Maple Finance
DAMASCUSInstitutional Lending · Ethereum + Solana · $500M+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
82
75
85
78
78
72
50
82
75
100
82
75
85
78
78
72
50
82
75
100
Audit History
Bug Bounty Program
Assessment
Institutional lending protocol that survived $50M bad debt from Celsius/Alameda. V2 rebuild addressed structural issues but historical event permanently impacts D6/D7. Undercollateralized lending inherently carries credit risk (D2).
Dimension Breakdown
How scores work →- Pool delegates manage individual lending pools
- Governor admin controls global parameters
- Withdrawal manager controls redemption flow
- Loan manager handles loan lifecycle
- Institutional undercollateralized lending (inherent credit risk)
- Pool delegate due diligence is off-chain trust model
- Celsius/Alameda bad debt exposed credit risk model
- V2 improvements: better withdrawal mechanics, loan terms
- Internal accounting for loan terms and interest
- No external price oracle dependency for core lending
- Pool share pricing based on NAV calculation
- Interest rate model is pool-delegate configured
- Live since May 2021 (60 months)
- $50M+ bad debt from Celsius/Alameda collapse (2022)
- V2 rebuild addressed structural weaknesses
- Surviving and operational post-crisis
- Z-factor: 0.903
- MPL token governance for protocol parameters
- Pool delegate selection process
- Governor multisig for emergency actions
- Limited on-chain governance history
- No validated adversarial findings — score set to neutral baseline
- Improved operations post-crisis
- Pool delegate monitoring and reporting
- Institutional-grade compliance framework
- Operational failure contributed to bad debt event
- Stablecoin dependency (USDC primarily)
- Integration with institutional borrowers (off-chain trust)
- Withdrawal manager creates pool composition complexity
- Limited DeFi composability by design
- Member of 1 dependency cluster(s)
- No cross-protocol cascade exposure detected
- Score: 100/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Standard Solidity with OpenZeppelin base
- Verified contracts on Ethereum
- Professional build pipeline
- Moderate dependency complexity
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "maple"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("maple")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.