Cover photo

Liquid Staking Is Easy to Enter. The rsETH Hack Reminded Me to Study the Exit.

A stETH exit, the rsETH exploit, and what Meta Pool reveals about validator distribution.

In April, the Lazarus group, a cybersecurity organization sponsored by the North Korean government, exploited KelpDAO for about $292 million. The hacked used forged cross-chain messages to mint 116,500 unbacked rsETH and then use that asset inside DeFi lending markets.

Note: rsETH, issued by Kelp DAO, is a liquid restaking token (LRT), that allows users to deposit their Ethereum staking assets (like stETH or ETHx) into EigenLayer and earn compounded yields.

The exploit destabilized the DeFi industry, specifically impacting users of borrowing and lending protocols Aave and Compound, and Layer 2 chains such as Arbitrum, Base, Mantle, and Linea, where the rsETH was used.

Personally, it changed how I looked at my stETH position (for readers who may not know, stETH is a liquid staking token on the Lido protocols that represents your staked ETH plus accumulated rewards) by making something obvious that is easy to ignore when markets are calm: liquid staking and restaking tokens are not isolated yield products. They are wrappers around validator systems, protocol contracts, governance decisions, liquidity venues, bridges, collateral markets, and exit paths.

The system underneath the token is what matters when something breaks.

Liquid staking makes staking feel simpler than it is

Before this, I mostly thought of stETH in the obvious way: ETH, but staked. ETH, but earning yield. ETH, but liquid enough to use elsewhere.

That framing is incomplete.

A liquid staking token makes staking easier to enter, hold, transfer, and use across DeFi. That is the whole point. But it can also make the underlying structure less visible. You are not only holding “ETH plus yield.” You are holding exposure to a staking architecture, a validator/operator set, a governance process, and a liquidity environment.

The rsETH incident did not make me think liquid staking is broken. It made me think liquid staking requires better diligence.

The exit path is where the abstraction breaks

The lesson became clearer when I exited my stETH position.

There are two broad ways out of stETH. You can sell it in the market, or you can redeem it through Lido’s withdrawal process. Those are not the same thing.

Selling is a market exit. It depends on liquidity, pricing, slippage, and whether someone else is willing to take the other side.

Redeeming is a protocol exit. It pushes you closer to the underlying staking mechanics: Ethereum validators, queues, timing, and settlement constraints.

You learn what the token really abstracts when you try to leave.

The validator layer is not just plumbing

A liquid staking token is easy to think of as a receipt for yield: deposit the asset, get the token, earn the return. But that framing skips the part that actually secures the network.

Underneath the token, someone is deciding where the stake goes.

That raises a different set of questions:

• Which validators receive the stake?
• Who decides that allocation?
• Is stake being spread across the network, or routed through a dominant protocol?
• What happens when the token becomes widely used as collateral?
• Does the system still work cleanly when markets are stressed?

These questions make Meta Pool became a useful comparison point for me.

Meta Pool has a liquid staking protocol, stNEAR, for networks like NEAR. On NEAR, users can stake directly with validator pools, but Meta Pool adds a liquid staking layer on top: users deposit NEAR, receive stNEAR, and continue holding a liquid token while the underlying NEAR is delegated across validators.

That makes it useful for this discussion because Meta Pool is not just creating a yield-bearing token. It is also making allocation decisions inside NEAR’s validator set.

The relevant question becomes:

If liquid staking abstracts the validator layer from the user, can it still help distribute stake across the network?

That question is especially important because Meta Pool distributes NEAR deposits across 80+ validator nodes and automatically rebalances based on validator concentration and performance. In other words, stNEAR is not only a convenience wrapper. It is also a window into how liquid staking can be designed as a stake-distribution mechanism.

Protocol Concentration

Lido, like Metapool, routes stake across many node operators, and it has been actively working to broaden participation. Its Community Staking Module, for example, helped increase the number of node operators to 566 and active validators to 21,377, at the time of writing.

So the concern is not validator concentration but rather protocol concentration risk.

A large share of Ethereum staking demand flows through one dominant liquid staking protocol, one governance layer, one staking architecture, and one very important token wrapper: stETH. Even if the underlying operators are distributed, the coordination layer itself can become systemically important.

The real lesson is to look past the wrapper

The deeper lesson from rsETH is that staking wrappers can carry risks beyond the base asset. Smart contract risk, bridge risk, oracle risk, collateral market risk, governance risk, liquidity risk, and validator allocation risk can all become part of the user’s actual exposure.

Most of that is invisible on the way in.

It becomes visible on the way out, or when something nearby breaks.

So the next time when evaluating a liquid staking token ask yourself:

  • Where does the stake go?

  • Who controls allocation?

  • How concentrated is the protocol layer?

  • How distributed is the validator set?

  • Where does liquidity actually come from?

  • Can I exit through the market, the protocol, or both?

The rsETH hack is a good lesson in looking past the wrapper and asking deeper questions. Because staking products are easiest to understand when you enter them.. You find out what they really are when you try to leave.