ページをめくっています。
次の章を表示しています…
A vault-accounting attack in which manipulation of assets per share and rounding can cause a depositor to receive too few shares.
ブラウザーの読み上げ対応を確認しています…
この読み物は現在、英語で提供されています。画面の操作部分には、選択した言語を使用しています。
英語の原文を読む →ERC-4626 standardizes a tokenized vault interface, including conversions between deposited assets and vault shares. The standard does not automatically make every implementation economically safe. In a vulnerable design, direct asset transfers can change the assets-per-share ratio without minting matching shares. OpenZeppelin explains how this interacts with rounding, particularly when a vault is empty or has very little share supply.
As an illustrative model, suppose a very small number of outstanding shares comes to represent a large asset balance. A later small deposit may convert to a fraction of one share. If the implementation rounds that result down aggressively, the depositor can receive little or no ownership despite adding assets. The harmful effect comes from the conversion and rounding rules, not from the word inflation referring to ordinary token issuance or consumer-price increases.
Mitigations can include virtual shares and assets, higher share precision, suitable initialization, and user-enforced minimum-share bounds, depending on the design. These choices should be analyzed against the actual implementation and integration. Preview functions are useful estimates but a transaction can execute against changed state, so slippage protections remain important. An audit should test first deposits, direct donations, rounding boundaries, and withdrawal behavior.
A vault using the ERC-4626 interface should not be described as protected merely because its interface conforms to the standard.