Skip to content

Tech deep dive · Economic & Game-theoretic · 14 min

Bonded Work & Cryptoeconomic Security

How restaking and shared security let one stake back multiple services — and the risks of correlation.

On this page
Why this matters

Every chain rests on one idea: whoever does the network's work posts a deposit that is destroyed if they cheat. Shared-security systems — Polkadot's relay chain, Cosmos's Interchain Security, Ethereum through — stretch one deposit across several services. That makes new services costlier to attack, but lets one failure hit many of them together. Understanding the overlaps is the only way to judge what “secured by $X of stake” really means.

Standard Explanation

Bonded work means locking up collateral (a bond or stake) for the right to do a job — producing blocks, signing bridge messages, reporting prices — under rules that destroy () the collateral if you break the protocol. Honesty is enforced by economics, not by trusting who the participants are. reuses one pool of bonded stake for several services, so each need not build its own validator set.

What bonded work means

A bond makes participation costly, so no one can cheaply fake thousands of identities, and it gives the protocol something to take away. A who signs two conflicting blocks, or a bridge operator who signs a false withdrawal, leaves cryptographic evidence; the protocol checks it and burns part or all of the bond.

The EigenLayer whitepaper calls the goal cryptoeconomic security: guarantees that hold because breaking them costs more than it pays, not because enough participants are altruistic.

The security budget: cost vs. profit of corruption

Two numbers define the budget:

  • (CoC) — the least an attacker must lose to break a security property. In a bonded system, mostly the stake that would be slashed.
  • Profit from corruption (PfC) — the most an attacker could gain by breaking it: funds stolen from a bridge, trades rigged with a false price, and so on.

A system has robust security when CoC is much greater than PfC. So the size of a stake alone tells you little; what matters is the stake relative to what it protects. A billion dollars of stake guarding ten billion of bridged assets is not safe. PfC is also harder to know: it grows with the value flowing through a service, often unnoticed.

Sunk cost vs. slashable bond

builds its budget differently. Miners spend on hardware and electricity, and an attacker must out-spend the honest hash power. That cost is sunk — the protocol has nothing to take back — and after an attack the attacker still owns the machines and can attack again. Vitalik Buterin calls this “spawn camping.”

In proof of stake the security sits in a bond the protocol controls. When an attack leaves attributable evidence — validators signing two conflicting histories, say — much of the attacker's stake can be destroyed automatically, so they cannot simply try again with the same capital. And because deposited coins, unlike mining chips, do not wear out, a given level of rewards buys more attack cost.

This is also why security can be shared with bonds but not with hash power. The EigenLayer whitepaper compares restaking to merge mining, where Bitcoin miners also mine a smaller chain: if they attack it, nothing is taken from them and their hardware keeps its value. With restaking, misbehavior on the smaller service can be proven and punished on the main chain's stake.

Ethereum adds a twist that matters later: a slashed validator also pays a that grows with the total stake slashed in the same window of roughly 36 days. It is about three times the slashed share of all stake, so if a third of all stake is slashed together, every offender loses everything — a lone misconfigured node is punished lightly, a coordinated attack as hard as possible.

What can be slashed: objective and intersubjective faults

Slashing works automatically only when code can prove the fault. Eigen Labs' 2024 EIGEN token whitepaper sorts faults into four kinds:

  • Objective — provable by math and cryptography alone, such as double-signing or an invalid rollup state transition. Code can slash these.
  • — faults all reasonable, active observers agree happened, but on-chain code cannot see. The example is data withholding: watchers know the data was never published, yet the chain cannot prove a negative.
  • Non-attributable — visible only to the victim, such as a committee secretly leaking data it should keep private.
  • Subjective — matters of judgment where honest observers may disagree.

For intersubjective faults, Eigen Labs proposes slashing by forking: if a majority of EIGEN stakers misbehave, anyone can fork the EIGEN token so the offenders' stake is removed, and the community chooses which version is real. The post said this was only partly in place at launch.

Here Buterin drew a line in his 2023 essay Don't overload Ethereum's consensus. Reusing validators' stake for other services is, in his view, “fundamentally fine.” What is dangerous is a service that assumes Ethereum's community will fork or bail it out if it fails — turning social consensus into insurance for every application and making the base layer more fragile. The EigenLayer whitepaper agrees: even a provable attack on a restaked service should not be expected to make Ethereum hard-fork.

Shared security designs

Polkadot: one validator set for many chains

On Polkadot, the relay chain's validators secure every parachain (now also called rollups). Small groups of validators check and back each parachain block; randomly chosen extra validators re-check it, and any disagreement escalates to the whole set, settled by a two-thirds supermajority. Backing an invalid block costs a validator and its nominators 100% of their stake. Equivocation penalties are correlated, min((3x/n)², 1) for x offenders among n validators: one offender in 100 loses 0.09%, twenty lose 36%. Slashes wait 27 days so governance can reverse a mistaken one — a deliberate human check.

Cosmos: Interchain Security

Interchain Security let consumer chains borrow the Cosmos Hub's validators and staked ATOM — at first every Hub validator (replicated security), later only the top ones or volunteers (partial set security). Downtime on a consumer chain only gets a validator jailed; double-signing evidence, submitted by relayers or others, gets it slashed, jailed and permanently removed on the Hub. Slash throttling limits how much of the validator set can be jailed at once. In 2025 Hub governance approved Neutron's move off Interchain Security to its own validator set, and Gaia v28.0.0, the Hub software released in August 2026, removes the Interchain Security provider module.

Ethereum restaking: EigenLayer

EigenLayer lets ETH stakers, and the operators they delegate to, opt in to extra slashing conditions set by Actively Validated Services () — data-availability layers, oracles, bridges and similar. Its current design rests on two ideas from the ELIP-002 upgrade:

  • Operator sets. Each AVS groups its operators; operators choose which sets to join.
  • Unique stake. An operator splits its delegated stake between those sets, and each unit of stake can be slashed by only one set at a time — so a service knows exactly how much stake only it can slash.

ELIP-002 deliberately keeps the protocol out of judging faults: an AVS may slash operators in its sets “for any reason,” there are no protocol-level vetoes, and slashed funds were originally burned. (The original whitepaper had proposed a veto committee for slashing as “training wheels”; the design that shipped left any such check to each AVS.)

Slashing went live on Ethereum mainnet on 17 April 2025. It was opt-in, and a new 14-day withdrawal delay stops stake leaving before a pending fault can be punished. A July 2025 upgrade let AVSs redistribute slashed funds — to reimburse users, for example — instead of burning them; Eigen Labs warned that a compromised AVS could use this to take stakers' funds.

Others: Symbiotic and Babylon

Symbiotic generalizes the model: vaults hold collateral, which need not be ETH, and networks set their own slashing rules. A network can name resolvers that may veto a slashing request during a waiting period — a built-in slot for a human check on faults that are not purely objective.

Babylon brings bonded work to Bitcoin. Stakers lock BTC in a time-locked script they control; one spending path sends a set fraction to a burn address, and needs signatures from the staker, the finality provider they delegate to, and a covenant committee. Finality providers sign with extractable one-time signatures, so signing two conflicting blocks exposes their private key and supplies the missing signature. The covenant committee is a trusted part of the design.

A worked example: one stake, five services

Suppose a group of operators has $10 million of restaked collateral and serves five services. Each service holds $3 million that a majority of these operators could steal by signing false messages.

One service alone looks fine: stealing $3 million needs a majority, so it costs over $5 million in slashed stake.

All five together do not. The same majority controls every service, so one coordinated attack nets $15 million for the same $5-million-plus of stake — stake can only be burned once. The EigenLayer whitepaper gives a near-identical example: $8 million of stake looks safe guarding one $2 million service, but not when the same stakers back ten more like it.

Now add an honest failure: a bug in shared signing software, or a stolen key at a large operator, triggers a fault in all five.

  • Without unique stake, each service can slash the full $10 million. Five 50% slashes in a row take nearly everything, and the first one already shrinks the collateral behind the other four, lowering their CoC and inviting attacks — a cascade.
  • With unique stake, the operators might allocate $2 million to each service. A fault in all five can still cost $10 million, but no service can take more than its $2 million. The honest accounting also reveals what the pool hid: a service holding $3 million is protected by only $2 million.

The lesson: shared security is only as strong as the least well-covered combination of services that the same operators control.

The risks of correlation

Correlated slashing. Operators in many services often run the same software and key setup, so one bug can trigger slashing everywhere at once — and Ethereum's correlation penalty punishes mass slashing hardest. A rule meant to deter coordinated attacks also amplifies coordinated accidents.

Leverage and rehypothecation. Restaking reuses one pool of ETH as collateral several times over; each layer adds risk without adding capital, and the value protected can quietly outgrow the stake behind it.

Operator concentration. If a handful of operators are “entrenched across many other AVSs,” in the whitepaper's words, they can attack several services together, and one compromise at a big operator reaches all of them.

Overloading social consensus. The more value restaked ETH secures, the stronger the pressure on Ethereum to “do something” after a big failure — the slippery slope Buterin warned against.

Liquid restaking token depegs. wrap a restaked position in a tradable token that is then used as collateral elsewhere. On 24 April 2024 Renzo's ezETH briefly fell to about $750 on Uniswap with ETH near $3,200, as holders rushed for the exit through thin liquidity; leveraged positions on Gearbox and Morpho were liquidated before the price recovered within hours. Nothing was slashed — the losses came from the liquidity and leverage layered on top. The products themselves belong to the separate restaking and liquid staking topic.

“Secured by $X” is not a single number

When a service claims billions of dollars of restaked security, ask three questions. How much of that stake can this service actually slash? What could an attacker gain across every service the same operators run? And what happens to the remaining stake if a shared bug hits all of them at once?

Key takeaways

  • Bonded work enforces honesty economically: collateral is destroyed for provable misbehavior. Security is robust when the cost of corruption is well above the profit from corruption.
  • Proof of work's security is a sunk cost; proof of stake's slashable bond can be destroyed, which makes attacks costlier to repeat and lets security be shared.
  • Only objective faults can be slashed automatically. Intersubjective faults, such as data withholding, need social consensus, a committee or a token fork — and Buterin warns against leaning on Ethereum's own consensus for them.
  • Polkadot, Cosmos, EigenLayer, Symbiotic and Babylon share stake in different ways. EigenLayer's AVS slashing went live on 17 April 2025, with unique stake so each unit is slashable by only one service.
  • The core risk is correlation: the same stake, operators and software back many services, so attacks pay across all of them and accidents hit all of them. Leverage, operator concentration and liquid-token depegs add more.
Educational only, not financial or legal advice.