> For the complete documentation index, see [llms.txt](https://kerneldao.gitbook.io/kernel/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kerneldao.gitbook.io/kernel/getting-started/kelp/security/oracle-and-exchange-rate.md).

# Oracle & Exchange Rate

### How the rate is calculated

rsETH is a reward-bearing token. Rewards are not paid out as extra tokens; instead, the amount of ETH each rsETH represents rises over time as staking and restaking rewards accrue to the assets underneath it. So the rate is not a market price, and it does not come from a trading pair. It is share accounting over the assets the protocol actually holds.

The [LRTOracle](https://etherscan.io/address/0x349A73444b1a310BAe67ef67973022020d70020d) contract on Ethereum is the source of rsETH's exchage rate. It reads the balance of every supported asset held across the protocol, prices each one, adds them into a single total ETH value, and divides by the current rsETH supply. The output is the value of one rsETH in ETH. \
\
Because the inputs are on-chain balances rather than a spot quote from an AMM, the rate can't be pushed around by a single swap or a flash-loan sandwich inside one block — there is nothing in-block for an attacker to move.

The live figure is readable directly using `getLiveRsETHPrice()`  on [TotalETHValueReader](https://etherscan.io/address/0x788f0b81809be6f5e07f277a676c7f392c3854aa#readContract#F5) and recomputes the price view-only from per-asset backing, so it works as an independent cross-check against the oracle rather than being a value the oracle writes. This acts as the **Proof of reserves** for rsETH

\
Verify it yourself

Read the live rsETH price from the reserve reader on Ethereum:

```
cast call 0x788f0b81809be6F5e07F277a676C7F392C3854AA \
  "getLiveRsETHPrice()(uint256)" --rpc-url <mainnet_rpc_url>
# returns the rsETH/ETH rate
```

The value should track the rate reported by the LRTOracle contract.

### Guardrails on the rate

Under normal operation the rate only moves one way, upward, as rewards come in. To stop an operational mistake or a mispriced input from ever writing a bad rate, the oracle caps how far a single update can move the price. That cap is `pricePercentageLimit`, currently set to **1%**. \
\
Any update that would move the price by more than the limit is rejected outright. The oracle also keeps the all-time-high price and will auto-pause deposits, withdrawals, and further oracle updates on a downside breach, so a sharp drop stops the system instead of flowing through it.

Control over these parameters is deliberately split. The limit and the bounds around it can only be changed by the 6-of-11 admin multisig. The routine price updates are submitted by the 3-of-6 manager multisig. Neither of those is a single EOA, so there is no individual key anywhere that can quietly rewrite the rate.

### L2 rate path

The canonical rate is computed by the on-chain L1 LRTOracle. On the L2s, the rate is currently relayed — the L1 RSETHMultiChainRateProvider broadcasts it as a LayerZero V1 cross-chain message to each L2's purpose-deployed RSETHRateReceiver, which the L2 deposit pool contracts then read.

Planned upgrade: switch the L2 rate source to Chainlink rate feeds with a 0.5% deviation threshold and a 24-hour heartbeat (typical day-to-day movement ≲1 bps), alongside on-chain sanity-assertions on the L2 rate consumer (rate is zero / positive / in-bounds / not stale / within deviation) as defense-in-depth; currently in audit.

###


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://kerneldao.gitbook.io/kernel/getting-started/kelp/security/oracle-and-exchange-rate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
