Over the past two quarters, the aggregate reward rate paid by active validated services on EigenLayer fell below 1.5% annualized. Restaked ETH did not fall. It kept climbing.
Two lines crossed and stayed crossed. AVS-denominated rewards, measured against the capital that secures them, now sit below the risk-free rate available on tokenized treasury products in the same jurisdictions where the bulk of that capital is domiciled. Restakers are paying a spread to provide security. Most have not run the arithmetic that reveals it.
There is no exploit here. No oracle failure. No governance coup. This is arithmetic — the one failure mode that no audit can patch, because the contracts are executing exactly as written. Incentives break before code does. My last three research notes were about protocols that failed. This one is about a protocol that is working precisely as designed, and that is the problem.
Restaking began as a capital-efficiency argument. If ETH already secures consensus, the same ETH could secure middle-layer services — data availability, oracles, bridges, keeper networks — through reuse of a single stake and an additional slashing condition. EigenLayer productized this into a marketplace with three roles. Operators run services. Restakers delegate stake. AVS teams pay for security.
The design is elegant. The incentive map underneath it is not.
Between 2024 and 2026 the market filled with points programs, airdrop expectations and pre-token commitments. Restaked TVL became a scoreboard, and scoreboards are easier to grow than revenue. Capital arrived years ahead of the services that needed it. Most of that capital was not economically motivated. It was narrative-motivated, chasing a distribution that might eventually clear its own opportunity cost.
Then the tokens launched. Then the tokens fell.
Now the market is sideways. ETF flows are steady but not accelerating. Global M2 has expanded again, but velocity is landing in short-duration instruments — T-bills, money market funds, tokenized treasuries — rather than long-duration crypto risk. In a chop, three variables determine survival: real yield, collateral quality, and unwind cost. Restaking is being repriced against all three at once, and only one of them is visible on a public dashboard.
Start with the denominator, because almost everyone counts it wrong.
The headline metric is restaked TVL. It counts ETH deposited into a restaking contract. It does not count ETH that is economically committed to securing anything. Those two sets are not the same, and the gap between them has widened for six consecutive quarters. Deposited ETH sits in a strategy contract behind a withdrawal queue that ranges from seven to fourteen days depending on operator and AVS composition. Economically committed ETH carries an active slashing condition across one or more services. My own tracking puts the ratio near 3:1 — three units of TVL for every one unit a rational attacker would actually have to corrupt.
That ratio is the security budget. Not the TVL.
Now the numerator. AVS fee revenue splits into two buckets: payments denominated in ETH or stablecoins, and payments denominated in the AVS's own token. The first bucket is real but small — my model puts aggregate annualized ETH-denominated AVS fees in the low nine figures against a restaked base in the mid eleven figures. The second bucket is larger and largely fictional, because it is paid in assets whose circulating supply is thin and whose price is down 60% to 90% from launch-week marks.
This creates a structural mismatch the industry has been slow to name. A restaker posts collateral denominated in ETH and accepts slashing risk denominated in ETH. The reward for that risk arrives denominated in an illiquid altcoin. You are underwriting an ETH-denominated liability and collecting an altcoin-denominated premium, and the correlation between the two approaches one in a drawdown — precisely when the premium is needed. In 2020, I built a risk model to value Uniswap V2 pools and wrote a note titled "The Fragility of Algorithmic Yields." The shape of that failure is familiar: a yield manufactured by emissions rather than earned by revenue. It looks stable right up until the emissions stop.
Then there is correlation, the part no dashboard captures.
Slashing risk in restaking is typically modeled per-AVS, as though each service were an independent draw. It is not. The top decile of operators by delegated stake runs a meaningful share of all active AVS simultaneously. They share hardware, key management, monitoring stacks and — critically — personnel. A fault in one operator's key custody is not a fault in one AVS. It is a fault in every AVS that operator validates for, at the same moment, on the same block.
Restaking does not diversify risk across services. It concentrates a single operational failure into a portfolio-wide loss. The math looks like hedging. The structure is the opposite. When I audited the Golem distribution logic in 2017, the vulnerability I found was an integer overflow — two individually safe operations composing into an unsafe one. Restaking has the same compositional property, relocated from arithmetic to incentives.
Be precise about who the counterparty is. Restaking is, functionally, a reinsurance market. Restakers sell tail protection. AVS buy it. In any reinsurance market, the premium must exceed expected loss. If aggregate premium collected across all restaked ETH sits under 1.5% annualized while modeled expected loss — slashing plus correlated operational failure plus exit illiquidity — is anywhere near that figure, the market is not pricing risk. It is pricing hope. Volatility is the tax on uncertainty, and restakers are currently paying that tax in ETH in order to collect it back in altcoins.
Where does genuine demand exist? In my 2026 review of Render Network's transition to a decentralized GPU mesh integrated with AI inference, I found a real one. Verifiable compute requires verification, and verification requires an economic bond a market can actually slash. That is a service with a paying customer and a calculable cost of corruption. I also found a latency bottleneck in the consensus path that would have broken real-time inference attestation, and the v3 zero-knowledge proof optimization the cryptography team and I proposed exists precisely because the demand was real enough to be worth optimizing for.

The lesson generalizes. The only AVS with sustainable fee revenue are those whose customers need a verification they cannot perform themselves. Inference attestation qualifies. A generic DA service does not. Of roughly forty AVS in production, a large majority are data-availability-adjacent, and their combined throughput is a rounding error against what a single Ethereum blob target supports at current utilization. Dedicated DA is being purchased largely by teams buying airdrop eligibility, not bandwidth.
That distinction determines which half of this market survives the next eighteen months.
The consensus fear is a slashing cascade. One AVS is exploited, correlated operators are slashed across the board, restaked ETH unwinds into a fire sale, ETH breaks down. This scenario gets modeled, stress-tested and hedged. Legible risks are cheap to hedge and therefore already priced.
The likelier path is quieter and worse. It is a liquidity drain that never appears on a dashboard.
Operators rotate off low-paying AVS without announcement. Restakers whose points expectations have expired exit through withdrawal queues and simply do not redelegate. The security budget thins in increments too small to trip any monitoring threshold. No alarm fires. There is no exploit to write up and no post-mortem to publish. The AVS that remain become cheaper to corrupt in expectation — not because a component failed, but because the marginal cost of buying enough stake to attack fell below the value of the attack.
Contagion in this model is not a cascade. It is a slow leak. Incentives break before code does, and they usually break in the direction nobody modeled, because nobody was paid to model it.
The second blind spot is on the demand side. The industry assumed restaking demand would come from services that need security. In practice, a growing share came from services that need a token narrative. When the narrative stops paying, that demand does not rotate into other primitives. It disappears.
The governance layer that might catch this is not structured to. The committees approving AVS onboarding have run delegate turnout in the low single digits for consecutive cycles, with the same small set of addresses appearing across the top decile of proposals. That is not a decision process. It is a filter operated by the parties with the most exposure to the outcome.

The question for the rest of this cycle is not whether restaking survives. It will survive. The question is what it looks like when points programs stop subsidizing the security budget.
Watch the ratio, not the total: AVS revenue net of token emissions, divided by economically committed stake. If that ratio keeps falling while restaked TVL keeps climbing, the market is paying for a service nobody is buying.
Incentives break before code does. Volatility is the tax on uncertainty. Right now restakers are collecting the tax without ever receiving the premium — and the queue to exit is already seven days long.