Is Renzo Safe in 2026? A Security Analysis

TL;DR verdict

Renzo is conditionally safe. The protocol has been audited by Halborn and Sigma Prime, and its core contracts have not suffered a hack. However, on 2024-04-24 its ezETH token depegged ~79% in under an hour, triggering roughly $56M in cross-protocol liquidations for leveraged holders—an important reminder that liquid restaking tokens carry peg and liquidity risk distinct from contract exploits. Renzo launched in 2024, placing it in an early stage relative to older DeFi primitives, and holds roughly $97M in TVL as of mid-2026. The restaking layer adds further risk through EigenLayer dependencies, slashing conditions, and cross-chain bridges. Users should approach with caution, especially given the evolving regulatory landscape for liquid restaking tokens.

Audit history

Renzo has completed audits with Halborn and Sigma Prime, both tier-one security firms. Details of the engagement scope, date, and findings count are not fully public. Halborn and Sigma Prime audited the core restaking contracts, with a focus on asset custody, slashing logic, and AVS allocation mechanisms. As of our May 2026 review, no further third-party audits are listed in Renzo’s documentation. The community-led Renzo DAO may commission additional reviews as the protocol matures.

Incidents and exploits

Renzo's core smart contracts have not been hacked as of 2026-07-15. However, Renzo experienced a significant market incident on 2024-04-24: its ezETH liquid restaking token depegged by roughly 79% (trading as low as about $700 versus ETH) within an hour. The trigger was a combination of disappointment over the newly announced REZ governance-token allocation and the fact that the protocol did not permit native ezETH-to-ETH withdrawals, so the only exit was to sell ezETH into thin on-chain liquidity. Leveraged positions using ezETH as collateral were force-liquidated in a cascade totalling about $56M, including roughly $33M on Gearbox and $23M on Morpho. The peg recovered once withdrawals and market conditions normalized, and no user lost funds through a contract exploit—but the episode is a material demonstration of peg, liquidity, and withdrawal-design risk specific to LRTs. This is distinct from the separate April 2026 Kelp DAO exploit that affected other parts of the LRT ecosystem; Renzo's own contracts were not the source of that event.

Smart contract risks

Renzo’s smart contracts are young, having launched in 2024. The codebase governs the minting and burning of ezETH, operator delegation, and reward distribution. Upgradability is a key concern—if contracts use proxy patterns, the team or DAO can modify logic, which introduces trust assumptions. The protocol’s multi-chain presence on Ethereum, Arbitrum, Linea, BNB, Base, Mode, and Blast relies on messaging bridges (Connext, Hyperlane) that have their own security models. Oracle dependency is central to AVS slashing conditions and reward calculations, though specific oracle providers are not disclosed. Renzo's TVL of roughly $97M as of mid-2026 is well down from its 2024 peak, reflecting outflows after the ezETH depeg.

Operational and counterparty risks

Renzo depends on EigenLayer’s infrastructure and its AVS operators. Any slashing or smart contract failure in EigenLayer could directly impact ezETH’s value. Governance is managed by the Renzo DAO, with unclear team entities behind the initial development. Liquid restaking tokens face potential regulatory classification as securities or derivatives, which could affect protocol operations. Insurance coverage for users appears absent, leaving depositors unhedged against loss.

How to use it more safely

Verdict

Renzo earns a safety score of 6.0 out of 10. Two respected auditors and the absence of a core-contract hack are favorable, but the April 2024 ezETH depeg (~79% intraday, ~$56M in cascading liquidations) demonstrated real peg and withdrawal-design risk, and TVL has since fallen to roughly $97M. Combined with the protocol’s youth, reliance on EigenLayer, and multi-chain bridge complexity, the risk is non-trivial. Users comfortable with the restaking narrative may find Renzo a reasonable small allocation within a diversified portfolio, but caution is warranted. DeFi Intel publishes editorial research, not financial advice. Smart contract risk is never zero. Do your own research and consider position sizing accordingly.

Frequently asked questions

Has Renzo ever been hacked?

Renzo's core smart contracts have not been hacked. However, on 2024-04-24 its ezETH token depegged ~79% within an hour—driven by disappointment over REZ tokenomics and the lack of native withdrawals—triggering roughly $56M in cross-protocol liquidations (including ~$33M on Gearbox and ~$23M on Morpho). The peg later recovered.

Who audits Renzo?

Renzo has been audited by Halborn and Sigma Prime, two reputable blockchain security firms.

What are the main risks of using Renzo?

The main risks include smart contract risk from young code, dependency on EigenLayer's security and slashing mechanisms, cross-chain bridge risks for multi-chain ezETH, and governance risks via the Renzo DAO.

Is Renzo's code open source?

Renzo's smart contracts are publicly verifiable on-chain, though the specific license is not detailed in our records.

Sources