All vaults / Euler EVK (eVault)

Spec mismatch

EVK Vault eeUSD-4

Euler EVK (eVault)Asset eUSD0xf26dC2F1FE883b11Dd56700db594DfC32Eee95BfMonad mainnet

2 of 30 properties failed at block 111,461,783. The vault's behavior contradicts an EIP-4626 MUST sentence.

Known to the watcher from a backfill scan in block 109,195,820, 2026-09-30 08:20 UTC.

What failed

  • sf-maxDeposit-honoredEIP-4626 MUST

    maxDeposit was 5,192,296,858,534,827,628,530,496,329,220,095, but deposit(6,281,844,442,681,804,148) reverted with 0xea8e4eb5, NotAuthorized().

    EIP-4626: maxDeposit MUST return the maximum amount of assets deposit accepts without reverting.

    Counterexample: test_sf_maxDeposit_honored(11297107174309809211892377277870259943554067261449759553286370912298578415, 6281844442681804148)

  • sf-maxMint-honoredEIP-4626 MUST

    maxMint was 5,192,296,858,534,827,628,530,496,329,220,095, but mint(6,281,844,442,681,804,148) reverted with 0xea8e4eb5, NotAuthorized().

    EIP-4626: maxMint MUST return the maximum amount of shares mint accepts without reverting.

    Counterexample: test_sf_maxMint_honored(11297107174309809211892377277870259943554067261449759553286370912298578415, 6281844442681804148)

A spec mismatch is a disagreement with an EIP-4626 MUST sentence, shown by a concrete call. It is not a claim that funds are at risk.

What the watcher saw

Every event the watcher recorded for this vault, newest first. Each check is a statement about one block; a re-check with the same outcome is recorded here without a new attestation.

  1. Checked
    Spec mismatch

    0 pass, 2 fail, 28 inconclusive, 0 not applicable at block 111,461,783, 1 min. Report

    Why: scheduled re-check.

  2. Queued

    Waiting for a check: scheduled re-check.

JSON: this vault's history

All 30 properties

In report order. Bit i is the bit the registry's passedBitmap and failedBitmap use for that property.

BitPropertyResultWhat was found
a16z/erc4626-tests at ac48546, 26 properties: 16 on EIP-4626 MUST sentences, 10 on SHOULD guidance (the round trips and the allowance checks)
0assettest_assetEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: asset() does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
1totalAssetstest_totalAssetsEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: totalAssets() does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
2convertToSharestest_convertToSharesEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: convertToShares gives the same result for any caller

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
3convertToAssetstest_convertToAssetsEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: convertToAssets gives the same result for any caller

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
4maxDeposittest_maxDepositEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: maxDeposit does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
5previewDeposittest_previewDepositEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit mints at least the shares previewDeposit quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
6deposittest_depositEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 3995 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit moves assets from the caller, credits shares to the receiver and spends allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 3995 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
7maxMinttest_maxMintEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: maxMint does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
8previewMinttest_previewMintEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint pulls at most the assets previewMint quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
9minttest_mintEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 3995 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint moves assets from the caller, credits shares to the receiver and spends allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 3995 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
10maxWithdrawtest_maxWithdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: maxWithdraw does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
11previewWithdrawtest_previewWithdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw burns at most the shares previewWithdraw quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
12withdrawtest_withdrawEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 3995 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 3995 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
13withdraw-zero-allowancetest_withdraw_zero_allowanceEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw on behalf of an owner without allowance reverts

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
14maxRedeemtest_maxRedeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4009 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: maxRedeem does not revert

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4009 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
15previewRedeemtest_previewRedeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem pays at least the assets previewRedeem quoted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
16redeemtest_redeemEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 3995 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem burns owner shares, pays the receiver and spends share allowance

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 3995 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
17redeem-zero-allowancetest_redeem_zero_allowanceEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem on behalf of an owner without allowance reverts

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
18RT-deposit-redeemtest_RT_deposit_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem(deposit(a)) returns no more than a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
19RT-deposit-withdrawtest_RT_deposit_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw(a) burns at least the shares deposit(a) minted

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
20RT-redeem-deposittest_RT_redeem_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit(redeem(s)) mints no more than s

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
21RT-redeem-minttest_RT_redeem_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint(s) costs at least the assets redeem(s) paid

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
22RT-mint-withdrawtest_RT_mint_withdrawEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: withdraw(mint(s)) burns at least s shares

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
23RT-mint-redeemtest_RT_mint_redeemEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: redeem(s) pays no more than mint(s) cost

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
24RT-withdraw-minttest_RT_withdraw_mintEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: mint(withdraw(a)) costs at least a

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
25RT-withdraw-deposittest_RT_withdraw_depositEIP-4626 SHOULDInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs. Along the way deposit reverted 4008 times at amounts up to maxDeposit; some of these may be tiny amounts that round to zero shares, which many vaults reject. Those inputs were discarded, as upstream does, so this stays inconclusive; whether deposit honors maxDeposit is judged by sf-maxDeposit-honored.

Checks: deposit(a) mints no more than the shares withdraw(a) burned

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed); deposit reverted below maxDeposit 4008 times (inputs discarded, EIP-4626 says it must not revert)
runs: 0
Specfirst max-honored properties, MIT, each on one EIP-4626 MUST sentence about a max function
26sf-maxDeposit-honoredtest_sf_maxDeposit_honoredEIP-4626 MUSTFail

maxDeposit was 5,192,296,858,534,827,628,530,496,329,220,095, but deposit(6,281,844,442,681,804,148) reverted with 0xea8e4eb5, NotAuthorized(). EIP-4626: maxDeposit MUST return the maximum amount of assets deposit accepts without reverting.

Checks: deposit goes through up to min(maxDeposit, 1e6 tokens); when a smaller amount is refused the bound must go through, and refusals are counted (EIP-4626: maxDeposit MUST NOT be higher than what deposit accepts)

Raw result
reason: deposit(6281844442681804148) reverted with selector 0xea8e4eb5 while maxDeposit is 5192296858534827628530496329220095
runs: 0
call: test_sf_maxDeposit_honored(11297107174309809211892377277870259943554067261449759553286370912298578415, 6281844442681804148)
calldata: 0x600eccd7000664d8fe81387729cab93dc5f857bb9ba6f0a6d07d10d3b98a1ed221f3b1ef000000000000000000000000000000000000000000000000572d983cec4f8574
27sf-maxMint-honoredtest_sf_maxMint_honoredEIP-4626 MUSTFail

maxMint was 5,192,296,858,534,827,628,530,496,329,220,095, but mint(6,281,844,442,681,804,148) reverted with 0xea8e4eb5, NotAuthorized(). EIP-4626: maxMint MUST return the maximum amount of shares mint accepts without reverting.

Checks: mint goes through up to min(maxMint, shares of 1e6 tokens); when a smaller amount is refused the bound must go through, and refusals are counted (EIP-4626: maxMint MUST NOT be higher than what mint accepts)

Raw result
reason: mint(6281844442681804148) reverted with selector 0xea8e4eb5 while maxMint is 5192296858534827628530496329220095
runs: 0
call: test_sf_maxMint_honored(11297107174309809211892377277870259943554067261449759553286370912298578415, 6281844442681804148)
calldata: 0xb1f65c3b000664d8fe81387729cab93dc5f857bb9ba6f0a6d07d10d3b98a1ed221f3b1ef000000000000000000000000000000000000000000000000572d983cec4f8574
28sf-maxWithdraw-honoredtest_sf_maxWithdraw_honoredEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: withdraw goes through up to maxWithdraw; when a smaller amount is refused maxWithdraw must go through, and refusals are counted (EIP-4626: maxWithdraw MUST NOT be higher than what withdraw accepts, and MUST be 0 when withdrawals are disabled)

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0
29sf-maxRedeem-honoredtest_sf_maxRedeem_honoredEIP-4626 MUSTInconclusive

Never exercised: the vault rejected nearly every amount the fuzzer tried, and forge gave up after 4096 discarded inputs.

Checks: redeem goes through up to maxRedeem; when a smaller amount is refused maxRedeem must go through, and refusals are counted (EIP-4626: maxRedeem MUST NOT be higher than what redeem accepts, and MUST be 0 when redemptions are disabled)

Raw result
reason: `vm.assume` rejected too many inputs (4096 allowed)
runs: 0