# Vault inflation attacks: donations, rounding and first deposits

A vault inflation attack manipulates the assets-to-shares conversion of a vulnerable vault, often using a donation when few shares exist. A later deposit can then round to very few or even zero shares, shifting value toward existing holders. The weakness depends on implementation; ERC-4626 compatibility alone does not establish that a vault has suitable defenses.

Evidence: [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626); [Tokenized Vaults](https://eips.ethereum.org/EIPS/eip-4626)

Canonical: https://degreesofsatoshi.com/encyclopedia/vault-inflation-attacks/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T18:19:48.887Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Rounding:** Deposits that convert to less than one smallest share unit can round to zero in the illustrated vulnerable design. ([ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626))
- **Donation:** Adding assets without minting proportional shares can move the conversion rate. ([ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626))
- **Defense example:** OpenZeppelin describes virtual assets and shares with a precision offset as a defense. ([ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626))

## Use base units to see the rounding problem

Consider an intentionally simplified unprotected vault with one smallest share unit and 100 asset base units after a donation. A deposit of 50 asset units computes 50 × 1 / 100 = 0.5 share units, which rounds down to zero.

The depositor receives no shares in that vulnerable calculation. This assumes the vault accepts the deposit and has no offset or minimum-share protection; it is not the behavior of every deployed vault.

Evidence: [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626)

## The donation changes who receives future value

The attacker must already hold shares to benefit from increasing assets behind existing shares. A later depositor’s rounding loss can then accrue to those holders.

A donation by itself is not proof of an attack or of profitability. Share ownership, precision, transaction ordering and protection mechanisms determine the actual outcome.

Evidence: [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626)

## Inspect the implementation and transaction limits

OpenZeppelin explains how virtual balances and increased share precision reduce rounding exposure and make its illustrated donation attack costly. Those properties must actually be present in the implementation being assessed.

ERC-4626 also tells integrators to handle slippage and unexpected conversion changes. Review the exact contract version and caller-enforced minimum outcome rather than assuming a familiar vault interface guarantees safe accounting.

Evidence: [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626); [Tokenized Vaults](https://eips.ethereum.org/EIPS/eip-4626)

## Questions

### Does any increase in assets per share mean the strategy earned yield?

No. A direct asset donation can change the conversion without strategy earnings. Establish the cause before presenting a share-price change as investment performance.

Evidence: [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626)

## Claims and scope

### vault-inflation-attacks-quick-answer

A vault inflation attack manipulates the assets-to-shares conversion of a vulnerable vault, often using a donation when few shares exist. A later deposit can then round to very few or even zero shares, shifting value toward existing holders. The weakness depends on implementation; ERC-4626 compatibility alone does not establish that a vault has suitable defenses.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### vault-inflation-attacks-fact-rounding

Rounding: Deposits that convert to less than one smallest share unit can round to zero in the illustrated vulnerable design.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### vault-inflation-attacks-fact-donation

Donation: Adding assets without minting proportional shares can move the conversion rate.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### vault-inflation-attacks-fact-defense-example

Defense example: OpenZeppelin describes virtual assets and shares with a precision offset as a defense.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [ERC-4626](https://docs.openzeppelin.com/contracts/5.x/erc4626) — OpenZeppelin. Vault share conversion, rounding, donations and inflation-attack defenses. Locator: Security concern: Inflation attack; Defending with a virtual offset. Retrieved: 2026-10-02T17:03:43.088Z.
- [Tokenized Vaults](https://eips.ethereum.org/EIPS/eip-4626) — Ethereum Improvement Proposals. Assets, shares, deposits, withdrawals, limits and preview rounding. Locator: Specification; Security Considerations. Retrieved: 2026-10-02T17:03:42.366Z.

## Revision history

- 2026-10-02: First publication after primary-source research and independent automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Vault inflation attacks: donations, rounding and first deposits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/vault-inflation-attacks/
