กำลังพลิกหน้า
กำลังเปิดบทถัดไป…
นี่… ปรับการอ่านให้เป็นแบบคุณสิ
ฟอนต์และธีมอยู่ใน รูปลักษณ์ เลือกสิ่งที่สบายตาสำหรับคุณ
กำลังเปิดบทถัดไป…
A vault-accounting attack in which manipulation of assets per share and rounding can cause a depositor to receive too few shares.
กำลังตรวจสอบว่าเบราว์เซอร์รองรับการอ่านออกเสียงหรือไม่…
บทอ่านนี้มีเป็นภาษาอังกฤษในขณะนี้ ส่วนติดต่อใช้ภาษาที่คุณเลือก
อ่านต้นฉบับภาษาอังกฤษ →ERC-4626 standardizes a tokenized vault interface, including conversions between deposited assets and vault shares. The standard does not automatically make every implementation economically safe. In a vulnerable design, direct asset transfers can change the assets-per-share ratio without minting matching shares. OpenZeppelin explains how this interacts with rounding, particularly when a vault is empty or has very little share supply.
As an illustrative model, suppose a very small number of outstanding shares comes to represent a large asset balance. A later small deposit may convert to a fraction of one share. If the implementation rounds that result down aggressively, the depositor can receive little or no ownership despite adding assets. The harmful effect comes from the conversion and rounding rules, not from the word inflation referring to ordinary token issuance or consumer-price increases.
Mitigations can include virtual shares and assets, higher share precision, suitable initialization, and user-enforced minimum-share bounds, depending on the design. These choices should be analyzed against the actual implementation and integration. Preview functions are useful estimates but a transaction can execute against changed state, so slippage protections remain important. An audit should test first deposits, direct donations, rounding boundaries, and withdrawal behavior.
A vault using the ERC-4626 interface should not be described as protected merely because its interface conforms to the standard.