medium SHARE_COUNT_MISREAD_RISK
SCHD: reading balanceOf() as shares understates by 0.5508% (multiplier 1.005538607x)
Who carries the exposure
Any integrator that presents SCHD balanceOf() as a share count. The contract itself is behaving as ERC-8056 specifies and is not at fault.
The contract named above is what was READ. Naming it is not an accusation against it: a Stock Token that moves uiMultiplier() is doing what ERC-8056 specifies.
SCHD reports uiMultiplier() = 1005538606893683992 (1.005538607), which is CORRECT AND SPEC-COMPLIANT behaviour under ERC-8056 — this finding is not a defect in the token contract. It records the exposure carried by a caller that reads balanceOf() as shares. Under ERC-8056 a corporate action moves the multiplier rather than balances, so balanceOf() returns tokens and share-equivalents = balance * uiMultiplier() / 1e18. A surface presenting the raw balance as a share count understates it by 0.5508% (the true count is 1.0055x the raw balance). Token value computed as balance * Chainlink feed price is unaffected, because the feed is already multiplier-adjusted.
Impact
0.5508%
totalSupply raw 234.4221 tokens vs 235.7205 share-equivalents (delta 1.2984). Presenting the raw balance as a share count understates by 0.5508%; equivalently the true count is 1.0055x the raw.
Evidence — 2/2 citations re-fetched and byte-compared
uiMultiplier() == 1005538606893683992
0x0000000000000000000000000000000000000000000000000df464090fd6d518
totalSupply() == 234422137930000000000
0x00000000000000000000000000000000000000000000000cb542bc6cf5466400
Right of reply
No reply has been received for this finding. Anyone named here can have a response published verbatim and unedited alongside it. A finding shown to be wrong is corrected by changing the rule that produced it, with the notice recorded in the repository. Open a right-of-reply issue or see docs/RIGHT-OF-REPLY.md. Pre-publication notice is deliberately not claimed: the sweep publishes on a timer and for most findings the subject is a contract, not a person to notify.