Karak Review
Nine-day withdrawal with a slashing window, docs blocked
of 10
Karak secures Distributed Secure Services that can slash restaked funds, documents a 9-day minimum withdrawal delay with a 7-day slashing window, and is BUSL-1.1 converting to MIT in 2027. Its documentation site fails TLS, so most facts came via search extraction and an audit mirror.
No money changes hands. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links. Links to the services below earn us nothing. Every overall score is the plain average of the criteria shown on the page, so you can check the arithmetic yourself — see our rating methodology and how the site is funded.
Type
Restaking into Distributed Secure Services
Withdrawal
9-day minimum (withdraw + veto windows)
Slashing window
Up to 7 days before withdrawal initiation
Vaults
Per-asset ERC-4626, value-accruing
Licence
BUSL-1.1, change date 2 Apr 2027 to MIT
Scores
Each criterion carries equal weight. The overall score is the average of these 5 scores — (2.0 + 6.0 + 7.0 + 5.0 + 4.0) ÷ 5 = 4.8.
Pros
- Distributed Secure Services model documented, with the DSS able to slash malicious behaviour
- Withdrawal delay stated: a 9-day minimum, combining a withdraw window and a veto window
- Slashing window stated at up to 7 days before withdrawal initiation
- Per-asset ERC-4626 vaults, a value-accruing share model
- BUSL-1.1 converting to MIT on 2 April 2027, read from an audit mirror of the contracts
Cons
- The documentation site fails TLS (certificate covers only Netlify), so most facts came via search extraction
- No fee figure was found
- No insurance or exit fee is stated
- Only a Code4rena audit is identifiable, via a third-party platform rather than Karak's own page
Slashing and exit, both quantified
Karak documents a restaking model where operators register with Distributed Secure Services that can slash their funds, a 9-day minimum withdrawal delay combining a withdraw window and a veto window, and a slashing window of up to 7 days for behaviour before withdrawal initiation. Those are specific, useful numbers for understanding what a holder is exposed to and for how long.
The access problem
Karak's documentation site fails TLS — its certificate covers only the underlying Netlify host — so the fee, vault and withdrawal facts here came through search extraction of Karak's own docs, and the licence text was read from a Code4rena audit mirror because the official repository file returned 404. The licence is BUSL-1.1 converting to MIT on 2 April 2027.
What is missing
No fee figure, no insurance and no exit fee could be found, and the only identifiable audit is a Code4rena engagement reached through a third-party platform rather than Karak's own security page. The review scores what could be verified and is explicit about the compromised sourcing.
How it compares
Eigenpie (mLRT)
Isolated per-LST restaking, little else documented
EigenLayer
The restaking layer itself, opt-in slashing stated
Symbiotic
Twelve named auditors and a stated risk framework
Swell Restaking (rswETH)
Value-accruing rswETH, no licence file
Kelp DAO (rsETH)
10% fee and a delayed-open licence
ether.fi (eETH / weETH)
MIT-licensed, three-way reward split published
YieldNest (ynETH)
BSD-licensed with slashing stated plainly
Mellow
Six named auditors on a Symbiotic-and-EigenLayer vault
Renzo (ezETH)
Fee split and withdrawal delays published in full
Sources
Scored from published primary sources rather than hands-on use. Every figure above comes from one of the pages below, on the date shown. Manufacturers change prices and specifications without notice — if something here no longer matches the source, tell us and we will correct it.
Frequently asked questions
How long does a Karak withdrawal take?
Karak documents a 9-day minimum withdrawal delay, combining a withdraw window and a veto window, with a slashing window of up to 7 days before withdrawal initiation.
Is Karak open source?
Its licence is Business Source License 1.1 converting to MIT on 2 April 2027, read from an audit mirror of the contracts because the official repository file was unreachable.
Nothing here is financial advice. Editorial policy · How we score · How we're funded.