The $13 Billion Lesson in Risk Layering
On April 19, 2026, attackers stole $292 million in liquid restaking tokens from Kelp DAO's bridge and used them as collateral to borrow funds on Aave. Within 48 hours, $13.2 billion evaporated from DeFi's total value locked. Aave alone lost between $6 billion and $8 billion in deposits. The exploit exposed what researchers had warned about for two years: restaking multiplies failure points, and when one layer breaks, the damage cascades. The incident contributed to crypto's mounting security losses in 2026, but the contagion effect made it distinct from isolated exploits.
Restaking emerged as DeFi's newest yield mechanism in 2024, allowing users to deploy the same capital twice to earn multiple streams of rewards. By 2026, EigenLayer held over $20 billion in restaked ether, and liquid restaking protocols managed an additional $8 billion. The Kelp incident proved that layering yields also layers risks, and a breach at one level can unravel positions across the entire stack.
What Restaking Actually Does
Restaking takes cryptocurrency already locked in one staking arrangement and assigns it to secure additional protocols. On Ethereum, validators lock 32 ETH to participate in consensus and earn staking rewards of around 3% annually. Restaking lets those same validators pledge their stake to smaller applications, called Actively Validated Services, in exchange for extra fees.
EigenLayer founder Sreeram Kannan framed the concept as shared security. Instead of 100 separate blockchain projects each raising $1 billion to secure themselves independently, they could share access to $100 billion in pooled stake. An attacker targeting any single protocol would need to compromise the entire pool, raising the cost of an exploit far beyond what most small networks could afford on their own.
The mechanism works through a registry. Validators who have already staked ETH opt into EigenLayer and select which AVSs to support. Those services pay fees for the borrowed security. Validators collect both their base Ethereum staking yield and the additional fees from restaking, layering one income stream on top of another.
Liquid Restaking Tokens Enter the Stack
Direct restaking through EigenLayer requires running a validator, which demands technical expertise and a 32 ETH minimum. Liquid restaking protocols like Ether.fi, Renzo, and Puffer removed that barrier by acting as intermediaries. Users deposit any amount of ETH or liquid staking tokens, the protocol handles the restaking, and users receive a tradable receipt token that accrues the combined yield.
The model mirrors Lido's approach to liquid staking, which turned locked ETH into stETH that could be traded, borrowed against, or deployed into other DeFi protocols. Liquid restaking tokens like rsETH and ezETH did the same for restaked positions, unlocking capital that would otherwise sit idle in a validator.
By April 2024, Ether.fi held over $3.2 billion, Renzo had $2 billion, and Puffer managed $1.3 billion. Kelp DAO, which issued rsETH, accumulated $740 million in deposits. These tokens became accepted collateral across DeFi lending markets, embedding restaking exposure throughout the sector.
Where the Cascade Started
The Kelp exploit targeted the bridge that moved rsETH between blockchains. Attackers drained 116,500 rsETH, worth roughly $292 million, and deposited the stolen tokens as collateral on Aave V3. They then borrowed $196 million in wrapped ether against that collateral, creating bad debt the moment the theft became public.
Because rsETH represented a claim on restaked ether held by Kelp, the stolen tokens lacked legitimate backing. Lending protocols had accepted them at face value, pricing in the yield from restaking but not the risk that the underlying bridge could be compromised. When the exploit went public, Aave faced a shortfall: borrowers had withdrawn real ETH against collateral that no longer pointed to anything of value.
The fallout spread beyond Aave. Users withdrew deposits from Euler, Sentora, and other lending platforms, even where those protocols had no direct exposure to Kelp. Total DeFi TVL dropped from $99.5 billion to $86.3 billion in two days. One analyst compared the event to depositing counterfeit currency at a traditional bank and walking out with a real loan, except that in DeFi, the counterfeit collateral sat on-chain for anyone to borrow against before the fraud was discovered.
The Structural Risk That Surfaced
Liquid restaking tokens sit at the end of a dependency chain. At the base layer, validators stake ETH to secure Ethereum. EigenLayer restakes that ETH to secure AVSs. Liquid restaking protocols wrap the restaked position into a tradable token. DeFi lending markets accept that token as collateral. Each step introduces a new point of failure, and a breach anywhere in the chain invalidates every layer above it.
The Kelp bridge was not a smart contract bug in the usual sense. According to research head Peter Chung, the issue originated in the verification layer of the cross-chain bridge itself. That meant the rsETH tokens were legitimately issued and traded, but the assets backing them disappeared in transit. By the time the gap was discovered, those tokens had already been deposited as collateral, borrowed against, and traded across multiple venues.
Aave's exposure was concentrated in the WETH market, which represented 39.49% of all loans on the platform. The rsETH-WETH lending pair was one of the largest, so the hack hit the most liquid and widely used part of the protocol. Altcoin Sherpa noted that Aave functions as the backbone of DeFi, with forks of its lending model running across dozens of chains. A contagion event there signals fragility across the entire system.
Slashing Remains Theoretical
EigenLayer's original design included slashing, the same penalty mechanism Ethereum uses to punish validators who misbehave. If an operator signs conflicting blocks or fails to validate correctly, a portion of their stake gets burned. Restaking was supposed to extend that mechanism to AVSs, so a validator who compromised one service would lose stake across all of them.
By mid-2024, slashing had not yet been activated. AVSs could register with EigenLayer, but they could not impose penalties on operators who failed to perform. That left the security model incomplete. Validators earned fees for restaking, but faced no downside risk if they neglected the services they were supposed to secure. The Kelp incident unfolded before slashing went live, so the theoretical deterrent against cascading failures had not been tested.
Slashing introduces its own cascade risk. If one operator faces a penalty, the damage propagates to every AVS they support. A single mistake or malicious act could wipe out stake that was supposed to secure dozens of independent protocols. The feature that was meant to enforce accountability also concentrates risk, turning isolated failures into systemic ones.
The Points Economy Drove Growth
Most of the capital that flowed into restaking in 2024 and early 2026 was chasing points, not yield. EigenLayer distributed unvalued scores to users who deposited funds, with the implicit promise that those points would convert into airdropped tokens. Liquid restaking protocols layered their own points programs on top, creating a speculative stack where users accumulated multiple sets of credits hoping for future payouts.
The incentive structure lacked economic grounding. Users were not earning real fees or interest. They were accumulating claims on potential future distributions, with no disclosed formula for how points would translate into tokens or what those tokens would be worth. When the EigenLayer and Renzo airdrops eventually launched, allocations disappointed participants who had expected larger shares, and the points economy lost credibility.
The Kelp hack occurred while much of the restaking market still operated on speculation rather than realized returns. That meant many depositors were exposed to layered technical risks in pursuit of rewards that had not yet materialized and might never match expectations.
Restaking After the Kelp Event
The April cascade did not kill restaking, but it forced lending protocols to reassess how they price risk. Accepting liquid restaking tokens as collateral now requires evaluating not just the base asset and the restaking protocol, but also the security of any bridges those tokens cross, the operators running the validators, the AVSs being secured, and the potential for slashing once that feature activates.
EigenLayer's TVL peaked above $20 billion in mid-2024, but the protocol remains the dominant player in the restaking sector. Liquid restaking platforms continue to offer tradable wrappers around restaked positions, and new AVSs are launching to use that pooled security. The infrastructure exists, but the Kelp incident demonstrated that yield layering and risk layering are the same mechanism viewed from opposite directions.
For users, restaking offers access to multiple income streams from a single deposit. Across the broader market, it concentrates failure points. A hack that targets staked ETH only affects validators. A hack that targets liquid staking tokens affects everyone holding stETH or similar wrappers. A hack that targets liquid restaking tokens, like the Kelp exploit, ripples through lending markets, triggers cross-protocol withdrawals, and exposes systemic dependencies that were invisible until the breach occurred.
The April event remains the clearest example of what happens when those dependencies break. The stolen rsETH was used to drain real value from Aave, which triggered a confidence crisis that spread to platforms with no Kelp exposure at all. The $13.2 billion drop in DeFi TVL was not just the direct cost of the exploit. It was the market pricing in the realization that restaking, for all its yield potential, had turned isolated risks into a contagion network.
Restaking works by sharing security. The Kelp cascade showed it also shares failure.