ERC-4626 vault vulnerability exposes first depositor to inflation attack
A security vulnerability known as the first-depositor inflation attack threatens ERC-4626 token vaults. The exploit occurs when a vault starts with zero assets and shares, allowing attackers to manipulate share pricing. An attacker can deposit a minimal amount, inflate the vault's asset balance through direct token transfer, then extract funds from subsequent legitimate depositors. This vulnerability stems from using raw token balances for accounting and integer rounding logic. OpenZeppelin's implementation includes mitigation through virtual shares and assets, while other implementations require additional safeguards.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in