How much security does your restaking protocol really need? by Tarun Chitra | Devcon SEA
Devcon·Tue, Oct 7, 2025, 12:00 AM
Speaker
Restaking protocols have aggregated millions of ETH with the hope of securing new infrastructure on Ethereum. These services, such as ZK provers and oracles, require restaking ETH to enforce custom slashing rules. But how much ETH do these services need? And how much risk do these services place on Ethereum L1? We will formulate a mathematical model for answering these questions and present an empirical analysis of cascading risks from restaking services to Ethereum, with a positive outlook! Speaker(s): Tarun Chitra Skill level: Expert Track: Cryptoeconomics Keywords: Staking, Censorship Resistance, Economics, Restaking, proof-of Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] [Music] um so I think uh you know in the in the kind of current ERA there have been a lot of new protocols that are being built on top of ethereum um some of them are rollups as many of you know and some of them are sort of these kind of new kind of amphibious things that are are sort of known as avss or networks or services so natural question you might say is you know what's the difference between these you know when do I need to pay for a rollup security when do I need to pay for something that's less and how do I quantify that so um there's sort of three things we'll talk about we'll talk about reaking sort of being a a a matching Market uh we'll talk about how to think about threat models for determining Economic Security and then finally we'll talk about how do you quantify that and so most of this talk they're bunch of papers that have sort of the formal results but this is sort of going to give a high level description so uh a natural question is is what is a matching market so matching Market uh kind of the most common one people think of is uh in this example sort of matching uh partners and so each person has a preference and based on their preferences you can kind of construct this graph and then try to find a valid uh matching and so it's sort of a a natural thing where you want to match two different types of goods one side that's the supply side and one side that's demand side uh of course I guess in the the dating one it maybe they're both symmetric hopefully uh but you know what is a matching market so matching markets are are sort of things that are studied in economics but also used in practice a lot so uh probably the most famous type of matching Market is the kidney exchange so this is for people who need kidney transplants uh you know maybe maybe I I had some type of accident I need a k kidney transplant but I can't just take any kidney there's some constraints on it it has to be a certain size it has to be the right blood type it has to to have have a bunch of different things uh and so there are people who are donors who are willing to donate kidneys and then people who need kidneys and there's sort of you'd be surprised but there are algorithms for kind of matching them but the main thing to think about is there's a supply of inhomogeneous goods I.E people whose kidneys have some properties uh you know blood type size Etc um the key thing is there there there there's some similarity between them they're all kidneys but they have some special properties and then there's sort of demand which is people who kind of want to to to to receive those so you know in crypto you hear a lot about auctions uh in fact someone yesterday told me they were surprised I went in an hour without saying the word auction which I felt embarrassed about but uh so you might say you know how do how do how do matching markets compared to auctions so matching markets are sort of more focused on stability uh under to perations of uh different kind of mechanisms versus auctions are focused on things like maximizing revenue or maximizing welfare um so for instance a matching may prefer to to to sell all Goods to all people participating even if it's doesn't maximize the amount of money that's transferred and in crypto we have a bunch right we have me auctions for the auction side we have intents and also restak for matching markets so natural place to to kind of formalized matching markets is is using graph Theory using sort of bipartite graphs where the idea is you have one side that is the set of suppliers the different types of supply and the other side is the types of demand um but in most classical matching markets um you this graph is sort of static IE the set of people who want kidneys or need kidneys is fixed and there's usually a Central planner now decentralized matching markets don't have either of these features um because people can join and leave whenever they want they can change their demand whenever they want and this is why uh you know we we need to start a little bit by thinking about reaking in terms of being a decentralized matching market so uh decentralized matching Market you can have the supply side and demand side join and leave at will and so a natural question is you know why are these harder to to to analyze how are they harder to analyze uh first off if people can can join and leave you can get matched and unmatched um which means that you have to consider kind of worst case Dropout from different participants um the second thing is without having a central planner uh without having kind of like the National Kidney registry you rely on how you pay incentives fees token incentives Etc to get people to to figure out the matching and finally you sort of need a explicit adversarial model so um you need to kind of model all the different types of attx so just to to to to kind of explain how restak looks like a matching Market um you know restak is really focused on people who are running ethereum validators who are offering to run extra services so you can kind of think of them as the supply side and the demand side are are services like these abss so you know a natural question that I think is a meme in a lot of ways uh is is Economic Security uh as you can see from from this there's many varying definitions um but we'll take a tiny detour to talk about Economic Security and then after that and sort of how to compare Economic Security between rollups and reaking and then kind of talk about the the kind of risks in reaking so a natural question is is what does it really mean to have Economic Security so you know the classical definition in proof of stake is oh onethird of the total amount of stake is enough to corrupt the network well that's true that's true for a double spend but suppose I want to do an oracle manipulation attack it might be much cheaper so uh defining Economic Security in absolute sense sorry about the font color there um is actually quite difficult um partially because you have things like me uh you have to think about the attack space Sorry all right well I guess we got a little ahead of ourselves um but basically there's there's sort of a bunch of different things you have to consider so so there's a lot of different attacks there's sort of meev there's attacks that come from uh competitive pressures uh between networks um for competing for the same fees um but generally we try to think of the the cost of an attack as sort of something bounded by a sort of linear function of the the the numer I maybe stable coin maybe Bitcoin whatever your your choice of numerar is value of the so in this uh figure we have the amount of asset Stak we have the price of the asset we have a notion of the expected time it takes to execute an attack uh this is sort of a measure of opportunity cost and then we have a sort of fixed constant upfront that's sort of what fraction of the network you need to execute the attack so the natural question is what does economic security look like for reaking so in reaking oh o hopefully this is not uh there are two competing pressures um the first pressure is if people see higher yields from reaking they purchase some fraction of stakes so they increase the uh amount staked by a multiplicative Factor Delta on the other hand uh the slash Stak so if if you know you get slash for a kind of penalty in the AVS the slash stake reduces uh your overall network security so here is something that looks a little more uh mischievous but let's go through the terms so so CR is the the sort of cost uh kind of attack cost for reaking so first we have a risk measure so this is sort of a measure of how much stake what fraction of stake do you expect to be slashed the second is we have a notion of a price impact function so all of these people who are who were not staking in the network but they see the excess yields from restak they actually go and buy stake so they increase the numer value and this sort of abstracts as to to this function G that's sort of a price impact function uh and uh basically the idea here is if we look at this this cost says there's two competing forces one is the risk measure so how much gets slashed and the other stuff is about how you increase the value of the the stake so the natural question ask is when is raking safe um so reaking can be kind of thought of as safe when you have this invariant where like the cost of attack in the reaking network is greater than the cost of attack uh without the reaking network uh if we write out the previous equations we get this condition which says Hey the risk this risk term the amount that has to be slashed the maximum percentage that can be slashed is bounded in terms of this sort of price impact like how much more people are new buying new stake to participate so there's sort of this dependence on on on how how elastic borrowers are to the incentives I.E the new fees so we'll make a tiny detour and make a comparison to rollups um so rollups have a number of sort of natural economic tradeoffs within ethereum um a lot of the execution Revenue now goes to the rollup a lot of the meev revenue goes to the sequencer um again sorry about the the font I didn't expect this um the uh da Revenue which is you know blob space can be dwarfed by execution Revenue so a natural question is when do rollups if I have a a set an L1 with n Roll-Ups when does the does that Network break even with the monolithic L1 so a paper that I have coming out soon kind of shows for n Roll-Ups in under a bunch of kind of generic assumptions you actually need N squared more Revenue so you can kind of think of this as a sort of inverse Metal's law so Metal's law is sort of a kind of heris Network law that says I have n participants in network the total value they they get is sort of Omega of n^ s uh this sort of says that's true for the rollup users but the L1 is sort of paying the the price and that's sort of what this result shows now you might say well how much re how how does the revenue from avss compensate for reaking risk and um it turns out that if you have s s sorry I just say SS's you only need this kind of factor that's decaying in the number of Serv so what this says is reaking actually can provide a lot of value to the L1 and sort of increase it its monetary premium in a way that's very different from rollups so the main thing in this entire line of logic is that the risk this r factor is sufficiently small right you need to not have slashing that Cascades in order for the the value for the reaking network to be higher than the underlying so natural question is how do you model that risk in in the the previous example it sort of relied on this notion of are the incentives high enough for people to buy more stake and and and deposit um and so a natural thing to do is to to now think about how how to model this formally and again this talk has none of the proofs but the you can find them on archive I should have put a QR code my bad so what does this look like abstractly mathematically um so the the basic construct is what's called a reaking graph rest taking graph like the matching Market graphs is a bipartite graph in this bipartite graph one of the bipartitions is the set of node operators that's the set V each of the node operators uh it's a a Vertex label that is stake which is how much stake each of them have there's a set of services s this the avss there's a set of profit from attacking so this is sort of if I attack the network what's the maximum profit I could get there's a set of corruption thresholds so this is you know in in bft protocols one3 is sort of this 1/3 of bft stake needs to be aggregated to do a double spend or in the longest chain this is the 1/2 that's sort of how you can think of these and one key difference between this reaking and proof of stake is you can have the same node operator operate multiple services with the same stake so that is represented by this middle thing so this uh operator labeled V intersection you can think of as taking its five ethereum of stake and operating both Services S1 and S2 too so you might say hey is this thing real like do these graphs exist this is the live I reaking graph from I think May to August and you can see uh basically on the left are the node operators uh who are ethereum validators who are also running these services on the right are the different Services um there's actually far more services now I think it's about double the number so this graph is a lot more dense than uh what you see here so when we talk about risk we need to also talk about what it means to be an attack what does an attack against three saking graph look like so the idea is you a need to be profitable so that means the maximum profit for attacking a set a of services has to be greater than the maximum slashing penalty for a group of validators who are colluding to attack uh so this kind of says even if I get lose my stake from doing the bad action The Profit that I get is higher so this is what it means uh for a profitable attack the second thing is a feasible attack a feasible attack says that for every service that's being attacked the amount of stake that the cartel that's attacking the group of validators who attacking that service have is greater than the threshold times the total stake of that service so it says for instance if there's two services in our previous example one that has Alpha is 1/3 one that has Alpha is 1/2 the attacking cartel has to have at least 1/3 staken uh set one and one half taken set two uh so you can write this in symbols uh using this this way this comes from sort of the IG white paper appendix B uh and then it was sort of cleaned up more by D and rough Gard which sort of lays out the initial version of this so unlike proof of stake the interesting thing here is is to how to think about tax here so here every service is actually over collateralized so service one there's a profit of four uh and stake of six that could be lost um so uh it's not worth attacking and service two uh the same thing however if all the validators collude it's actually profitable to attack both Services simultaneously and so this sort of says that unlike proof of stake where you're isolated proof of stake is sort of a graph with one service when you have multiple services and you share you can have these kind of profitable attacks from from the shared stake so what does this look like what does sort of the bad case that this look like so what we're going to talk about is something known as a cascading attack so a cascading attack is some validator somehow drops out maybe they're dosed maybe they lost their stake maybe they committed a infraction that got themselves slashed and they get knocked out now by them being knocked out they open up an attack against the service that they were validating so in this case you can see the middle node operator attacks the service and then once the middle operator attacks the service they open up an attack on the other service and now you can see that the entire stake has been burnt so this is the wor case this is R equals 1 in the previous example and you can think of this as the proof of stake analog of like a lending liquidation Cascade or Perpetual liquidation Cascade so how do we Define these uh so we take sets of services and operators where each of them is a feasible attack after uh the previous attacks are executed and we Define this quantity RI which is the maximum percentage of stake that can be lost due to initial loss of sign that's how you write it formally but don't worry about that so you might say hey this tells us how much money we have to spend to secure an AVS if we're willing to if we only want we we we choose a sigh such that our sigh is less than some threshold so maybe I want that to be less than 5% maybe I want that to be less than 10% so this gives you a concrete way of computing how much security you need unfortunately there's a a bad news which is uh this this result which says there's an infinite family of restak graphs which you burn the whole stake that have the Cascades like we saw uh in the effort sense of time I won't talk about it but this is sort of what they look like U where the the dots are validators and the boxes or Services uh but there's a slightly less bad news which is uh a theorem from this paper that says uh RI is actually bounded if the system is really over collateralized and we won't talk exactly about what the definition is but this is sort of you can interpret this as the proof of stake analogy of a decentralized coin needs to be sufficiently over collateralized to avoid cascading deegs the problem is this over collateralization condition is so strong that each service needs stake potentially proportional to the sum of all the profits so as an example imagine I have the network with two Services where one of the profits is one eth and one is a million eth well the one e service needs to attract a million and one e to be secured to cascading attacks under this overcloud realization definition that's not good right like if if if I'm a service whose Pro Max profit is one eth there's no way I can attract that much I'm not going to generate that much revenue so you might say okay is this like bad does this mean abss are kind of hard are we never going to be able to control this risk so that we can get this kind of safe cost of attack that we started talking about uh and the key here is to consider the incentives so what we do is we now consider incentives that are paid so think of this as like block rewards that are paid by service to the validators and then we also allow the validators to adjust their stake um in response to the rewards so they can change which services are validating uh and what you can show is this this sort of lets you halt some of these cascading attacks and the key things to know about this are we we kind of include some notion of a cost of attack if an adversary is attacking a bunch of services simultaneously it costs them more than if they were just attacking one um and so so having this cost actually uh we sort of is more realistic than the the ruard model the second thing is we assume the node operators are smart they are looking at the rewards and they're selfish and they're like how do I optimize my payout and if you get this you know our result is basically you can bound this risk this RSI um in in a way that decays in the number of services um and so uh there's also a way to approximate this so the interpretation is if adversaries who are attacking face costs if node operators are smarter and if avss and services can pay sufficiently high rewards the risk is small so that actually means you can you can actually have these things be safely added to your network and they generate Revenue so how do you reduce this in practice uh so IG proposed a new mechanism recently which is uh called unique stake again sorry about my font uh where each service is allowed to say some fraction of any stake that is delegated to to my service only I can slash someone else can't slash it uh which sort of caps the overlap like how much a single validator can share their stake across multiple Services um and if you use this you can sort of get very nice verifiable proofs that the risk is small and you can think of these as sort of verifiable capital requirements and with that I'm ready for questions I think wow thanks for the very informative session ter if I could invite you to stand in the middle sounds good to answer the questions so we have one question so far please feel free to continue submitting more but the first question what's the tldr what's the main takeaway that you want people to know main takeaway is reaking networks generally if you can bound the risk that they create like from this stuff we were analyzing they're actually very good Revenue generators for l1s they generate sort of premium for the L1 token it's a little bit it actually somewhat counterintuitive but the result is that they actually generate more value with a small smaller number of services that generate fees than rollups you actually need way more rollups to generate you we need way more fees from rollups to compensate the L1 um whereas in in in reaking it's it's it's actually a lot lower and so the the point is this is only true if this risk is bounded that's sufficiently small and so you know most of this result is like how do you show that risk is small under what conditions is that risk small and that's that's kind of what we're sh which is basically that validators are need to be active management uh and uh the adversar is face cost all right so we see a couple more questions coming in um let's go to the first one so should we Advocate or enshrine reaking protocols then yeah so this is a great question I uh you know I I I'm not sure about the the the political Liberty on this but I actually think reaking protocols because they generate so much revenue potentially for the L1 it actually does make sense in a lot of ways for them to be Ed um of course you know you also have to keep in mind all of these extra risks you have um and so I think it would take a lot longer for the L1 to really be able to justify it um but yeah okay so we see a couple more that's coming up I'll read the the one so what do you think about asset migration from one reaking protocol to another yeah great question um so I think like in a world where there's no restrictions there no unbonding time where you can immediately move your stake you have a lot of problems where you can open up attacks um but generally if you look at symbiotic igen lay jeto all all of the the major reaking networks are actually giving have have sort of unbonding times and and and sort of friction for you moving between them uh and that friction is actually quite important uh to for their security in a lot of ways um and I think this is one of the reasons it might not make sense to enshrine right now uh it's probably better to see how these different reaking networks work in practice how much revenue they generate and then over time figure out how to internalize them but I think reaking is a little bit different than me in the sense that it's not really parasitic to users unless you have these cascading slashing events uh and so so as long as you limit those it's just more money for the L1 stakers okay um yeah great answer so wait that's a couple more I and we still have time as well so let's talk about can you go over the one e and 1 M example again for sure so yeah imagine have two Services um you know let's let's take two avss let's say one is igen Da and let's say the other one is uh an Oracle and let's suppose that you know I da doesn't have that much in fees right now now and the the the max profit you get from getting the validators to collude to attack it is 1 e on the other hand suppose the Oracle is tied to a perpetuals exchange so if I could manipulate the Oracle I can cause a price to to to move a lot and then I can earn a lot of profit and imagine you could earn one million E from that now if these were two separate proof of stake networks like the da network was its own POS Network and the uh uh Oracle network was its own POS Network then the cost of attack is or the amount of stake you need should somehow be proportional to the profit so for the Oracle I would need a million eth for the uh uh uh da layer I would only need one eth but if they're used in reaking and they have a lot of overlapping validators the one e service the one that has one e of aack profit has to pay has to attract an amount of stake that's equal to 1 million and 1 E so the sum of their profit if they have a lot of shared validators and this is because if the shared validators get slashed it kills both of them at the same time it doesn't just kill one of them and so so this is sort of one of the reasons you in the worst case you have this additive Behavior okay I think we have um short wo um uh I like to thank tun for the questions please give him a round of applause
Automatic transcript — names and jargon may be misspelled.