TL;DR
The DeFiLlama slug this report tracks, mellow-lrt, resolves to Mellow Restaking, and that leg holds $20.81M. It peaked at $916.07M on 2024-12-07, so it is down 97.7% over roughly twenty months, down 95.8% over one year and down 47.5% over 90 days. That is not decay at the edges, it is the old liquid-restaking business winding down: the legacy multi-vault LRTs pay 2.183% and make you wait 14 days to leave. The money went to a second DeFiLlama entry, Mellow Core, at $214.56M. All three legs together are about $235.7M, itself down 74.3% from a combined peak of $916.2M and down 49.5% in 90 days, though up 17.5% since this report's last edition on 2026-07-01.
Inside that $235.7M, one vault is the protocol. earnETH holds $168.3M, 71.4% of everything. It is the Lido Earn MetaVault co-curated by Mellow and Veda, the same vault that froze deposits and withdrawals for about four weeks in April 2026 after the KelpDAO bridge hack impaired its rsETH position. Read on-chain today, earnETH deploys 90.6% of its 87,013 ETH into a single other Mellow vault, strETH, the Lido stRATEGY vault, and owns 97.04% of it. So the top two lines of the vault table are not two positions, they are one position counted twice.
The code record is genuinely clean. Six audit firms, no exploit of Mellow contracts in over two years, and no Mellow entry anywhere in DeFiLlama's 621-item hacks list. The problems are all in the control surface, and every one of them was verifiable on Ethereum mainnet this morning.
Checklist
Audits & contracts. Verified firm by firm against Mellow's own security page: StateMind (Mellow LRT with deployment, MultiVault), ChainSecurity (Mellow LRT, MultiVault), Sherlock (Modular LRTs, Core Vault contest), MixBytes (Simple-LRT and DVV Vault, SyncRedeemQueue dated 202607), Nethermind (Interop, plus Core Vault audits dated 202508 through 202606) and Decurity (Interop). Six real firms, no invented names, and coverage that runs to within two months of today. No exploit of Mellow's own contracts. The only adjacent hack in DeFiLlama's list is Kelp on 2026-04-18, $293M through a LayerZero OFT bridge, which was upstream of Mellow rather than in it. No bug bounty program is listed on the security page.
Admin control. Every Core Vault checked is an OpenZeppelin TransparentUpgradeableProxy pointing at implementation 0x0000000615B2771511dAa693aC07BE5622869E01. Upgrade authority runs through a per-vault ProxyAdmin, and one Safe, 0x81698f87c6482bf1ce9bfcfc0f103c4a0adf0af0, threshold 5 of 8, owns the ProxyAdmin of six of them: earnETH, earnUSD, earnUSDc, strETH, DVstETH and rstETH, about $201M of depositor money once earnETH's overlap with strETH is netted out. getMinDelay() reverts on that Safe and on the other three upgrade owners, so there is no timelock anywhere on the upgrade path. Five signatures replace the code behind the whole Ethereum book in one transaction, with no waiting period and no window to leave first.
Operationally each vault also has its own role set, and the thresholds differ a lot. earnETH and earnUSD share a 5-of-8 admin Safe and a 3-of-5 curator; strETH has a 5-of-8 admin and a 3-of-8 curator; mbhBTC has a 3-of-5 admin and, alongside it, a 1-of-2 Safe holding both PULL_LIQUIDITY_ROLE and PUSH_LIQUIDITY_ROLE, meaning one signature moves the assets of a live $6.5M mainnet vault. Curator calls are constrained by a per-subvault Verifier, but createSubvault(version, owner, verifier) is an admin call, so the constraint is only as tight as the verifier the admin chose.
Oracle. Core Vaults price assets through handleReport(asset, priceD18, depositTimestamp, redeemTimestamp), and that price is what deposits mint at and redemptions burn at. Mellow's docs are explicit that no external feed is trusted and validation is local. The caps are real and I read them: on all four vaults checked, maxRelativeDeviationD18 is 5e15, a 0.5% move per report, and suspiciousRelativeDeviationD18 is 1e15, 0.1%. A report past 0.5% simply does not land. A report between 0.1% and 0.5% lands flagged isSuspicious, and acceptReport can clear that flag. maxAbsoluteDeviation is 5e15 on earnETH and strETH but 5e27 on earnUSD and 5e25 on mbhBTC, values so large the absolute check is effectively switched off there, leaving only the relative one.
The separation of duties is where it breaks. On earnETH and earnUSD it holds: submissions come from a 3-of-8 Safe through an OracleSubmitter, and acceptance sits with the 5-of-8 admin Safe. On strETH the 5-of-8 admin Safe holds SUBMIT_REPORTS_ROLE and ACCEPT_REPORT_ROLE directly on the vault, so the same five keys can submit a suspicious price and accept it. Same pattern on mbhBTC, whose 3-of-5 admin holds both, and whose separate submitter Safe is 1-of-1, a single key. And because earnETH prices its strETH position at exactly strETH's self-reported NAV (1.0297 shares per strETH against strETH's own 1.044362 ETH per share, the same number to five figures), 90.6% of earnETH's book is marked at a price the strETH Safe sets for itself.
Liquidity & exit. Withdrawals are request-then-batch. A request becomes eligible only once an oracle report arrives with timestamp <= reportTimestamp - redeemInterval, after which the curator has to pull liquidity back from subvaults before handleBatches settles it. Requests cannot be cancelled, an explicit anti-griefing choice that also means once you queue you are committed to whatever price clears. setQueueStatus(queue, isPaused) lets the role holder pause any deposit or redeem queue, and every controller holding that role on earnETH, earnUSD, strETH and mbhBTC answers getMinDelay() with 0, so a pause lands immediately. Core Vault docs describe no force-withdraw; the 90-day escape hatch in the older MultiVault stack does not carry over.
The on-chain redeemInterval settles the question the last edition left open. earnETH and strETH are 86,400 seconds (24 hours), earnUSD 172,800 (48 hours), and mbhBTC 31,536,000 seconds, a configured 365-day lock, not an observed average. Mellow's published average exit times line up: earnETH and strETH 1.5 days, earnUSD 2.5 days, tqETH 3.5 days, DVstETH 4 days, the legacy multi-vault LRTs 14 days, stBARD 21 days, rsENA 28 days, and mbhBTC plus mbhcbBTC at 365.5 days on $9.6M between them.
Yield: real vs emission. Real. Staking, restaking and strategy income, no protocol token inflation, and still no live governance token. The legacy LRT vaults report 2.183%, roughly the stETH base rate, so the restaking leg is not paying for its 14-day lockup. Core Vault APRs come back null from Mellow's API and were not verified here. strETH carries a 1% annual platform fee per Lido's own announcement. Points programs still run alongside.
Holder concentration. There is no tradeable governance token, so the concentration that matters is in the deposits, and it is worse than it looks. earnETH is $168.3M of $235.7M, 71.4%, and the second line, strETH at about $155.0M on-chain, is 97.04% earnETH's own money. Net of that overlap the ranking is earnETH $168.3M, earnUSD $26.9M, rsuniBTC $7.1M, mbhBTC $6.5M, DVstETH $4.5M, rstETH $3.8M. If earnETH's depositors leave, Mellow is a $67M protocol. Who those depositors are inside earnETH is the one question I could not answer: Etherscan's top-holders endpoint and Nansen's both returned Pro-subscription errors this run.
Track record. No hack of Mellow's own code across two years and multiple audit rounds, which is a real result for a protocol this size. The counterweight is April 2026. The KelpDAO bridge exploit, 116,500 rsETH worth about $292M, impaired a leveraged rsETH position inside earnETH, roughly $21.6M or about 9% of the vault. Deposits and withdrawals were suspended for about four weeks and depositors were made whole through first-loss coverage plus coordinated ecosystem relief; contemporaneous coverage describes a $3M Lido DAO treasury backstop and about $70M of ETH recovered. That was a curator-and-collateral failure, not a contract failure, and it landed on the vault that today holds 71% of everything Mellow custodies. I searched for anything new between 2026-07-01 and 2026-08-12 and found none, in the hacks data or the news. Separately, on 2026-07-22 SEC Commissioner Hester Peirce published a statement titled "Headstands and Summervaults" arguing that curator-managed vaults may implicate securities law, with discretionary control as the trigger. That is commentary, not a rule or an enforcement action, and I read only secondary coverage of it.
Worst case
Two shapes, and they are different.
The slow one is the April 2026 replay, now with a longer chain. A curator holds impaired or illiquid collateral, cannot pull enough liquidity back from subvaults to settle the queue, and pauses redemptions. You cannot cancel your request, you cannot force a withdrawal, and you wait. Last time it was about four weeks and it ended well because Lido and the surrounding ecosystem chose to cover it. That was a decision, not a contractual guarantee, and it was made when the exposure was 9% of one vault. Today the structure is more fragile in one specific way: if you deposit into earnETH, 90.6% of your money is really in strETH, so you are exposed to strETH's 3-of-8 curator and strETH's subvaults through a vault you never chose, and the price you eventually redeem at is strETH's self-reported NAV.
The fast one is the control surface. Five of eight signers on one Safe can replace the implementation behind earnETH, earnUSD, earnUSDc, strETH, DVstETH and rstETH in a single transaction, no delay, no warning, against about $201M. On strETH the same five can submit a price and accept it when the contract flags it as suspicious. On mbhBTC a single key can submit prices to a vault whose depositors are locked in for a configured 365 days. None of that requires a bug. It requires a compromised or captured key set, which is the failure mode that has actually been draining DeFi this year. The 0.5% per-report cap does bound how fast a bad price can move, which is worth something, but it is a speed limit, not a stop.
Position sizing is the only mitigation available to a depositor, because there is no insurance fund and no exit window ahead of an upgrade.
Bottom line
Caution, and closer to the avoid line than it was in July. Nothing has gone wrong with Mellow's code, the audits are real and current to within two months, the yield is real, and the July 1 to August 12 window was quiet. But three of the four things that can lose your money without a bug are wide open: an upgradeable vault with no timelock over essentially the whole Ethereum book, a self-attested price that on two vaults is submitted and accepted by the same Safe, and an exit that a role holder stops instantly with no force-withdraw behind it. Any one of those would keep this out of a conservative book on its own.
What holds it at caution rather than avoid is the clean contract record, the fact that the one realized stress event ended with depositors whole, and that all of this is disclosed and inspectable rather than hidden. What would push it to avoid: a timelock-free upgrade actually being exercised on a live vault, a second exit freeze, or earnETH's concentration going up rather than down.
If you deposit, the vault and the curator are the decision, not "Mellow", and the thresholds are not interchangeable. earnETH has the strongest controls of the set and still routes 90.6% of your money somewhere else. mbhBTC has a 1-of-1 price submitter, a 1-of-2 curator and a 365-day lock. Read the specific Safe for the vault you pick rather than assume it matches the one above. And note that the leg this report is filed under, Mellow Restaking at $20.81M, is now 8.8% of the protocol and paying 2.183% for a 14-day exit; there is very little reason to be in it.
Data appendix
- TVL (tracked slug): $20.81M, DeFiLlama
mellow-lrt, which resolves to protocol id 4756, Mellow Restaking. The series reads $20.79M at the 2026-08-11 close and $21.02M at the latest 2026-08-12 point. Peak $916.07M on 2024-12-07, down 97.7% over about twenty months. 90d: $40.05M on 2026-05-14, down 47.5%. 1y: $504.22M on 2025-08-12, down 95.8%. Against the prior report date of 2026-07-01 ($18.58M) it is up 13.1%. - TVL (whole protocol): DeFiLlama parent
mellow-protocol= Mellow Core $214.56M + Mellow Restaking $21.02M + Mellow Yield $0.09M = $235.66M at the latest 2026-08-12 point ($215.81M at the 2026-08-11 close). Combined peak $916.17M on 2024-12-07, down 74.3%. 90d: $466.45M, down 49.5%. 1y: $504.40M, down 53.3%. Versus 2026-07-01 ($200.52M), up 17.5%. Mellow Core alone peaked at $496.84M on 2026-04-06 and is down 56.8%. Market context: total DeFi TVL fell from roughly $115B in January 2026 to about $70B, so a 90-day halving is worse than the market but not detached from it. - Vault concentration (Mellow API
api.mellow.finance/v1/vaults, 86 vaults, pulled twice identically): earnETH $168.30M, earnUSD $26.92M, strETH $21.74M direct / $172.30M aggregate, rsuniBTC $7.14M, mbhBTC $6.51M, DVstETH $4.45M, rstETH $3.78M, mbhcbBTC $3.08M, pzETH $2.83M. earnETH is 71.4% of DeFiLlama's $235.66M. The API's owntvl_usdcolumn sums to $255.22M, which double counts: verified on-chain, earnETH's subvault0xc5901c2481ca9c26398a9da258b13717894bfebfholds 75,494.43 of strETH's 77,799.47 shares (97.04%). The API's two strETH figures ($21.74M and $172.30M) do not reconcile with each other or with the on-chain value; on-chain, strETH is 77,799.47 shares at 1.044362 ETH per share = 81,251 ETH, about $155.0M at ETH $1,908.12. earnETH is 85,794.91 shares at 1.0142 ETH per share = 87,013 ETH, about $166.0M, of which the strETH position is 78,844 ETH, 90.6%. - Audits: StateMind (Mellow LRT with deployment, MultiVault), ChainSecurity (Mellow LRT, MultiVault), Sherlock (Modular LRTs, Core Vault contest), MixBytes (Simple-LRT and DVV Vault, SyncRedeemQueue 202607), Nethermind (Interop, plus Core Vault audits dated 202508, 202509, 202511, 202512, 202601, 202604, 202605, 202606), Decurity (Interop). Source: docs.mellow.finance/security. No bug bounty program is listed.
- Upgrade authority (on-chain, 2026-08-12): all Core Vault proxies checked are
TransparentUpgradeableProxyon implementation0x0000000615B2771511dAa693aC07BE5622869E01. ProxyAdmin owners:0x81698f87c6482bf1ce9bfcfc0f103c4a0adf0af0(Safe v1.3.0, 5-of-8) for earnETH, earnUSD, earnUSDc, strETH, DVstETH and rstETH;0x55d9eceb5733f72a48c544e20d49859ec92fba5f(Safe 1.4.1, 4-of-7) for tqETH;0xb7b2ee53731fc80080ed2906431e08452bc58786(5-of-8) for mbhBTC and mbhcbBTC;0x54977739cf18b316f47b1e10e3068bb3f04e08b6(3-of-4) for the msvUSD-family vault0x7207595E4c18a9A829B9dc868F11F3ADd8FCF626.getMinDelay()reverts on all four, so no timelock. Signer0x8888843c607f4bbd6ad72128f478085256bdd15dsits on all four, though never enough alone to reach a threshold. - Vault roles (on-chain):
DEFAULT_ADMIN_ROLEis0x0dd73341d6158a72b4d224541f1094188f57076e(5-of-8) for earnETH and earnUSD,0xabe20d266ae54b9ae30492dea6b6407bf18feeb5(5-of-8) for strETH,0xd5aa2d083642e8dec06a5e930144d0af5a97496d(3-of-5) for mbhBTC. Curators (PULL_LIQUIDITY_ROLEandPUSH_LIQUIDITY_ROLE): earnETH and earnUSD0xe5abcc40196174ae0d12153de286f0d8e401769d(3-of-5); strETH0x5Dbf9287787A5825beCb0321A276C9c92d570a75(3-of-8); mbhBTC0x7df72e9bbd03d8c6faf41c0dd8ce46be2878c6fa(1-of-2, owners0xd19b598712413e69b48f70c5ea16286cf8dfd632and0x56105c17bef06455e1066f7c455ff28f15c7283e) alongside its admin Safe. - Queue pause:
SET_QUEUE_STATUS_ROLEholders are0x363ba8843d06ba5968f55c26ab055162edd62189plus the 5-of-8 admin Safe on earnETH,0x8d8b65727729fb484cb6dc1452d61608a5758596on strETH,0xda6da82dff8cd29d828e4775cc003f504a968845on earnUSD,0x972ae54bf6950fde7539a803cc5cd71b0f2f0cb2on mbhBTC. Each controller answersgetMinDelay()with 0 (it responds rather than reverting, so the read is genuine), i.e. a pause takes effect immediately. - Oracle (on-chain
securityParams()): all four vaults sharemaxRelativeDeviationD185e15 (0.5% per report),suspiciousRelativeDeviationD181e15 (0.1%),timeout72,000s (20h) anddepositInterval3,600s (1h).maxAbsoluteDeviationis 5e15 on earnETH and strETH but 5e27 on earnUSD and 5e25 on mbhBTC, effectively disabling the absolute check there.redeemInterval: earnETH 86,400s, strETH 86,400s, earnUSD 172,800s, mbhBTC 31,536,000s (365 days). Role holders: earnETH and earnUSD submit viaOracleSubmitterwith a 3-of-8 submitter Safe0x93a797643d74fc81e7a51f3f84a9d78f930435d1and accept via the 5-of-8 admin Safe; strETH's 5-of-8 admin Safe holds bothSUBMIT_REPORTS_ROLEandACCEPT_REPORT_ROLEdirectly; mbhBTC's 3-of-5 admin holds both directly, and itsOracleSubmittersubmitter Safe0xa68b023d9ed2430e3c8cbbde4c37b02467734c33is 1-of-1 (sole owner0xf6edb1385ec1a61c33b9e8dcc348497dcceabe8d). PerOracle._validatePrice, deviation is measured against the previous report, so the cap is per report, not cumulative. - Exit times (Mellow API
withdraw_avg_time_seconds): earnETH 1.5d, strETH 1.5d, earnUSD 2.5d, tqETH 3.5d, DVstETH 4d, legacy multi-vault LRTs (rstETH, pzETH, steakLRT, amphrETH, Re7LRT, cp0xLRT, flowETH) 14d, stBARD 21d, rsENA 28d, mbhBTC and mbhcbBTC 365.5d ($9.6M combined), which the on-chainredeemIntervalconfirms is a configured lock. - Holder concentration: no tradeable token. Vault-level concentration measured above. Per-vault depositor splits: Etherscan
tokenTopHoldersand Nansentoken_current_top_holdersboth returned Pro-subscription errors. refresh - Incident record: no Mellow entry in DeFiLlama's hacks list (621 entries checked 2026-08-12). April 2026: KelpDAO LayerZero OFT bridge exploit (116,500 rsETH, about $292M, 2026-04-18) impaired a leveraged rsETH position inside the Mellow and Veda co-curated Lido earnETH MetaVault, roughly $21.6M or about 9% of the vault; deposits and withdrawals were suspended for about four weeks and depositors were made whole. Contemporaneous coverage cites a $3M Lido DAO treasury first-loss backstop and about $70M of ETH recovered; the 143.98 ETH figure and the 2026-05-15 resumption date carry over from the 2026-07-01 report and were not re-verified: refresh. Nothing new found between 2026-07-01 and 2026-08-12.
- Regulatory: SEC Commissioner Hester Peirce, statement "Headstands and Summervaults", 2026-07-22, applying the Howey test to curator-managed vaults and on-chain lending; secondary coverage only, primary text not read.
Maintained monthly. Methodology: DeFi Research Instruction v2.