{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "vault-inflation-attacks",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/vault-inflation-attacks/",
  "collection": "defi",
  "title": "Vault inflation attacks: donations, rounding and first deposits",
  "description": "Understand how donations and share rounding can harm deposits into vulnerable vaults, and why the exact implementation and defenses matter.",
  "aliases": [],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T18:19:48.887Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A vault inflation attack manipulates the assets-to-shares conversion of a vulnerable vault, often using a donation when few shares exist. A later deposit can then round to very few or even zero shares, shifting value toward existing holders. The weakness depends on implementation; ERC-4626 compatibility alone does not establish that a vault has suitable defenses.",
    "claimId": "vault-inflation-attacks-quick-answer",
    "sourceIds": [
      "oz-vault",
      "eip4626"
    ]
  },
  "keyFacts": [
    {
      "label": "Rounding",
      "value": "Deposits that convert to less than one smallest share unit can round to zero in the illustrated vulnerable design.",
      "sourceIds": [
        "oz-vault"
      ],
      "id": "rounding",
      "claimId": "vault-inflation-attacks-fact-rounding"
    },
    {
      "label": "Donation",
      "value": "Adding assets without minting proportional shares can move the conversion rate.",
      "sourceIds": [
        "oz-vault"
      ],
      "id": "donation",
      "claimId": "vault-inflation-attacks-fact-donation"
    },
    {
      "label": "Defense example",
      "value": "OpenZeppelin describes virtual assets and shares with a precision offset as a defense.",
      "sourceIds": [
        "oz-vault"
      ],
      "id": "defense-example",
      "claimId": "vault-inflation-attacks-fact-defense-example"
    }
  ],
  "prerequisites": [
    "vault-share-price"
  ],
  "sections": [
    {
      "id": "example",
      "heading": "Use base units to see the rounding problem",
      "sourceIds": [
        "oz-vault"
      ],
      "paragraphs": [
        "Consider an intentionally simplified unprotected vault with one smallest share unit and 100 asset base units after a donation. A deposit of 50 asset units computes 50 × 1 / 100 = 0.5 share units, which rounds down to zero.",
        "The depositor receives no shares in that vulnerable calculation. This assumes the vault accepts the deposit and has no offset or minimum-share protection; it is not the behavior of every deployed vault."
      ]
    },
    {
      "id": "mechanism",
      "heading": "The donation changes who receives future value",
      "sourceIds": [
        "oz-vault"
      ],
      "paragraphs": [
        "The attacker must already hold shares to benefit from increasing assets behind existing shares. A later depositor’s rounding loss can then accrue to those holders.",
        "A donation by itself is not proof of an attack or of profitability. Share ownership, precision, transaction ordering and protection mechanisms determine the actual outcome."
      ]
    },
    {
      "id": "defenses",
      "heading": "Inspect the implementation and transaction limits",
      "sourceIds": [
        "oz-vault",
        "eip4626"
      ],
      "paragraphs": [
        "OpenZeppelin explains how virtual balances and increased share precision reduce rounding exposure and make its illustrated donation attack costly. Those properties must actually be present in the implementation being assessed.",
        "ERC-4626 also tells integrators to handle slippage and unexpected conversion changes. Review the exact contract version and caller-enforced minimum outcome rather than assuming a familiar vault interface guarantees safe accounting."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does any increase in assets per share mean the strategy earned yield?",
      "answer": "No. A direct asset donation can change the conversion without strategy earnings. Establish the cause before presenting a share-price change as investment performance.",
      "sourceIds": [
        "oz-vault"
      ]
    }
  ],
  "claims": [
    {
      "id": "vault-inflation-attacks-quick-answer",
      "articleSlug": "vault-inflation-attacks",
      "statement": "A vault inflation attack manipulates the assets-to-shares conversion of a vulnerable vault, often using a donation when few shares exist. A later deposit can then round to very few or even zero shares, shifting value toward existing holders. The weakness depends on implementation; ERC-4626 compatibility alone does not establish that a vault has suitable defenses.",
      "sourceIds": [
        "source-e18b8696025f65d0",
        "source-0500eb916f66cd39"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-e18b8696025f65d0",
          "locator": "Security concern: Inflation attack; Defending with a virtual offset"
        },
        {
          "sourceId": "source-0500eb916f66cd39",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:19:48.887Z",
        "reviewer": "automated independent verification — Codex root, separate from final-ten DeFi author",
        "notes": [
          "Read OpenZeppelin inflation attack and virtual-offset defense, plus ERC-4626 slippage warnings. Recomputed50×1/100=.5 and floor→0 in explicitly unprotected base-unit example. No claim every vault is vulnerable or that donation proves profitable attack."
        ]
      }
    },
    {
      "id": "vault-inflation-attacks-fact-rounding",
      "articleSlug": "vault-inflation-attacks",
      "statement": "Rounding: Deposits that convert to less than one smallest share unit can round to zero in the illustrated vulnerable design.",
      "sourceIds": [
        "source-e18b8696025f65d0"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-e18b8696025f65d0",
          "locator": "Security concern: Inflation attack; Defending with a virtual offset"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:19:48.887Z",
        "reviewer": "automated independent verification — Codex root, separate from final-ten DeFi author",
        "notes": [
          "Read OpenZeppelin inflation attack and virtual-offset defense, plus ERC-4626 slippage warnings. Recomputed50×1/100=.5 and floor→0 in explicitly unprotected base-unit example. No claim every vault is vulnerable or that donation proves profitable attack."
        ]
      }
    },
    {
      "id": "vault-inflation-attacks-fact-donation",
      "articleSlug": "vault-inflation-attacks",
      "statement": "Donation: Adding assets without minting proportional shares can move the conversion rate.",
      "sourceIds": [
        "source-e18b8696025f65d0"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-e18b8696025f65d0",
          "locator": "Security concern: Inflation attack; Defending with a virtual offset"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:19:48.887Z",
        "reviewer": "automated independent verification — Codex root, separate from final-ten DeFi author",
        "notes": [
          "Read OpenZeppelin inflation attack and virtual-offset defense, plus ERC-4626 slippage warnings. Recomputed50×1/100=.5 and floor→0 in explicitly unprotected base-unit example. No claim every vault is vulnerable or that donation proves profitable attack."
        ]
      }
    },
    {
      "id": "vault-inflation-attacks-fact-defense-example",
      "articleSlug": "vault-inflation-attacks",
      "statement": "Defense example: OpenZeppelin describes virtual assets and shares with a precision offset as a defense.",
      "sourceIds": [
        "source-e18b8696025f65d0"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-e18b8696025f65d0",
          "locator": "Security concern: Inflation attack; Defending with a virtual offset"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:19:48.887Z",
        "reviewer": "automated independent verification — Codex root, separate from final-ten DeFi author",
        "notes": [
          "Read OpenZeppelin inflation attack and virtual-offset defense, plus ERC-4626 slippage warnings. Recomputed50×1/100=.5 and floor→0 in explicitly unprotected base-unit example. No claim every vault is vulnerable or that donation proves profitable attack."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "oz-vault",
      "label": "ERC-4626",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/erc4626",
      "locator": "Security concern: Inflation attack; Defending with a virtual offset",
      "note": "Vault share conversion, rounding, donations and inflation-attack defenses.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02T17:03:43.088Z",
      "contentSha256": "76a796f770dd8a76bb890dbe91359d0f35582c995e72e1aa809f32b41831005f",
      "recordId": "source-e18b8696025f65d0"
    },
    {
      "id": "eip4626",
      "label": "Tokenized Vaults",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-4626",
      "locator": "Specification; Security Considerations",
      "note": "Assets, shares, deposits, withdrawals, limits and preview rounding.",
      "version": "EIP/ERC-4626; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.366Z",
      "contentSha256": "0f3b3abdb9e37ef4094f0ad5c6c469a56e888fcc52415d4bf8e657e2b34792ab",
      "recordId": "source-0500eb916f66cd39"
    }
  ],
  "related": {
    "articles": [
      "vault-share-price",
      "yield-vaults",
      "smart-contract-audits"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and independent automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Vault inflation attacks: donations, rounding and first deposits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/vault-inflation-attacks/"
}
