Maya Protocol's Aug. 18 exploit has metastasized from a ~$1.36M direct theft into roughly $11M of pool damage, with the suspected attacker still holding 20.8273 BTC untouched and no public restoration plan accounting for the spread. Founder Aaluxx initially framed the loss as ~20 BTC plus ~$300K in other assets, a figure Maya now says it could replace through Aztec Chain investments and a hoped-for bug-bounty return. But a CryptoSlate reconstruction pegs the bulk of the damage at ~$6.4M in CACAO repricing and ~$2.9M in post-dislocation arbitrage after the token collapsed 88.7% from $0.115 to $0.013.
Why it matters
A SigIntZero technical post-mortem attributes the drain to six accounting and state-handling flaws chained inside one 23-message transaction. Overwritten outbound state produced a false missing-transfer signal, activating a compensation path that credited ~49.45M CACAO to a thin ARB.LINK pool even though Maya's reserve held only ~168,000 CACAO. The reserve transfer failed but the inflated balance persisted, letting the attacker absorb ~99.93% of the pool's ownership units and walk out with ~48.87M CACAO. The $11M figure is a function of one exploit being executed against a structurally thin pool, where a single oracle dislocation cascades into repricing across every CACAO-denominated book on MAYAChain.
Market impact
Even if the 20.83 BTC is returned or replaced, Maya has not publicly defined who absorbs the CACAO repricing hit or the ~$2.9M arbitrage gap. On-chain data shows 11 confirmed transactions funding the address and zero spending as of Aug. 21, with the balance worth roughly $1.59M at current BTC prices. CACAO's 88.7% drop in hours is the kind of single-venue dislocation that ripples through cross-chain DEXs: liquidity providers in CACAO pools on connected chains face mark-to-market losses without a defined backstop, and the protocol's governance credibility takes a hit whether or not the BTC is ultimately recovered.
Frequently asked questions
-
How much did the Maya Protocol exploit actually cost?
The direct theft is estimated at $1.36M in assets moved to external chains plus ~$291K still on MAYAChain, but the broader pool damage reaches roughly $11M once CACAO repricing and post-dislocation arbitrage are included.
-
Why did CACAO's price drop 88.7% during the exploit?
The attacker withdrew ~48.87M CACAO after capturing ~99.93% of a thin ARB.LINK pool's ownership units, then swapped into assets held by other MAYAChain pools. The sell pressure against CACAO-denominated books drove the token from ~$0.115 to ~$0.013 in hours.
-
Can Maya Protocol recover the lost funds?
Maya has signaled it may replace the ~20 BTC through Aztec Chain investments and is hoping for a bug-bounty return, but has not published a plan to restore the ~$6.4M in CACAO repricing losses or the ~$2.9M arbitrage hit. The 20.83 BTC held by the attacker is still untouched on-chain.
-
What technical flaw enabled the Maya Protocol exploit?
A SigIntZero reconstruction attributes the drain to six accounting and state-handling flaws chained inside one 23-message transaction. Overwritten outbound state produced a false missing-transfer signal that credited ~49.45M CACAO to a pool whose reserve held only ~168,000 CACAO.
-
What is the exposure for liquidity providers on connected chains?
CACAO pool LPs on cross-chain DEXs connected to MAYAChain face mark-to-market losses from the token's 88.7% decline without a defined backstop. Maya has not publicly committed to covering the repricing gap, leaving LP exposure open-ended.
CryptoSlate