All vaults

Spec mismatch

0x79b0D94d84D1EE1021E0077E6cD36091e28276c5

0x79b0D94d84D1EE1021E0077E6cD36091e28276c5Monad mainnet

2 of 30 properties failed at block 111,193,713. The vault's behavior contradicts an EIP-4626 MUST sentence.

Found by the watcher at its first Deposit event in block 110,981,283, 2026-10-06 16:51 UTC. No factory the watcher follows announced it. It was not on the hand-made list the board started from.

What failed

  • sf-maxWithdraw-honoredEIP-4626 MUST

    maxWithdraw was 948,377,805,652,677,803,591,669, but withdraw(1,719) reverted with 0x23c85ecd.

    EIP-4626: maxWithdraw MUST return the maximum amount of assets withdraw accepts without reverting, and 0 while withdrawals are disabled.

    Counterexample: test_sf_maxWithdraw_honored(23591211398699137692442106053138452891147, 9307740202017086815948377805652677803591669, 1719)

  • sf-maxRedeem-honoredEIP-4626 MUST

    maxRedeem was 948,377,805,652,677,803,591,669, but redeem(1,719) reverted with 0x23c85ecd.

    EIP-4626: maxRedeem MUST return the maximum amount of shares redeem accepts without reverting, and 0 while redemptions are disabled.

    Counterexample: test_sf_maxRedeem_honored(23591211398699137692442106053138452891147, 9307740202017086815948377805652677803591669, 1719)

A spec mismatch is a disagreement with an EIP-4626 MUST sentence, shown by a concrete call. It is not a claim that funds are at risk.

What the watcher saw

Every event the watcher recorded for this vault, newest first. Each check is a statement about one block; a re-check with the same outcome is recorded here without a new attestation.

  1. First result
    Spec mismatch

    16 pass, 2 fail, 12 inconclusive, 0 not applicable.

    Now failing: sf-maxRedeem-honored, sf-maxWithdraw-honored

  2. Checked
    Spec mismatch

    16 pass, 2 fail, 12 inconclusive, 0 not applicable at block 111,193,713, 3 min. Report

    Why: first Deposit event from an unknown address.

  3. Queued

    Waiting for a check: first Deposit event from an unknown address.

  4. Checked
    Spec mismatch

    16 pass, 2 fail, 12 inconclusive, 0 not applicable at block 111,123,284, 7 min. Report

    Why: first Deposit event from an unknown address.

  5. Queued

    Waiting for a check: first Deposit event from an unknown address.

  6. Found

    First Deposit event from an unknown address in block 110,981,283 tx 0xc89d15...aa4b8c

JSON: this vault's history

All 30 properties

In report order. Bit i is the bit the registry's passedBitmap and failedBitmap use for that property.

BitPropertyResultWhat was found
a16z/erc4626-tests at ac48546, 26 properties: 16 on EIP-4626 MUST sentences, 10 on SHOULD guidance (the round trips and the allowance checks)
0assettest_assetEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: asset() does not revert

1totalAssetstest_totalAssetsEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: totalAssets() does not revert

2convertToSharestest_convertToSharesEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: convertToShares gives the same result for any caller

3convertToAssetstest_convertToAssetsEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: convertToAssets gives the same result for any caller

4maxDeposittest_maxDepositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxDeposit does not revert

5previewDeposittest_previewDepositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit mints at least the shares previewDeposit quoted

6deposittest_depositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit moves assets from the caller, credits shares to the receiver and spends allowance

7maxMinttest_maxMintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxMint does not revert

8previewMinttest_previewMintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint pulls at most the assets previewMint quoted

9minttest_mintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint moves assets from the caller, credits shares to the receiver and spends allowance

10maxWithdrawtest_maxWithdrawEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxWithdraw does not revert

11previewWithdrawtest_previewWithdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: withdraw burns at most the shares previewWithdraw quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
12withdrawtest_withdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: withdraw burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
13withdraw-zero-allowancetest_withdraw_zero_allowanceEIP-4626 SHOULDPass

No counterexample in 16 fuzz runs at this block.

Checks: withdraw on behalf of an owner without allowance reverts

14maxRedeemtest_maxRedeemEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxRedeem does not revert

15previewRedeemtest_previewRedeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: redeem pays at least the assets previewRedeem quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
16redeemtest_redeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: redeem burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
17redeem-zero-allowancetest_redeem_zero_allowanceEIP-4626 SHOULDPass

No counterexample in 16 fuzz runs at this block.

Checks: redeem on behalf of an owner without allowance reverts

18RT-deposit-redeemtest_RT_deposit_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: redeem(deposit(a)) returns no more than a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
19RT-deposit-withdrawtest_RT_deposit_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: withdraw(a) burns at least the shares deposit(a) minted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
20RT-redeem-deposittest_RT_redeem_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: deposit(redeem(s)) mints no more than s

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
21RT-redeem-minttest_RT_redeem_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: mint(s) costs at least the assets redeem(s) paid

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
22RT-mint-withdrawtest_RT_mint_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: withdraw(mint(s)) burns at least s shares

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
23RT-mint-redeemtest_RT_mint_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: redeem(s) pays no more than mint(s) cost

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
24RT-withdraw-minttest_RT_withdraw_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: mint(withdraw(a)) costs at least a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
25RT-withdraw-deposittest_RT_withdraw_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: deposit(a) mints no more than the shares withdraw(a) burned

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
Specfirst max-honored properties, MIT, each on one EIP-4626 MUST sentence about a max function
26sf-maxDeposit-honoredtest_sf_maxDeposit_honoredEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit does not revert for amounts up to maxDeposit (EIP-4626: maxDeposit is the most deposit accepts without reverting)

27sf-maxMint-honoredtest_sf_maxMint_honoredEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint does not revert for shares up to maxMint (EIP-4626: maxMint is the most mint accepts without reverting)

28sf-maxWithdraw-honoredtest_sf_maxWithdraw_honoredEIP-4626 MUSTFail

maxWithdraw was 948,377,805,652,677,803,591,669, but withdraw(1,719) reverted with 0x23c85ecd. EIP-4626: maxWithdraw MUST return the maximum amount of assets withdraw accepts without reverting, and 0 while withdrawals are disabled.

Checks: withdraw does not revert for assets up to maxWithdraw (EIP-4626: maxWithdraw MUST return 0 when withdrawals are disabled)

Raw result
reason: withdraw(1719) reverted with selector 0x23c85ecd while maxWithdraw is 948377805652677803591669
runs: 0
call: test_sf_maxWithdraw_honored(23591211398699137692442106053138452891147, 9307740202017086815948377805652677803591669, 1719)
calldata: 0x72b950e200000000000000000000000000000045540e0bb3cf1181ed6b6eac2768f4c60b00000000000000000000000000006ad8fd74f6d33d051a19c7797951329747f500000000000000000000000000000000000000000000000000000000000006b7
29sf-maxRedeem-honoredtest_sf_maxRedeem_honoredEIP-4626 MUSTFail

maxRedeem was 948,377,805,652,677,803,591,669, but redeem(1,719) reverted with 0x23c85ecd. EIP-4626: maxRedeem MUST return the maximum amount of shares redeem accepts without reverting, and 0 while redemptions are disabled.

Checks: redeem does not revert for shares up to maxRedeem (EIP-4626: maxRedeem MUST return 0 when redemptions are disabled)

Raw result
reason: redeem(1719) reverted with selector 0x23c85ecd while maxRedeem is 948377805652677803591669
runs: 0
call: test_sf_maxRedeem_honored(23591211398699137692442106053138452891147, 9307740202017086815948377805652677803591669, 1719)
calldata: 0x942509aa00000000000000000000000000000045540e0bb3cf1181ed6b6eac2768f4c60b00000000000000000000000000006ad8fd74f6d33d051a19c7797951329747f500000000000000000000000000000000000000000000000000000000000006b7