
Maple Syrup Router audit
A private security review of Maple Finance Syrup Router (permissionless lending), conducted with Three Sigma and completed on 21st May 2024 over 2 days. 0xSimao disclosed 5 findings: 2 low and 3 informational.
What Syrup is
Syrup, built by Maple Labs, opens secured institutional lending to permissionless depositors for the first time: USDC in, syrupUSDC out, with the yield sourced from fully collateralised loans to the largest institutions in crypto.
Scope
A two-day Three Sigma review of the deposit path: the SyrupRouter contract and the SyrupRateProvider that reports the syrupUSDC exchange rate.
Low severity findings
- Attacker may frontrun SyrupRouter::depositWithPermit() call and use a different depositData_ as it is not signed
- SyrupRouter::depositWithPermit() may be DoSed by frontrunning ERC20::permit()
Informational findings
- Signatures in the SyrupRouter are not fully compatible with EIP712
- Hardcoded 1e18 in SyrupRateProvider
- owner in SyrupRouter also requires transfer permission
The report