An attacker drained roughly $1.36 million in hard assets from cross-chain liquidity network MAYAChain, led by about 20.83 BTC moved to external chains. The damage inside MAYAChain's liquidity pools, however, ran closer to $11 million, with the network's CACAO token collapsing 88.7%, from about $0.115 to $0.013, during the incident. Independent researcher Vini Barbosa traced most of the activity to a single MsgDeposit transaction carrying 23 messages, in which the final DONATE overwrote earlier ObservedTxVoter state, made legitimate outbound transfers register as missing, and triggered a false theft-detection subsidy that the protocol could not actually fund.
Why it matters
The exploit turned an accounting entry the reserve could never fund into a withdrawable liquidity position. With the outbound height misclassified, the subsidy path meant to compensate a pool after a real theft kicked in for legitimate transfers, calculating roughly 49.45 million CACAO of value for a near-empty ARB pool, even though the reserve held only about 168,000 CACAO. The on-chain transfer failed, but the inflated balance survived in pool records, and the attacker captured about 99.93% of the distorted pool's ownership units by adding negligible liquidity. The $1.36M figure tracks what left the network; the $11M figure captures the cascade inside. Maya Protocol has yet to publish a confirmed patch, swap restart, or compensation framework.
Market impact
CACAO fell 88.7% during the incident, the bridge between the two loss numbers. The token represents one side of MAYAChain's paired liquidity pools, so a sharp decline in its dollar price reduces the measured value of CACAO inventory across the system, even when those tokens remain inside a pool. Trades executed against distorted pool prices and the exploit-created balance added another layer of impact. Founder Aaluxx said on Aug. 18 the team would fix the incident and "recover in full." As of the Aug. 20 reporting cutoff, Maya's official channels had not yet published a confirmed swap restart, deployed patch version, asset-recovery total, final loss allocation, or compensation scope for liquidity providers.
Frequently asked questions
-
How much did the MAYAChain attacker actually take off-network?
About $1.36 million, led by roughly 20.83 BTC moved to external chains. The $11M figure tracks the network-wide pool impact, not what the attacker carried out.
-
What made the CACAO balance withdrawable in the first place?
Researcher Vini Barbosa traced the exploit to a 23-message MsgDeposit transaction whose final DONATE overwrote the outbound height used to match transactions. That activated theft-detection logic that calculated ~49.45M CACAO in subsidy value for a near-empty ARB pool.
-
How did an $1.36M extraction turn into $11M of pool damage?
CACAO is one side of every paired liquidity pool on MAYAChain, and the token collapsed 88.7%, from about $0.115 to $0.013. The price collapse cascades through the network's measured pool value, which is what drove the $11M estimate.
-
What does Maya Protocol still need to publish to make "recover in full" concrete?
As of the Aug. 20 reporting cutoff, Maya had not published a confirmed swap restart, deployed patch version, asset-recovery total, final loss allocation, or compensation scope for liquidity providers.
-
Does the same exploit path affect THORChain?
MAYANode's Trade Accounts drew from THORChain merge requests, which establishes shared development lineage. But public documentation as of press time did not demonstrate that THORChain carries the same exploit path.
CryptoSlate