medium SHARE_COUNT_MISREAD_RISK
QCOM: reading balanceOf() as shares understates by 0.1227% (multiplier 1.001228123x)
Who carries the exposure
Any integrator that presents QCOM balanceOf() as a share count. The contract itself is behaving as ERC-8056 specifies and is not at fault.
The contract named above is what was READ. Naming it is not an accusation against it: a Stock Token that moves uiMultiplier() is doing what ERC-8056 specifies.
QCOM reports uiMultiplier() = 1001228122794792830 (1.001228123), which is CORRECT AND SPEC-COMPLIANT behaviour under ERC-8056 — this finding is not a defect in the token contract. It records the exposure carried by a caller that reads balanceOf() as shares. Under ERC-8056 a corporate action moves the multiplier rather than balances, so balanceOf() returns tokens and share-equivalents = balance * uiMultiplier() / 1e18. A surface presenting the raw balance as a share count understates it by 0.1227% (the true count is 1.0012x the raw balance). Token value computed as balance * Chainlink feed price is unaffected, because the feed is already multiplier-adjusted.
Impact
0.1227%
totalSupply raw 462.4362 tokens vs 463.0041 share-equivalents (delta 0.5679). Presenting the raw balance as a share count understates by 0.1227%; equivalently the true count is 1.0012x the raw.
Evidence — 2/2 citations re-fetched and byte-compared
uiMultiplier() == 1001228122794792830
0x0000000000000000000000000000000000000000000000000de513ac4650977e
totalSupply() == 462436271470000000000
0x0000000000000000000000000000000000000000000000191197aacf4174cc00
Right of reply
No reply has been received for this finding. Anyone named here can have a response published verbatim and unedited alongside it. A finding shown to be wrong is corrected by changing the rule that produced it, with the notice recorded in the repository. Open a right-of-reply issue or see docs/RIGHT-OF-REPLY.md. Pre-publication notice is deliberately not claimed: the sweep publishes on a timer and for most findings the subject is a contract, not a person to notify.