All vaults / Upshift

Spec mismatch

earnAUSD (share symbol sAUSD)

UpshiftAsset AUSD0xD793c04B87386A6bb84ee61D98e0065FdE7fdA5EMonad mainnet

2 of 30 properties failed at block 111,224,893. The vault's behavior contradicts an EIP-4626 MUST sentence.

Asynchronous withdrawals: exits go through requestRedeemrequestRedeem(uint256,address,address) in the code at 0xFd2F793C248Dd673C830DF610a95a045054de267; in this check deposits worked while every withdraw and redeem reverted.

Known to the watcher from a backfill scan in block 109,195,820, 2026-09-30 08:08 UTC.

What failed

  • sf-maxWithdraw-honoredEIP-4626 MUST

    maxWithdraw was 609,877,786,697, but withdraw(609,877,786,695) reverted with 0x75ed2e3e, WithdrawalRequestRequired().

    EIP-4626: maxWithdraw MUST return the maximum amount of assets withdraw accepts without reverting, and 0 while withdrawals are disabled.

    For an asynchronous vault, ERC-7540 still requires maxWithdraw and maxRedeem to report what can be claimed now.

    Counterexample: test_sf_maxWithdraw_honored(204021641170440950934057, 170272127362186878622977996674609877786698, 115792089237316195423570985008687907853269984665640564039457584007913129639933)

  • sf-maxRedeem-honoredEIP-4626 MUST

    maxRedeem was 606,678,772,778, but redeem(606,678,772,776) reverted with 0x75ed2e3e, WithdrawalRequestRequired().

    EIP-4626: maxRedeem MUST return the maximum amount of shares redeem accepts without reverting, and 0 while redemptions are disabled.

    For an asynchronous vault, ERC-7540 still requires maxWithdraw and maxRedeem to report what can be claimed now.

    Counterexample: test_sf_maxRedeem_honored(204021641170440950934057, 170272127362186878622977996674609877786698, 115792089237316195423570985008687907853269984665640564039457584007913129639933)

A spec mismatch is a disagreement with an EIP-4626 MUST sentence, shown by a concrete call. It is not a claim that funds are at risk.

What the watcher saw

Every event the watcher recorded for this vault, newest first. Each check is a statement about one block; a re-check with the same outcome is recorded here without a new attestation.

  1. Checked
    Spec mismatch

    16 pass, 2 fail, 12 inconclusive, 0 not applicable at block 111,224,893, 5 min. Report

    Why: backfill scan.

  2. Checked
    Spec mismatch

    16 pass, 2 fail, 12 inconclusive, 0 not applicable at block 111,213,199, 4 min. Report

    Why: scheduled re-check.

  3. Queued

    Waiting for a check: scheduled re-check.

JSON: this vault's history

All 30 properties

In report order. Bit i is the bit the registry's passedBitmap and failedBitmap use for that property.

BitPropertyResultWhat was found
a16z/erc4626-tests at ac48546, 26 properties: 16 on EIP-4626 MUST sentences, 10 on SHOULD guidance (the round trips and the allowance checks)
0assettest_assetEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: asset() does not revert

1totalAssetstest_totalAssetsEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: totalAssets() does not revert

2convertToSharestest_convertToSharesEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: convertToShares gives the same result for any caller

3convertToAssetstest_convertToAssetsEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: convertToAssets gives the same result for any caller

4maxDeposittest_maxDepositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxDeposit does not revert

5previewDeposittest_previewDepositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit mints at least the shares previewDeposit quoted

6deposittest_depositEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit moves assets from the caller, credits shares to the receiver and spends allowance

7maxMinttest_maxMintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxMint does not revert

8previewMinttest_previewMintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint pulls at most the assets previewMint quoted

9minttest_mintEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint moves assets from the caller, credits shares to the receiver and spends allowance

10maxWithdrawtest_maxWithdrawEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxWithdraw does not revert

11previewWithdrawtest_previewWithdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw burns at most the shares previewWithdraw quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
12withdrawtest_withdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 291 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 291 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
13withdraw-zero-allowancetest_withdraw_zero_allowanceEIP-4626 SHOULDPass

No counterexample in 16 fuzz runs at this block.

Checks: withdraw on behalf of an owner without allowance reverts

14maxRedeemtest_maxRedeemEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: maxRedeem does not revert

15previewRedeemtest_previewRedeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem pays at least the assets previewRedeem quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
16redeemtest_redeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 291 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 291 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
17redeem-zero-allowancetest_redeem_zero_allowanceEIP-4626 SHOULDPass

No counterexample in 16 fuzz runs at this block.

Checks: redeem on behalf of an owner without allowance reverts

18RT-deposit-redeemtest_RT_deposit_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem(deposit(a)) returns no more than a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
19RT-deposit-withdrawtest_RT_deposit_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw(a) burns at least the shares deposit(a) minted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
20RT-redeem-deposittest_RT_redeem_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit(redeem(s)) mints no more than s

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
21RT-redeem-minttest_RT_redeem_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint(s) costs at least the assets redeem(s) paid

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
22RT-mint-withdrawtest_RT_mint_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw(mint(s)) burns at least s shares

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
23RT-mint-redeemtest_RT_mint_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem(s) pays no more than mint(s) cost

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
24RT-withdraw-minttest_RT_withdraw_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint(withdraw(a)) costs at least a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
25RT-withdraw-deposittest_RT_withdraw_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 325 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit(a) mints no more than the shares withdraw(a) burned

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 325 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
Specfirst max-honored properties, MIT, each on one EIP-4626 MUST sentence about a max function
26sf-maxDeposit-honoredtest_sf_maxDeposit_honoredEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: deposit goes through up to min(maxDeposit, 1e6 tokens); when a smaller amount is refused the bound must go through, and refusals are counted (EIP-4626: maxDeposit MUST NOT be higher than what deposit accepts)

27sf-maxMint-honoredtest_sf_maxMint_honoredEIP-4626 MUSTPass

No counterexample in 16 fuzz runs at this block.

Checks: mint goes through up to min(maxMint, shares of 1e6 tokens); when a smaller amount is refused the bound must go through, and refusals are counted (EIP-4626: maxMint MUST NOT be higher than what mint accepts)

28sf-maxWithdraw-honoredtest_sf_maxWithdraw_honoredEIP-4626 MUSTFail

maxWithdraw was 609,877,786,697, but withdraw(609,877,786,695) reverted with 0x75ed2e3e, WithdrawalRequestRequired(). EIP-4626: maxWithdraw MUST return the maximum amount of assets withdraw accepts without reverting, and 0 while withdrawals are disabled.

For an asynchronous vault, ERC-7540 still requires maxWithdraw and maxRedeem to report what can be claimed now.

Checks: withdraw goes through up to maxWithdraw; when a smaller amount is refused maxWithdraw must go through, and refusals are counted (EIP-4626: maxWithdraw MUST NOT be higher than what withdraw accepts, and MUST be 0 when withdrawals are disabled)

Raw result
reason: withdraw(609877786695) reverted with selector 0x75ed2e3e while maxWithdraw is 609877786697
runs: 0
call: test_sf_maxWithdraw_honored(204021641170440950934057, 170272127362186878622977996674609877786698, 115792089237316195423570985008687907853269984665640564039457584007913129639933)
calldata: 0x72b950e2000000000000000000000000000000000000000000002b34090b5b8898106a29000000000000000000000000000001f46282e0cd79769bb5d41b6d1ee9cea04afffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffd
29sf-maxRedeem-honoredtest_sf_maxRedeem_honoredEIP-4626 MUSTFail

maxRedeem was 606,678,772,778, but redeem(606,678,772,776) reverted with 0x75ed2e3e, WithdrawalRequestRequired(). EIP-4626: maxRedeem MUST return the maximum amount of shares redeem accepts without reverting, and 0 while redemptions are disabled.

For an asynchronous vault, ERC-7540 still requires maxWithdraw and maxRedeem to report what can be claimed now.

Checks: redeem goes through up to maxRedeem; when a smaller amount is refused maxRedeem must go through, and refusals are counted (EIP-4626: maxRedeem MUST NOT be higher than what redeem accepts, and MUST be 0 when redemptions are disabled)

Raw result
reason: redeem(606678772776) reverted with selector 0x75ed2e3e while maxRedeem is 606678772778
runs: 0
call: test_sf_maxRedeem_honored(204021641170440950934057, 170272127362186878622977996674609877786698, 115792089237316195423570985008687907853269984665640564039457584007913129639933)
calldata: 0x942509aa000000000000000000000000000000000000000000002b34090b5b8898106a29000000000000000000000000000001f46282e0cd79769bb5d41b6d1ee9cea04afffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffd