New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Inflation Attacks: A deep dive on ERC-4626 - Cupojoseph | Nerite.org

ETH Belgrade CommunityTue, Oct 7, 2025, 12:00 AM

Inflation Attacks: A deep dive on ERC-4626 - Cupojoseph | Nerite.org

Transcript

Okay, very good. We've got the after lunch crowd. Very good. Uh so before we start, I just want to know like who's in the room. So uh raise your hand if you are a Solidity developer.

Okay, raise your hand if you work in security in some way, smart contract security. Okay, raise your hand if you want to work in smart contract security and you're here to learn. Okay, you're all already experts. Got it. Except for this guy.

He needs help. Okay, so uh yes, I'm I'm Joseph. Today we're going to talk about uh 4626, which is one of our favorite Ethereum standards. It's a token standard. It's also known as the vault standard and it was uh we're going to go into the history of that.

We're going to have a little uh overview and uh then we're going to talk about an attack vector called inflation attacks and learn all about that. So uh first off, I'm Joseph. Uh thank you for the the intro earlier. I won't spend too much time showing my own stuff. Uh but I think 4626 is very cool and um so that's why I wanted to give a talk about it.

Uh I use it a lot and it's also very good for experimenting because there's lots of 4626 support in all of other protocols that you want to connect to. So, we're going to talk about why it's cool, then learn about uh that attack vector, and then how to prevent it so that you can become your a security auditor and get bug bounties on billion-dollar protocols by the end of this talk. Okay, do you believe me? Okay, good. Uh let's see.

Now, I lost my slide. Oh, next one. There we go. So, number one, vaults are cool. So, uh, who has ever deposited in a vault?

Any type of vault? Everybody who's paying attention. Great. So, vaults are very good because you can put things into them and your assets might become more valuable or you get some utility out of it. And there's only so many different things that we really do with our tokens.

We sell them, we hold them, we buy more. Uh but one of the other things is we put them in vaults and it's either a staking vault or a yield aggregation vault or a savings account vault where you put in dollars and it earns savings yield, right? So there's all these different types of experiences and there's no particular one thing that ERC 4626 was built for and there's no one particular use case. It's anytime anytime people put money in and they want to get it back later with some additional benefit. Um this is a way to do that.

So lots of companies have made vaults uh year alchemics beefy they have different types of lending and different types of yieldbearing vaults where you can deposit stable coins or deposit ETH. and they all kind of came together and said, "Hey, we want all of our vaults to work together. We want everyone to have one standardized interface for the things that vaults do." So, if you have a vault, what's uh what what are some of the actions that there are on a on a vault? Somebody Yes.

Deposit. What else?

Redeem. Yeah. What else could someone do on a vault? Maybe liquidate, right? Unstake, stake, stuff like that.

So, if we have a common interface that everybody uses, then we can build really cool experiences like Bunny has done. And Bunny lets you deposit LP tokens into Uniswap. So, you can put tokens in and you can rehypothecate that liquidity into any 4626 vault. So any urine vault, any Gearbox or Alchemix or Beefy Vault, you can move tokens around really, really easily. And because everything's standardized, it's safer.

Uh, and it's much much cheaper to build because we can build this oursel in like two minutes. Uh, so hooray, we did it. We solved vaults in crypto, right? Uh, well, not quite. There's some interesting things that we have to know about a vault.

So anytime you put one token into a vault, you should get a receipt for one token, right? But if the value of the one that I have deposited is going up, right? Let's say I've deposited into some kind of yield bearing vault and the value of it doubles. Now when I put one in, I only get 0.5 back, right?

Because the value has doubled. So the exchange rate changes over time. So the exchange rate of tokens going into the vault and how many tokens you can redeem it for changes over time. So let's see receipt. There we go.

All right. So we've got different lines here and each line is a particular redemption rate. So, we've got a rate of put in one, get 0.5 out, put in one, get one out, put in one, get two out. Right?

And those are the different lines, right? It's basically y equals x or y = 2x, right? Um, so we can kind of plot that on a graph to make it a lot more visual. And we've got a problem already because what happens if you have 0.5 of an asset?

What happens if you have 0.5 of a token in Ethereum land? Who knows? Solidity developers. H half the crowd already raised their hand and said they were a Solidity developer.

Yes.

Uh oh. It rounds down. That's right. So if you ever have five of something, it's always going to round down in favor of the vault value and rug the user. So raise your hand if you love rugging your users.

Get this man out of here. Security. All right. So, we don't love rugging our users. We hate rugging our users.

We love our users. We don't want them to get rugged. So, anytime someone deposits one and we give them 0.5, that rounds down to zero. So, they're going to put in one token and they're going to get zero tokens out.

That's very sad. So, we don't we don't like that. Another way we can plot that same exact graph, I'm going to go back. So we have we have these three lines. These are the the top three lines, right?

The blue, the purple, the blue, the green. Those those are the same exact lines just plotted on uh base 10 instead of linearly, right? So if we plot this, this is the exchange rate of different vaults, right? Or of the same vault at different values. So if I have a uh if I have a place on this curve right I'm exchanging 10 to the 0ero that's one right token and I get one token so what happens if that changes right it's going to change over time as my tokens become more valuable and that means there's another way it could change.

What if somebody donates to the vault, right? And they send 10 cents or they send a dollar themselves directly to the vault, then the next person who deposits is going to get a worse rate, right? Because they're not going to get the one for one. The value in the vault is now slightly more. So if that is one for one, maybe it's 1.

1 for one, right? or 1.5 even or 10 to one. Right? So this inflation attack exists where essentially the graph slides over to the right because the value inside of it has been increased uh and we didn't prepare for that.

So we have this super awesome standard 4626 and everybody should use it for your hackathon projects. If you want to become an auditor, you're gonna run into this all the time because it's one of the most used smart contract interfaces now. Uh but just because that code has been audited and it's a standard and it's safe and people like it doesn't mean that it's safe no matter what forever, right? So this is a very known issue, this inflation attack where the value inside the vault has been inflated and moved to the right. And now that rate of redemption is not as good for the user and depending on what those numbers are, the user could lose all of their money, right?

If they if they uh if the rate brings them down to a decimal and it rounds to zero. So every time we make a new uh we make a new vault, we have to simulate not just what is happening when we when everything is going well, but what happens if people donate to the vault and what happens uh what happens if somebody frontr runs our initial deposit into the vault, right? So we got to be really careful of these roundings and the inflation attack uh is real and can happen to you. So let's look at another example here. If you deposit 500 assets on this curve, that's kind of how much you get back, right?

So depending on where you are or which which rate of redemption you're on, right? which graph you're on. You could get uh you could get 500 assets back or you could get zero because you got slightly less than one. So, it depends on where this graph is. And if you move the slider to the right, if you move where the redemption rate is to the right,

the what?

There's a laser button.

Oh, there's a laser. Okay, cool. Boom. Whoa. I'll try that.

We've moved the graph to the right, but now the place that they redeem it is down here. And if that is less than one, then the user's totally rugged. They've lost all their money because they got zero uh they got zero dollars left because of the rounding. So inflation rounding that could happen. All right.

What's this one? I don't know. That's the same. Okay. So, the solution, what's the solution?

Uh, I meant to ask everybody to come up with their own solution, but I already skipped it. So, we'll just go on to this. So, solution, limit the deposits. You can write your contract that says uh you're not allowed to deposit right at the same time that somebody else has just deposited. So, if an attacker deposits to try to suck up the yield and earn all those fees uh and earn the normal users deposit by attacking them, you can say, "Hey, you're only allowed to deposit 10 blocks after or you're only allowed to deposit a certain amount of the percentage of the total vault value."

Right? So we can do things that don't allow the attacker to use flash loans to attack our vault uh and say okay you have to wait until an unlock period. Uh or we can check for rounding right we can just do the math ourselves and say hey did any rounding happen uh and if a maximum amount of slippage has been detected then just revert and don't let the user deposit and don't let our users get wrecked. Uh or you could seed all the vaults yourself and have initial liquidity in all of them and make sure that users are not allowed to deposit until uh there's a certain amount of liquidity that you already control and then make it more centralized. But that's not not as fun.

So, uh vaults are really good. They let us create money Legos. So, I got this little money Lego over here, right? We've got Ethereum, Year, Alchemix, Compound. They all use these vaults.

They all use 4626 vaults. Not Ethereum directly, but and and Alchemix and Compound do. So we want them all to play together and people are going to uh give you contracts to audit or ask you to integrate with whatever you are building and connect to our vault or get your users to deposit in our vault or our vault is going to interact with your protocol in some way. They're going to ask you that and this because it's standardized, it's going to feel like everything is going to be just perfect all the time because we love ERC standards. Uh but actually you must be very careful because inflation and tax are real.

Uh and if you wanted to be an auditor, somebody said that they were trying to become an auditor. Uh this is a very common issue that you can make lots of money by pointing out to people. So, uh, that's pretty much it. I'm Joseph. Thank you for coming.

Um, I hope that this has been a little bit valuable for you and that you will never ever be inflation attacked. Thank you.

Okay, big applause. Um, we can start the Q&A session. So, if you have a question, please raise your hand.

Great. And we're well ahead schedule. So if you have any questions that's not specific about this talk or vaults in general, you just want to know what my favorite food is, that is totally cool, too.

Yes.

So what is your favorite solution for solving inflation attack?

My my favorite solution is adding Oh, where did I go? There we go. Is this one I love this laser pointer. This is great. is check for rounding and uh adding a slippage parameter that is not enforced by the vault but rather completely up to the user.

So like you go on unis swap you get to choose what slippage you want right if you're making a trade you should have complete freedom to wreck yourself with 100% slippage and lose all your money or you have a default value of like 0.1 right and uh personally I believe in autonomy and freedom and everyone should be able to uh have the freedom to wreck themselves if they want. So you can have a slippage parameter that can be set uh by the user and give them a healthy default value and revert if uh the actual slippage is over that percentage.

Does that does that answer your question?

Yeah, but this breaks the interface, right?

But it breaks the interest

interface standard interface.

Yes, it might break the interface. It's possible. Yeah. So you can also uh you could maintain the same interface of the contracts and uh have a separate variable that the user sets outside and if it's not set use the default one of 0.1% or something like that.

How's that? Because then it doesn't break the interface.

Really nice. Really nice man.

Yeah. Okay. Thank you.

Uh any other any other questions? Thank you for that. That was a a a good question. Anything else? Andre, what's your question?

What's the best country in the world?

What's the best contract in the world?

Country.

Country.

Uh, Serbia is very nice. I'm having a great time here. So, thanks for all the Serbians who uh have welcomed me and been very polite.

Any any other serious question? Any other silly question? Okay. Uh, thanks for coming. I really appreciate uh seeing so many people and listening to me.

I appreciate you all and please message me if uh you ever need a security audit or um you need help with anything related to this uh or you just want to talk. So thanks.

Okay, huge applause. Thank you. Thank

Automatic transcript — names and jargon may be misspelled.