(1/7) Update from Maple
Maple has no active DeFi positions. We assessed risk exposure across DeFi and proactively removed all allocations. Through active risk management, Lenders have no exposure to rsETH or other indirect exposures, and the Maple platform operated as expected.
NEW MEMBER: @0xfarhaan
Leading the Smart Contracts team @maplefinance defining Onchain Asset Management. Designing and securing code holding over 4 Billion USD in value.
Off-duty: BBQs, F1, Macro Larp-ing
Announcing the Solidity Testing Handbook ✨
Fully free, one-stop resource for Solidity developers and security researchers.
Resources are currently scattered across blogs, docs, and forums. I found it difficult to keep track of everything in one place.
This handbook aggregates all testing patterns from basic unit tests to advanced mutation tests into a single, well-organized guide for quick reference.
It’s built from my own learnings and best practices observed in popular codebases.
https://t.co/02LS4uLFUM
"Vibe coded contract gets hacked" sounds good for a headline
but as @moo9000 points out, the issue is easy for both humans and AI to miss without digging deeper
reminds me of the infamous Nomad PR that introduced the bug that got the bridge hacked
the PR lived at a higher level of abstraction, which makes the issue hard to catch in human or AI review (unless you’re explicitly hunting for it). it also lacked key integration context, just like the Nomad PR
this is a process failure, not an AI/human failure: missing checks like forked integration tests that query all oracles and verify on-chain state
designing the security process—deciding which checks and defenses each change or upgrade needs—is still a human job
AI is just a tool, and like human-written code it needs review in critical systems
use AI, but don’t assume it won’t make mistakes. build defenses that catch both human and AI error
Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. https://t.co/op5zufgAGH
Expect this one to be good, top project payout means multiple audits and reviews and still had a critical
What are the implications? most projects need guard rails and design in a way to expect bugs to be present
current design is not fault tolerant on this space
My main takeaway from the recent rounding hacks is that every incorrect rounding needs to be considered a bug
Most of them are not exploitable, or not even vulnerabilities, but they are still bugs
Think of it as: bug → vulnerability → exploit. Every exploit starts from a vulnerability, and every vulnerability starts from a bug. Exploitability of rounding is often tricky because it depends on the system’s conditions, which will evolve
The relation between bugs and exploitability is more common in web2, but we don’t see it as often in web3
The nuance means that:
- If you develop a protocol, you need to be explicit about every rounding decision (cover all bugs)
- If you do a code review, you need to flag every incorrect rounding that can have a security impact (cover all vulnerabilities)
- If you do a bug bounty or contest, you need to focus on exploitable rounding (cover all exploits)
For code reviews: flagging every rounding doesn’t mean creating 100 issues; you can create one issue listing similar risks. But you do need to raise awareness of the risks
For bug bounties/contests: I wouldn’t be surprised to see future exploits that combine multiple rounding or other vulnerabilities (as we often see in web2). It’s something to keep in mind
Another revenue ATH: $2.159M in October and counting.
Maple has achieved its year-end revenue and AUM targets with two months to spare and we're not slowing down.
Pending governance approval, two @maplefinance assets (syrupUSDT and syrupUSDC) will soon be onboarded to Aave.
This introduces new institutional-grade collateral, backed by a consistent and trusted yield, to borrowers.
The next era of DeFi starts today.
@Aave and Maple are establishing a strategic partnership that brings institutional assets to the largest onchain lending market.
On October 10th, crypto saw over $19B in liquidations.
Maple recorded zero losses, zero liquidations, and uninterrupted performance across all products.
Awesome work by the whole team, super proud of the smart contracts we’ve build here at Maple from both old and new contributors a major milestone having a contract hold more then $1B in value 🎉
Maple surpasses $9 billion in loans originated.
The largest onchain asset manager continues to scale institutional lending with overcollateralized loans to accredited crypto-native firms.
Market-leading capital efficiency and institutional-grade security, on Maple.
The plan has always been to bring institutional quality products and yield to the DeFi ecosystem.
The integration experience just got a major upgrade enabling protocols, chains and anyone else to directly plug into and build on top of @maplefinance and $syrupUSD - this is onchain asset management.