Web3/Blockchain

uint256 Arithmetic Checker

Check Solidity integer arithmetic for overflow, division truncation and precision loss, with exact big-integer results and the operation order that preserves the most accuracy.

Last reviewed by the Radiatus Cloud team

Results appear here.

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Overflow reverts since 0.8.0, and that is not always what you want

Before Solidity 0.8 an arithmetic overflow wrapped silently, which produced enormous wrong balances from small mistakes. Since 0.8 the compiler inserts checks and the transaction reverts instead, which converts a silent corruption into a visible failure. That is a large improvement and it is not free: a revert in a loop over many users can make a function permanently uncallable because of one bad entry, and an unchecked block is sometimes correct rather than a shortcut. Knowing which behaviour applies is the point.

Integer division truncates, and the truncation is always downward

There are no fractions in the EVM. Every division discards the remainder, and it discards it in the same direction every time, so the error is systematic rather than random and it accumulates. A fee calculated as amount divided by 100 loses up to 99 wei on every call, always in the same direction, which over many calls is a real quantity that belongs to somebody. Deciding who receives the remainder is a design decision, and not deciding it means the contract keeps it by accident.

Multiplying before dividing preserves precision but risks overflow

The expression a times b divided by c gives a different answer from a divided by c times b, because the second truncates before multiplying and loses the fraction entirely. Multiplying first is almost always correct and it moves the intermediate value closer to the overflow ceiling, which is why libraries provide a mulDiv that computes the full 512-bit intermediate. For most realistic values the ceiling is far away and the precision loss is not, so multiply first.

Related tools

Frequently Asked Questions

Does Solidity still overflow silently?

Not since 0.8.0, which inserts checks and reverts. Earlier versions wrapped silently, and an unchecked block reinstates the old behaviour deliberately.

Which way does integer division round?

Always downward, discarding the remainder. The error is systematic rather than random, so it accumulates in one direction over many operations.

Should I multiply or divide first?

Multiply first. Dividing first truncates before the multiplication and loses the fraction entirely, which is almost always the larger error. Multiplying first risks overflow, which for realistic values is usually much further away.

What is the largest uint256?

About 1.16 times 10 to the 77, or 2 to the 256 minus 1. With 18 decimals that is around 10 to the 59 whole tokens, so overflow is rarely a practical concern for balances.

Where does the truncated remainder go?

Wherever the contract leaves it, which is usually itself by accident. Deciding deliberately who receives the rounding remainder is part of getting the rounding direction right.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter an expression and the integer width to check it.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.