TL;DR
Mellow is modular restaking infrastructure, not a single product. Anyone can spin up an LRT or vault; a "curator" (a risk manager like MEV Capital, Re7, Veda, Steakhouse) decides what collateral goes where, which Symbiotic networks to restake into, and how much leverage to run. Your risk is not "Mellow" as a monolith. It is the specific vault and the specific curator you deposit with, plus whatever slashing conditions that vault opted into. The core contracts are audited by six firms and have never been exploited. But in April 2026 a Mellow-co-curated MetaVault (Lido EarnETH) froze deposits and withdrawals for about four weeks and needed external relief to make depositors whole, after the KelpDAO rsETH bridge hack hit its leveraged position. That is the shape of the real risk here: not Mellow's own code, but curator leverage and the collateral a vault chose to hold.
Checklist
Audits & contracts. Audited by StateMind, ChainSecurity, Sherlock (contest), MixBytes, Nethermind, and Decurity across Core Vaults, MultiVault, DVV, and the Interoperable Vault. No exploit of Mellow's own contracts to date.
Admin control. Per-vault role model: 60+ scoped permissions, per-vault multisig, timelocked parameter changes (about 1 day), emergency pause. Subvaults are upgradeable. Exact multisig signer sets and timelock lengths vary by vault and are not confirmed on-chain this run. refresh
Oracle. Per-vault; oracle contracts were in scope for the StateMind audit. Specific price feeds depend on the vault's collateral. refresh
Liquidity & exit. Withdrawals are curator-batched (typically 1 to 4 days); users can force-withdraw after 90 days. In April 2026 one Mellow-curated vault paused exits for 27 days (about four weeks) under stress.
Yield: real vs emission. Real: staking plus restaking rewards, not token inflation. Extra yield comes from curator leverage and points (Mellow and Symbiotic), and there is no live governance token yet.
Holder concentration. No tradeable token; risk is depositor and curator concentration per vault, plus curator control over allocation. Not measured this run. refresh
Track record. No hack of Mellow contracts. But a co-curated MetaVault took ~$21.6M rsETH exposure (~9% of the vault) and a 27-day freeze in the April 2026 KelpDAO fallout; depositors were ultimately made whole.
Worst case
You deposit into a specific curated vault. The curator has run leverage (borrow ETH against a restaked LST, loop it) and holds a collateral asset that then depegs or gets exploited upstream, exactly what happened to the EarnETH strategy when rsETH lost its backing. Exits freeze because there is no liquidity to unwind at a fair price. You wait weeks. Whether you are made whole depends on a first-loss backstop and ad-hoc ecosystem relief, not a contractual guarantee. Separately, a Symbiotic network your vault restaked into could slash, a loss that is network-defined and permanent. The mitigation is entirely in your vault selection: prefer conservative, unlevered curators and vaults with collateral you understand, and size accordingly.
Bottom line
Caution. The base infrastructure is well-audited and unexploited, and the yield is real. What forces caution is that depositor risk is delegated to a curator you must trust, the newer flexible-vault stack is young, and a Mellow-curated vault already demonstrated in April 2026 that curator leverage plus impaired collateral can freeze exits for weeks. No Mellow-contract fund-loss deal-breaker, and reimbursement did happen, so this is not an avoid. But "which vault, which curator, how much leverage" is a live question you have to answer before depositing, not a detail.
Data appendix
- TVL:
$207.7M aggregate. DeFiLlama now splits the protocol into "Mellow Core" ($188.6M) and "Mellow Restaking" (~$19.2M); combined ~$207.7M, of which$206.8M is on Ethereum, plus small Rootstock ($0.85M), Mezo, and Monad. Note: marketing sources cite "$600M+", which does not reconcile with DeFiLlama and may be peak or restaked-collateral double-counting. 90d / ATH: refresh. - Audits: StateMind, ChainSecurity, Sherlock (contest), MixBytes, Nethermind, Decurity (official security page, docs.mellow.finance/security).
- Admin/governance: Per-vault roles, 60+ scoped permissions, per-vault multisig, ~1-day timelock on parameter changes, emergency pause, upgradeable subvaults, 90-day user force-withdraw. Exact signer sets / timelock durations: refresh.
- Oracle: Per-vault, in StateMind audit scope; specific feeds refresh.
- Holder concentration: No live token; per-vault depositor/curator concentration refresh.
- Incident record: No exploit of Mellow contracts. April 2026 KelpDAO/rsETH LayerZero bridge hack (116,500 rsETH,
$292M) impaired a leveraged rsETH/ETH strategy (on Aave) in the Mellow/Veda co-curated Lido EarnETH MetaVault ($21.6M exposure, ~9% of vault); deposits/withdrawals paused 27 days (resumed 2026-05-15), users made whole via 143.98 ETH first-loss coverage plus the coordinated ecosystem relief effort (DeFi United). Source: Lido governance Kelp incident review.
Maintained monthly. Methodology: DeFi Research Instruction v2.