# \[Direct to AIP\] Onboard syrupUSDT to Aave V3 Plasma Instance

**URL:** <https://governance.aave.com/t/direct-to-aip-onboard-syrupusdt-to-aave-v3-plasma-instance/23204>\
**Category:** Governance\
**Created:** [October 3, 2025, 9:34pm UTC](https://governance.aave.com/t/direct-to-aip-onboard-syrupusdt-to-aave-v3-plasma-instance/23204 "2025-10-03T21:34:22Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![bgdlabs](https://dub1.discourse-cdn.com/flex013/user_avatar/governance.aave.com/bgdlabs/32/1829_2.png) [@bgdlabs](https://governance.aave.com/u/bgdlabs)\
**Post date:** [October 16, 2025, 10:33am UTC](https://governance.aave.com/t/direct-to-aip-onboard-syrupusdt-to-aave-v3-plasma-instance/23204/5 "2025-10-16T10:33:52Z")

</div>

# syrupUSDT (cross-chain) technical analysis

## Summary

Following the new proposal for listing SyrupUSDT on Plasma, we examined the Maple Team’s implementation of the cross-chain asset.

This is a technical analysis of all the smart contracts of the SyrupUSDT on Plasma and main bridge dependencies.

_Disclosure:_ This is not an exhaustive security review of the asset like the ones done by the Maple team, but an analysis from an Aave technical service provider on different aspects we consider critical to review before a new type of listing.

  

## Analysis

SyrupUSDT in Ethereum follows the same architecture and is controlled by the same entities as SyrupUSDC, for which we did an extensive evaluation that can be found [here](https://governance.aave.com/t/arfc-onboard-syrupusdc-to-aave-v3-core-instance/22456/8). It’s a cross-chain asset on Plasma bridged through Chainlink’s CCIP infrastructure.

 ![syrupusdt-scheme](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/7/728693c92512d06d1ac1d7c5e75c78e33a1b932d.png)

  

## General points

- The SyrupUSDT contract uses the standard Chainlink’s CCIP contracts for lock/release on Ethereum and mint/burn Plasma.

- It relies on two non-upgradable contracts controlled by the [Maple’s timelock](https://plasmascan.to/address/0x2eFFf88747EB5a3FF00d4d8d0f0800E306C0426b) and Chainlink’s [RBACTimelock](https://plasmascan.to/address/0x3eC62564F66874f619640cBb7Fd42A157f21A442) **.**

- For access control, it uses OZ role-based.

  

## Contracts

The following is a non-exhaustive overview of the main smart contracts involved with SyrupUSDT on Plasma:

 ![syrupusdt-contracts](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/9/96ad924843685360ae75f465dfb172846df10529.png)

  

## [SyrupUSDT](https://plasmascan.to/address/0xC4374775489CB9C56003BF2C9b12495fC64F0771)

It represents the cross-chain SyrupUSDT token, which extends standard functionality for minting and burning capabilities through role-based access control.

| **Permission Owner** | **functions** | **Criticality** | **Risk** |
| --- | --- | --- | --- |
| `ADMIN_ROLE`: [3-day Timelock](https://plasmascan.to/address/0x2eFFf88747EB5a3FF00d4d8d0f0800E306C0426b) | setCCIPAdmin, grantRole | **HIGH** | 🟢 |
| `MINTER_ROLE`: [TokenPool](https://plasmascan.to/address/0x1d952d2f6ee86ef4940fa648aa7477c8ff175f09) | mint | **HIGH** | 🟢 |
| `BURNER_ROLE`: [TokenPool](https://plasmascan.to/address/0x1d952d2f6ee86ef4940fa648aa7477c8ff175f09) | burn, burnFrom | **HIGH** | 🟢 |

  

- **Access Control**

- **Minting and Burning**

  

## [TokenPool](https://plasmascan.to/address/0x1d952d2f6eE86Ef4940Fa648aA7477c8fF175F09)

The TokenPool contract manages cross-chain token operations via CCIP’s router contract, facilitating the minting and burning of SyrupUSDT. It handles token decimals across different chains, rate limiting, and uses a role-based access control.

  

**Plasma: [TokenPool](https://plasmascan.to/address/0x1d952d2f6eE86Ef4940Fa648aA7477c8fF175F09)**

| **Permission Owner** | **functions** | **Criticality** | **Risk** |
| --- | --- | --- | --- |
| **owner: [RBACTimelock](https://plasmascan.to/address/0x3eC62564F66874f619640cBb7Fd42A157f21A442)** | setRouter, addRemotePool, removeRemotePool, applyChainUpdates, setRateLimitAdmin, applyAllowListUpdates | **HIGH** | 🟢 |

  

**Mainnet: [TokenPool](https://etherscan.io/address/0xDE76A096C5eadDdf97Af3fE15ee49d32AEDa9822#readContract)**

| **Permission Owner** | **functions** | **Criticality** | **Risk** |
| --- | --- | --- | --- |
| **owner: [RBACTimelock](https://etherscan.io/address/0x44835bBBA9D40DEDa9b64858095EcFB2693c9449#code)** | setRouter, addRemotePool, removeRemotePool, applyChainUpdates, setRateLimitAdmin, applyAllowListUpdates, transferLiquidity | **HIGH** | 🟢 |

  

- **Access Control**
  - The [**RBACTimelock**](https://plasmascan.to/address/0x3eC62564F66874f619640cBb7Fd42A157f21A442) can configure the cross-chain between new chains through the `addRemotePool()`, `removeRemotePool()`, and `applyChainUpdates()` functions. It can also configure the allowlist via the `applyAllowListUpdates()` and set a rate limiter contract by calling the `setRateLimitAdmin()` method.

  - The liquidity locked in a previous TokenPool can be migrated to the new (current) TokenPool via the `transferLiquidity(amount)` function.

- **Bridging**
  - For cross-chain SyrupUSDT from Mainnet to Plasma, the call is initiated through the `router.ccipSend(destChain, message)` function. The SyrupUSDT is locked in the TokenPool contract and then forwarded via the `evmOnRap.forwardFromRouter(destChain, message)` method.

  - To send it back to the mainnet, it uses the same process via the router by calling the `ccipSend(destChain, message)` function. The token amount is burned on Plasma by the TokenPool, and the message is forwarded to the mainnet via the `offRamp. executeSingleMessage(msg)`, where the TokenPool contract receives a `releaseOrMint(releaseOrMintIn)` call and transfers the SyrupUSDT to the user.

  

## Pricing strategy

We recommend pricing SyrupUSDT with a CAPO Adapter using the SyrupUSDT/USDT exchange rate along with the Capped USDT/USD Price feed. This method aligns with the price recommendation for syrupUSDC on mainnet.

  

## Miscellaneous

- The security reviews of the CCIP contracts’ infrastructure used in SyrupUSDT can be found [here](https://github.com/Cyfrin/2024-07-CL-CCIP).

- During the review process, we suggested to the Maple team to timelock the admins of SyrupUSDT. They implemented it shortly afterward, keeping the system consistent with the mainnet.

  

## Conclusion

We believe SyrupUSDT has no issues with Aave integration and no major blockers for listing.

---

_[View the full topic](https://governance.aave.com/t/direct-to-aip-onboard-syrupusdt-to-aave-v3-plasma-instance/23204)._
