A slashing reserve is the capital a staking or restaking protocol puts between a validator penalty and its depositors. It is funded one of two ways: collateral the node operator posts and forfeits first, or a treasury buffer the protocol maintains centrally. The distinction matters more than the size, because operator-funded collateral also changes operator behaviour while a treasury backstop only pays for the consequences of it.
A reserve sized against the worst single incident is not sized. Slashing penalties are built to scale with correlated failure, so the number that matters is what several of your operators can lose in the same week, not what one can lose on a bad day.
Scroll to see the full diagram
Two funding models that fail differently
The first model makes the operator post capital they lose first. Rocket Pool describes its RPL requirement as an amount, expressed as a percentage of the ETH the protocol provides, that a node operator deposits to act as insurance reimbursing regular users if the operator exits staking with less than that protocol-provided ETH.1 Its own FAQ calls the arrangement bonding or insurance that ensures good behavior.2 The exact percentage is a governance parameter and has been adjusted over time, so read it from the protocol rather than from an explainer.
The second model funds a buffer centrally and pays out of it. That is administratively simpler and it does nothing to the operator's incentives, because the operator loses nothing they posted. The reserve absorbs the outcome without touching the behaviour that produced it.
In our view a design with only the second model has bought insurance and skipped the underwriting. Operator-funded first loss is the part that changes what happens before an incident, which is the only part that reduces incidents.
Rocket Pool's waterfall, as documented
The clearest published example runs in four steps. The operator's own ETH is at risk first: Rocket Pool's glossary sets the reimbursement trigger at the operator exiting with less than the protocol-provided ETH, naming 24 ETH in the case of an 8 ETH minipool and 16 ETH in the case of a 16 ETH minipool.1 The operator's staked RPL is the second layer, described as secondary collateral usable against slashing.1
Then comes the part most protocols never write down. Rocket Pool states that it socialises any penalties or losses occurring on nodes across the whole network, which reduces the effect on any single user.2 That is a real design decision with a real cost: it converts a concentrated loss into a small loss for everybody, including depositors who were nowhere near the failing operator.
Naming the layers is the deliverable. A depositor should be able to read, in one paragraph, whose capital goes first, whose goes second, and at what point their own balance moves. Most staking products cannot produce that paragraph on request.
Burned collateral never reaches a reserve
Restaking changes the shape of the problem, because the default disposition of slashed funds is destruction rather than compensation. EigenLayer burns slashed funds for standard operator sets, sending ERC-20s to a dead address after a seven day resolution delay.3 Nothing flows to a reserve, and nothing flows to the depositor who was penalised.
Redistributable operator sets change the destination but not the depositor's position: funds go to a redistribution recipient the AVS specifies at set creation and cannot change afterwards.3 The party receiving the slashed capital is chosen by the service, not by the people whose capital it was.
Natively restaked ETH is the sharpest case. It cannot be redistributed at all and remains permanently locked in the EigenPod contract when slashed, inaccessible to anyone.3 Any restaking product promising depositor protection has to fund that protection from its own balance sheet, because the protocol's slashing path does not return capital to anybody by design.
Sizing against correlation, not per-event maximum
Ethereum's penalty structure is explicit that correlated failures cost disproportionately more. A slashed validator's day 18 penalty scales with the total stake slashed in the surrounding 36 days, so an isolated incident is punished lightly while a mass event can take the full effective balance of everyone caught in it.4 A reserve sized against one operator's worst day is sized against the cheap scenario.
The restaking version is worse, because each service adds an independent condition while the operator, client stack, hosting region and on-call rotation stay shared. Disclosures that list a maximum loss per service side by side are implicitly claiming those losses are independent. They are not, and the operator concentration entry covers why.
So the three lines we require: how the reserve is funded and by whom, what the coverage ratio is against a correlated scenario rather than a single one, and what happens when the reserve is exhausted. That last one has an answer whether or not it is written down. The failure pattern is growing a service portfolio faster than reserve capacity, so TVL and yield keep rising while backstop per unit of exposure quietly falls. This page is reference material for design work, not investment advice and not a recommendation about any protocol.
Common questions
What is a slashing reserve and who funds it?
It is the capital standing between a validator penalty and depositor balances. It is funded either by collateral node operators post and forfeit first, or by a protocol treasury buffer. Rocket Pool uses the first model, describing operator-staked RPL as insurance that reimburses regular users if a node operator exits with less than the ETH the protocol provided.1 Operator-funded collateral also changes behaviour; a treasury buffer only pays for it.
Does EigenLayer have a slashing reserve?
Not in the compensating sense. Slashed funds are burned by default, sent to a dead address after a seven day resolution delay, and redistributable operator sets send them to a recipient the AVS chose rather than back to depositors.3 Natively restaked ETH cannot be redistributed at all and stays permanently locked in the EigenPod contract. Any depositor protection has to come from the product built on top.
How large should a slashing reserve be?
Size it against correlated loss, not the worst single event. Ethereum's day 18 correlation penalty scales with the total stake slashed in the surrounding 36 days, so an isolated incident costs a small fraction while a mass event can take the full balance.4 The relevant question is what several of your operators sharing a client build and a hosting region can lose in one week.
See Tokenomics Audit for how this applies in practice.
Sources
- Glossary
Rocket Pool Docs, 2026
The insurance definition of staked RPL as a percentage of protocol-provided ETH, the reimbursement trigger of an operator exiting with less than that ETH with the 24 ETH and 16 ETH cases named, and RPL described as secondary collateral against slashing. Read 3 August 2026. - Frequently Asked Questions
Rocket Pool Docs, 2026
RPL collateral described as bonding or insurance that ensures good behavior, and the statement that the protocol socialises any penalties or losses occurring on nodes across the whole network. Read 3 August 2026. - Slashing Overview
EigenCloud, Eigen Labs, 2026
Slashed funds burned to a dead address for standard operator sets, redistribution to an AVS-specified recipient fixed at set creation, the seven day slash resolution delay, and natively restaked ETH remaining permanently locked in EigenPod contracts. Cloudflare returns 403 to automated clients; content read by stealth fetch on 3 August 2026. - Proof-of-stake rewards and penalties
ethereum.org, Ethereum Foundation, 2026
The day 18 correlation penalty scaling with total stake slashed in the surrounding 36 days, and the maximum slash reaching the full effective balance of every validator caught in a mass event.
Last reviewed 2026-08
Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.
100+ projects advised. Complete tokenomics in 4 to 6 weeks.