# \[ARFC\] Onboard rsETH to Arbitrum and Base V3 Instances

**URL:** <https://governance.aave.com/t/arfc-onboard-rseth-to-arbitrum-and-base-v3-instances/20741>\
**Category:** Governance\
**Created:** [January 21, 2025, 11:48am UTC](https://governance.aave.com/t/arfc-onboard-rseth-to-arbitrum-and-base-v3-instances/20741 "2025-01-21T11:48:58Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![bgdlabs](https://dub1.discourse-cdn.com/flex013/user_avatar/governance.aave.com/bgdlabs/32/1829_2.png) [@bgdlabs](https://governance.aave.com/u/bgdlabs)\
**Post date:** [February 20, 2025, 2:35pm UTC](https://governance.aave.com/t/arfc-onboard-rseth-to-arbitrum-and-base-v3-instances/20741/5 "2025-02-20T14:35:10Z")

</div>

# rsETH (Arbitrum and Base) technical analysis
  

## Summary

Following the new proposal for listing it on Base and Arbitrum, we have checked how the KelpDAO Team had implemented the rsETH bridge mainnet \<\> L2s and native restaking.  
This is a technical analysis of all the smart contracts of the asset and main bridge dependencies.

_Disclosure:_ This is not an exhaustive security review of the asset like the ones done by the KelpDAO team, but an analysis from an Aave technical service provider on different aspects we consider critical to review before a new type of listing, in this case of a cross-chain asset.

  

## Analysis

The Kelp Team has added support for its cross-chain asset via two different layers:

- A native L2 minting system, where users can deposit ETH and LSTs for rsETH, which later on gets bridged to mainnet.
- A cross-chain bridge via LayerZero infrastructure, where tokens are locked in an OFT adapter contract on mainnet and minted on the respective L2.

  

### Bridge

The main cross-chain rsETH bridge to L2s (Base and Arbitrum in this case) relies on the Layer Zero infrastructure. The bridge flow between chains consists of a few steps:

- **L1 → L2s:**

- **L2s → L1:**

- **L2 → L2:**

  

### L2 Native Minting

The Kelp Team enables minting rsETH on both chains via the deposit pool contract. Later, the assets in the deposit pool are bridged back to the mainnet to be restaked via the `bridgeAssets()` function.

- Users can mint wrsETH on Base by depositing ETH via the `deposit(msg.value)` function.
- On Arbitrum, the Kelp treasury provides rsETH already bridged, so it is not a native minting, but users can swap ETH, ETHx, and stETH for rsETH via the `deposit(token, amount)` function.
- The exchange rate is calculated internally using the current exchange rate from the rsETH oracle, which is fetched using the `rsETHOracle.getRate()` function.
- The `rsETHOracle` contract receives the rate via a cross-chain rate provider deployed on Ethereum. This provider contract broadcasts the current rate to the respective chains via LayerZero cross-chain messages.

It’s important to mention that the deposit pool contract imposes a 500 rsETH/day limit on Base.

  

### Contracts
  

**Access Control:**

The system has role-based access control, which we described below.

- `DEFAULT_ADMIN_ROLE`: Is responsible for configuring the important addresses (oracle, layerZero endpoint, assets being deposited) and the general fees, as well as other roles.
- `BRIDGER_ROLE`: It manages the deposited assets on the L2 by sending them to the L1VaultETH contract on mainnet to mint rsETH, which is bridged to the L2 (see L1 → L2s bridge section for a detailed flow of the assets).
- `MANAGER_ROLE`: This is not used in other contracts where it is present, but it is used in L1VaultETH contract to mint rsETH and send it back to L2 (see L1 → L2s bridge section for a detailed flow of the assets).
- `LEGACY_MANAGER_ROLE`: deprecated.

  

**Ethereum Mainnet**

| **Contract** | **Role** | **Admin** | **Upgradable** |
| --- | --- | --- | --- |
| [RSETH\_OFTadapter](https://etherscan.io/address/0x85d456b2dff1fd8245387c0bfb64dfb700e98ef3#code) | OFT adapter for bridge rsETH via LayerZero | [Safe 3-of-6](https://etherscan.io/address/0xCbcdd778AA25476F203814214dD3E9b9c46829A1) | No |
| [RSETHMultiChainRateProvider](https://etherscan.io/address/0x0788906B19bA8f8d0e8a7015f0714DF3179D9aB6#code) | Exchange rate provider for L2s using LayerZero infrastructure | [Timelock](https://etherscan.io/address/0x10e5631320A6e7898F1b18aEADE46Acc81deB869#code) (3 days) | No |
| [L1VaultETH](https://etherscan.io/address/0x48cdad4c3c7a2f5818dab5eb08df7db5420a60f6#readProxyContract) | the receiver of ETH bridged from L2, which mints rsETH on L1 and send it back to the L2 | [Safe 3-of-6](https://etherscan.io/address/0xCbcdd778AA25476F203814214dD3E9b9c46829A1) (`DEFAULT_ADMIN_ROLE`,`MANAGER_ROLE`); [EOA](https://basescan.org/address/0xF2099c4783921f44Ac988B67e743DAeFd4A00efd) (`MANAGER_ROLE`) | [ProxyAdmin](https://etherscan.io/address/0x2155ab0b399a71df8c464dfc1b02149b53b2b2c1#readContract) → [Timelock](https://etherscan.io/address/0x10e5631320A6e7898F1b18aEADE46Acc81deB869#code) (3 days) |

  

**Arbitrum**

| **Contract** | **Role** | **Admin** | **Upgradable** |
| --- | --- | --- | --- |
| [Deposit Pool](https://arbiscan.io/address/0x376A7564AF88242D6B8598A5cfdD2E9759711B61#readProxyContract) | The main entrance for users who want to swap rsETH | [Safe 3-of-6](https://arbiscan.io/address/0x96D97D66d4290C9182A09470a5775FF90DAf922c#readProxyContract) (`DEFAULT_ADMIN_ROLE`, `BRIDGER_ROLE`) | [ProxyAdmin](https://arbiscan.io/address/0x4938c803EBe999FB0A5527310662624f2E7A38C1#readContract) → [Timelock](https://arbiscan.io/address/0xe15109D97e84cacEd271502C5D1DBbC50A4D6B0C#readContract) (3 days) |
| [rsETH](https://arbiscan.io/address/0x4186BFC76E2E237523CBC30FD220FE055156b41F) | OFT adapter representing rsETH bridged | [Safe 3-of-6](https://arbiscan.io/address/0x96D97D66d4290C9182A09470a5775FF90DAf922c#readProxyContract) | No |
| [rsETHOracle](https://arbiscan.io/address/0x3222d3De5A9a3aB884751828903044CC4ADC627e#readContract) | cross chain rsETH exchange rate receiver | [Timelock](https://arbiscan.io/address/0xe15109D97e84cacEd271502C5D1DBbC50A4D6B0C#readContract) (3 days) | No |

  

**Base**

| **Contract** | **Role** | **Admin** | **Upgradable** |
| --- | --- | --- | --- |
| [Deposit Pool](https://basescan.org/address/0x291088312150482826b3a37d5a69a4c54daa9118) | The main entrance for users who want to mint rsETH | [Safe 3-of-6](https://basescan.org/address/0x7Da95539762Dd11005889F6B72a6674A4888B56d) (`DEFAULT_ADMIN_ROLE`, `BRIDGER_ROLE`) | [ProxyAdmin](https://basescan.org/address/0xDf3f5926Fd14Ed048B04941189da54BdEDD478d0#readContract) → [Timelock](https://basescan.org/address/0xf425ed48483B49cF10C8a7f6cFd25dFD86d3155a#readContract) (10 days) |
| [rsETH](https://basescan.org/address/0x1Bc71130A0e39942a7658878169764Bbd8A45993#readContract) | OFT adapter representing rsETH bridged | [Safe 3-of-6](https://basescan.org/address/0x7Da95539762Dd11005889F6B72a6674A4888B56d) | No |
| [wrsETH](https://basescan.org/address/0xEDfa23602D0EC14714057867A78d01e94176BEA0#readProxyContract) | Wrapper for OFT rsETH | [Safe 3-of-6](https://basescan.org/address/0x7Da95539762Dd11005889F6B72a6674A4888B56d) (`DEFAULT_ADMIN_ROLE`); [EOA](https://basescan.org/address/0xF2099c4783921f44Ac988B67e743DAeFd4A00efd) (`BRIDGER_ROLE`) | [ProxyAdmin](https://basescan.org/address/0xDf3f5926Fd14Ed048B04941189da54BdEDD478d0#readContract) → [Timelock](https://basescan.org/address/0xf425ed48483B49cF10C8a7f6cFd25dFD86d3155a#readContract) (10 days) |
| [rsETHOracle](https://basescan.org/address/0x7781ae9B47FeCaCEAeCc4FcA8d0b6187E3eF9ba7#code) | Cross-chain rsETH exchange rate receiver | [Timelock](https://basescan.org/address/0xf425ed48483B49cF10C8a7f6cFd25dFD86d3155a#readContract) (10 days) | No |

  

## Price strategy

The Kelp team has not only bridged the rsETH token itself but also added the rsETH Oracle to support the native L2 minting, which receives the rate via LayerZero cross-chain messages from a rate provider on mainnet. Apart from this, Chainlink also has rate feeds on both chains, which pulls the exchange rate from the mainnet oracle.

Given that we don’t see any issue with synchronization of the rate update between Chainlink feeds and the rsETH Oracle (depending on LayerZero), we think it makes sense to use the Chainlink feeds in order to be consistent with other Aave approaches on cross-chain pricing.

  

## Miscellaneous aspects

- The system has security review by Mixbytes, and can be found [here](https://kelpdao.xyz/audits/smartcontracts/mixbytes.pdf).
- Currently, Kelp is using LayerZero’s DVN for the verifications. We suggest that this can be expanded to other DVNs.

  

## Conclusion

We think rsETH has no problem integrating with Aave on Base and Arbitrum.  
The Kelp Team has already addressed our recommendations for time-locking the sensitive contracts for the L2 bridging and minting system, and there is no major blocker for listing.

---

_[View the full topic](https://governance.aave.com/t/arfc-onboard-rseth-to-arbitrum-and-base-v3-instances/20741)._
