
What is an AVS in restaking?
An AVS is a decentralized service that verifies off-chain work on-chain, made of verification contracts plus an off-chain operator network that executes the service and posts evidence back to those contracts.2 Operators who act maliciously can have their delegated stake slashed autonomously and be removed from the operator set. EigenLayer now expands the acronym as Autonomous Verifiable Service, though the ecosystem still widely says actively validated service. Current examples include rollup services, co-processors and proof services.2
How much value is locked in restaking?
DefiLlama's public data API reports EigenLayer, now recorded under the name EigenCloud, at $4,952,961,944 as of 3 August 2026 at 13:48 UTC.5 For contrast, a 2024 academic systematization recorded the same protocol at $15.07 billion inside a restaking category above $25.2 billion.4 The two use different methodologies, so treat the comparison as directional. Any restaking TVL figure needs its timestamp attached, because the number moves substantially.
Does restaking increase slashing risk?
Yes. EigenLayer's own documentation states that stake delegated to an operator becomes slashable once that operator opts into an operator set and allocates unique stake, and it makes stakers responsible for confirming their risk tolerance and for monitoring operator allocations as they change.3 A position securing three services answers to four sets of rules including Ethereum's. The concern is not the count but the correlation, since one operator misconfiguration can breach several conditions in a single incident, making the realistic loss the sum rather than the average.
What is the difference between native restaking and liquid restaking?
Native restaking points an Ethereum validator's withdrawal credentials at the restaking protocol's contracts, so it requires running a validator and the full 32 ETH minimum.1 Liquid restaking deposits a liquid staking token into those contracts instead, which needs no validator and no minimum, and issues a tradable receipt in return. The second path adds the liquid staking protocol as an extra counterparty and inherits its operator set and withdrawal queue.
See LST and LRT Tokenomics Design for how this applies in practice.
Sources
- EigenLayer: Decentralized Ethereum Restaking Protocol Explained
Consensys, 2024
The distinction from rehypothecation, the native and LST restaking paths, pooled security, and the marketplace framing of extra yield in exchange for accepting increased slashing risk. - AVS Overview
EigenCloud, Eigen Labs, 2026
Current canonical AVS definition, now expanded as Autonomous Verifiable Service, the split between on-chain verification contracts and an off-chain operator network posting evidence, and autonomous slashing plus removal from the operator set for malicious execution. Cloudflare returns 403 to automated clients; verified live by stealth fetch on 3 August 2026. - Slashable Stake Risks
EigenCloud, Eigen Labs, 2026
Delegated stake becomes slashable once the operator opts into an operator set and allocates unique stake, and the protocol assigns stakers responsibility for confirming their own risk tolerance and monitoring operator allocations on an ongoing basis. Cloudflare returns 403 to automated clients; verified live by stealth fetch on 3 August 2026. - SoK: Liquid Staking Tokens (LSTs) and Emerging Trends in Restaking
arXiv preprint 2404.00644v3, 2024
Whole-balance delegation to a single operator, the multiplied-slashing and implicit-leverage argument, the 2024 TVL snapshot, and the survey of Durvasula and Roughgarden and of Chitra and Pai on bounded worst-case loss and incentive design. - EigenLayer protocol TVL, public data API
DefiLlama, 2026
Total value locked of $4,952,961,944 read on 3 August 2026 at 13:48 UTC, category Restaking, current entity name recorded as EigenCloud. This is the data API behind defillama.com, whose web interface blocks automated clients. Figures update continuously. - Restaking with EigenLayer
Blockdaemon, 2024
Per-customer EigenPod architecture and the confirmation that native restaked funds are not commingled.
Last reviewed 2026-08
Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.
100+ projects advised. Complete tokenomics in 4 to 6 weeks.