Membuka halaman berikutnya.
Menampilkan bab berikutnya…
Psst… sesuaikan cara membaca Anda.
Font dan tema ada di Tampilan. Mata Anda juga berhak memilih.
Menampilkan bab berikutnya…
A vault-accounting attack in which manipulation of assets per share and rounding can cause a depositor to receive too few shares.
Memeriksa dukungan baca nyaring pada peramban ini…
Bacaan ini saat ini tersedia dalam bahasa Inggris. Antarmuka menggunakan bahasa pilihan Anda.
Baca teks asli bahasa Inggris →ERC-4626 standardizes a tokenized vault interface, including conversions between deposited assets and vault shares. The standard does not automatically make every implementation economically safe. In a vulnerable design, direct asset transfers can change the assets-per-share ratio without minting matching shares. OpenZeppelin explains how this interacts with rounding, particularly when a vault is empty or has very little share supply.
As an illustrative model, suppose a very small number of outstanding shares comes to represent a large asset balance. A later small deposit may convert to a fraction of one share. If the implementation rounds that result down aggressively, the depositor can receive little or no ownership despite adding assets. The harmful effect comes from the conversion and rounding rules, not from the word inflation referring to ordinary token issuance or consumer-price increases.
Mitigations can include virtual shares and assets, higher share precision, suitable initialization, and user-enforced minimum-share bounds, depending on the design. These choices should be analyzed against the actual implementation and integration. Preview functions are useful estimates but a transaction can execute against changed state, so slippage protections remain important. An audit should test first deposits, direct donations, rounding boundaries, and withdrawal behavior.
A vault using the ERC-4626 interface should not be described as protected merely because its interface conforms to the standard.