LibraryCredit and stable value2022Design paperCorpus record
Tokenized Vault Standard
ERC-4626. Joey Santoro, t11s, Jet Jadeja, Alberto Cuesta Cañada, Señor Doggo.
A tokenised vault has deposit, mint, withdraw and redeem, and a defined conversion between the asset and the share. The share is an ERC-20.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A protocol that accepts 'any yield token' should say whether it requires this interface, and what it does when convertToAssets moves suddenly.
The five-minute read
The defect
Every lending pool invented its own share token. Integrators guessed how to deposit and how shares convert.
The rule
A tokenised vault has deposit, mint, withdraw and redeem, and a defined conversion between the asset and the share. The share is an ERC-20.
How it is put together
Assets go in. Shares come out. The conversion functions are the interface. Yield is whatever increases assets per share. The standard does not promise yield.
Where the claim stops
The standard does not make a vault solvent.
One action, walked through
- Deposit assets, receive shares.
- Redeem shares, receive assets.
- An integrator reads convertToAssets rather than assuming a 1:1 peg.
- What does one share redeem for, and who computes it?
The argument, unpacked
Why it is still on the desk
A protocol that accepts 'any yield token' should say whether it requires this interface, and what it does when convertToAssets moves suddenly.
After the text
Yearn, Morpho vaults and many lending wrappers adopted it. The strategy behind the share is still a separate document.
What has to be true
- The standard does not make a vault solvent.
- It does not define the strategy.
- A malicious vault can implement the interface and still steal assets. The interface is not an audit.
What happened after the paper
Yearn, Morpho vaults and many lending wrappers adopted it. The strategy behind the share is still a separate document.
What to check before you use the idea
- What does one share redeem for, and who computes it?
- Can the conversion change inside a transaction?
- Is the strategy in the same contract as the share?
Terms
- Share
- The ERC-20 that represents a claim on the vault's assets.
- Asset
- The token the vault custodies.
The problem the paper names
Every lending pool invented its own share token. Integrators guessed how to deposit and how shares convert.
What the design proposes
- Assets go in. Shares come out.
- The conversion functions are the interface.
- Yield is whatever increases assets per share. The standard does not promise yield.
How the mechanism is specified
- Deposit assets, receive shares.
- Redeem shares, receive assets.
- An integrator reads convertToAssets rather than assuming a 1:1 peg.
What this page does not treat as proven
- The standard does not make a vault solvent.
- It does not define the strategy.
- A malicious vault can implement the interface and still steal assets. The interface is not an audit.
Why a venture studio still reads it
A protocol that accepts 'any yield token' should say whether it requires this interface, and what it does when convertToAssets moves suddenly.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
