Skip to content
PROTOCOL RESEARCH

Mellow risk

Well-audited, unexploited modular restaking infrastructure where your real risk is the specific curator and vault you pick: one Mellow-co-curated MetaVault (Lido EarnETH) froze exits 27 days in the April 2026 KelpDAO fallout before depositors were made whole.
CautionResearched Jul 1, 2026
strong: Audits & contractsSix firms (StateMind, ChainSecurity, Sherlock contest, MixBytes, Nethermind, Decurity) confirmed on the security page; no exploit of Mellow's own contracts.
watch: Admin controlPer-vault multisig + ~1-day timelock + emergency pause + upgradeable subvaults; exact signer sets and timelock lengths not confirmed on-chain (refresh).
watch: OraclePer-vault, in StateMind audit scope; specific price feeds vary by collateral and were not verified this run (refresh).
watch: Liquidity & exitCurator-batched withdrawals (1-4 days), 90-day force-withdraw; a Mellow-curated vault froze exits 27 days under stress in April 2026.
strong: Yield (real vs emission)Real staking + restaking rewards plus points; no token inflation and no live governance token yet. Extra yield rides curator leverage.
watch: Holder concentrationNo tradeable token; risk is per-vault depositor/curator concentration and curator allocation control. Not measured (refresh).
watch: Track recordNo hack of Mellow code, but the Mellow/Veda co-curated EarnETH MetaVault took ~$21.6M rsETH exposure and a 27-day freeze in the April 2026 KelpDAO fallout; depositors made whole via 143.98 ETH first-loss coverage plus ecosystem relief.
🟢 strong🟡 watch / caveat🔴 weak / fund-loss risk
Verdict is a gate (worst flaw wins), not an average. Our read, not financial advice.
auto-sourced now
TVL$218.7M
30d↑4%
Audits1
Last hacknone

DeFiLlama + our exploits feed. Cross-check the dated report against today.

TL;DR

Mellow is modular restaking infrastructure, not a single product. Anyone can spin up an LRT or vault; a "curator" (a risk manager like MEV Capital, Re7, Veda, Steakhouse) decides what collateral goes where, which Symbiotic networks to restake into, and how much leverage to run. Your risk is not "Mellow" as a monolith. It is the specific vault and the specific curator you deposit with, plus whatever slashing conditions that vault opted into. The core contracts are audited by six firms and have never been exploited. But in April 2026 a Mellow-co-curated MetaVault (Lido EarnETH) froze deposits and withdrawals for about four weeks and needed external relief to make depositors whole, after the KelpDAO rsETH bridge hack hit its leveraged position. That is the shape of the real risk here: not Mellow's own code, but curator leverage and the collateral a vault chose to hold.

Checklist

Audits & contracts. Audited by StateMind, ChainSecurity, Sherlock (contest), MixBytes, Nethermind, and Decurity across Core Vaults, MultiVault, DVV, and the Interoperable Vault. No exploit of Mellow's own contracts to date.

Admin control. Per-vault role model: 60+ scoped permissions, per-vault multisig, timelocked parameter changes (about 1 day), emergency pause. Subvaults are upgradeable. Exact multisig signer sets and timelock lengths vary by vault and are not confirmed on-chain this run. refresh

Oracle. Per-vault; oracle contracts were in scope for the StateMind audit. Specific price feeds depend on the vault's collateral. refresh

Liquidity & exit. Withdrawals are curator-batched (typically 1 to 4 days); users can force-withdraw after 90 days. In April 2026 one Mellow-curated vault paused exits for 27 days (about four weeks) under stress.

Yield: real vs emission. Real: staking plus restaking rewards, not token inflation. Extra yield comes from curator leverage and points (Mellow and Symbiotic), and there is no live governance token yet.

Holder concentration. No tradeable token; risk is depositor and curator concentration per vault, plus curator control over allocation. Not measured this run. refresh

Track record. No hack of Mellow contracts. But a co-curated MetaVault took ~$21.6M rsETH exposure (~9% of the vault) and a 27-day freeze in the April 2026 KelpDAO fallout; depositors were ultimately made whole.

Worst case

You deposit into a specific curated vault. The curator has run leverage (borrow ETH against a restaked LST, loop it) and holds a collateral asset that then depegs or gets exploited upstream, exactly what happened to the EarnETH strategy when rsETH lost its backing. Exits freeze because there is no liquidity to unwind at a fair price. You wait weeks. Whether you are made whole depends on a first-loss backstop and ad-hoc ecosystem relief, not a contractual guarantee. Separately, a Symbiotic network your vault restaked into could slash, a loss that is network-defined and permanent. The mitigation is entirely in your vault selection: prefer conservative, unlevered curators and vaults with collateral you understand, and size accordingly.

Bottom line

Caution. The base infrastructure is well-audited and unexploited, and the yield is real. What forces caution is that depositor risk is delegated to a curator you must trust, the newer flexible-vault stack is young, and a Mellow-curated vault already demonstrated in April 2026 that curator leverage plus impaired collateral can freeze exits for weeks. No Mellow-contract fund-loss deal-breaker, and reimbursement did happen, so this is not an avoid. But "which vault, which curator, how much leverage" is a live question you have to answer before depositing, not a detail.

Data appendix

  • TVL: $207.7M aggregate. DeFiLlama now splits the protocol into "Mellow Core" ($188.6M) and "Mellow Restaking" (~$19.2M); combined ~$207.7M, of which $206.8M is on Ethereum, plus small Rootstock ($0.85M), Mezo, and Monad. Note: marketing sources cite "$600M+", which does not reconcile with DeFiLlama and may be peak or restaked-collateral double-counting. 90d / ATH: refresh.
  • Audits: StateMind, ChainSecurity, Sherlock (contest), MixBytes, Nethermind, Decurity (official security page, docs.mellow.finance/security).
  • Admin/governance: Per-vault roles, 60+ scoped permissions, per-vault multisig, ~1-day timelock on parameter changes, emergency pause, upgradeable subvaults, 90-day user force-withdraw. Exact signer sets / timelock durations: refresh.
  • Oracle: Per-vault, in StateMind audit scope; specific feeds refresh.
  • Holder concentration: No live token; per-vault depositor/curator concentration refresh.
  • Incident record: No exploit of Mellow contracts. April 2026 KelpDAO/rsETH LayerZero bridge hack (116,500 rsETH, $292M) impaired a leveraged rsETH/ETH strategy (on Aave) in the Mellow/Veda co-curated Lido EarnETH MetaVault ($21.6M exposure, ~9% of vault); deposits/withdrawals paused 27 days (resumed 2026-05-15), users made whole via 143.98 ETH first-loss coverage plus the coordinated ecosystem relief effort (DeFi United). Source: Lido governance Kelp incident review.

Maintained monthly. Methodology: DeFi Research Instruction v2.

← all protocols