
Maple Syrup audit
A private security review of Maple Finance Syrup (permissionless lending), conducted with Three Sigma and completed on 23rd August 2024 over 5 days. 0xSimao disclosed 5 findings: 1 low and 4 informational.
What Syrup is
Syrup, built by Maple Labs, opens Maple's institutional lending yield to permissionless deposits: USDC deposited through the Syrup platform mints syrupUSDC, an ERC-4626 share over pools lending to vetted institutional borrowers, with the same fixed-term and open-term loan machinery underneath.
Scope
The Three Sigma engagement covered the migration and user-action layer around the launch: the MPL-to-SYRUP token Migrator, SyrupDrip for token distributions, and SyrupUserActions/MPLUserActions, which bundle deposit, migration, staking and Balancer-routed swap steps into single transactions, alongside touched paths in the fixed- and open-term loan contracts.
Low severity findings
Informational findings
- Extra spaces found in some instances of the codebase
- Duplicated slippage check in SyrupUserActions
- Duplicated _permit() function
- Immutable variables are emitted in events
The report