Maya Protocol halted its MAYAChain network after an attacker chained six software flaws together to drain about $1.7 million in bitcoin and other assets. The exploit also triggered a CACAO selloff and arbitrage activity that dragged the total decline in Maya's liquidity pools to an estimated $10.9 million. The team says it hopes the attacker returns the funds for a bug bounty and will otherwise replace the stolen bitcoin.
Maya Protocol halted MAYAChain, its cross-chain trading network, after an attacker exploited six linked software flaws to steal an estimated $1.7 million in bitcoin and other assets. Founder Aalux said on X that the attacker took 20 BTC, worth about $1.4 million, plus roughly $300,000 of other assets, before the protocol activated a global halt to stop further losses.
Six bugs opened the door
A preliminary technical reconstruction found the attack depended on six flaws working together rather than a single vulnerability. MAYAChain first mistakenly flagged an outgoing transaction as stolen and triggered code meant to compensate a liquidity pool for the loss, but that mechanism miscalculated the payout and added roughly 49 million CACAO to a small pool even though MAYAChain's reserve held only about 168,000 CACAO. The transfer failed, but the inflated balance had already been saved, so the network kept treating the pool as if it held the extra tokens.
The attacker then deposited a small amount into the distorted pool, ended up owning more than 99% of it, and withdrew 48.87 million CACAO tokens from Maya's Asgard module using a single cross-chain transaction containing 23 messages. From there, the attacker swapped the tokens for bitcoin, ether and other assets sitting in MAYAChain's pools.
CACAO collapses as the attacker sells
CACAO traded around $0.115 before the exploit and fell as low as $0.013, a drop of nearly 89%, before recovering to around $0.03. As the token plunged, arbitrage traders bought the cheap CACAO and swapped it for bitcoin, ether, stablecoins and other assets in Maya's pools, deepening the damage beyond what the attacker took directly.
The reconstruction estimated the attacker personally extracted about $1.65 million, while roughly $6.4 million of the $10.9 million pool decline came from CACAO's devaluation and another $2.9 million from arbitrage. Separately, about $1.36 million in assets moved to external blockchains, while another $291,000 remained under the attacker's control.
Maya weighs a bug bounty and BTC replacement
According to Aalux's post on X: "Will work to fix and recover in full. We carry on." MAYAChain said it hopes the attacker will return the funds in exchange for a bug bounty and, if not, will work to replace the roughly 20 BTC through investments in Aztec Chain and other means. Repairing the software will not by itself restore the pools, since much of the CACAO created through the exploit is now mixed with tokens belonging to ordinary liquidity providers.
Sources: CoinDesk, crypto.news
Trading involves risk.