Loading prices…
🩸BEARISH

Maya Protocol exploit wipes $11M; attacker holds 20.8 BTC

Maya has committed to replacing the ~20 BTC stolen. That covers a fraction of the $11M in pool damage, with the bulk sitting in CACAO repricing and arbitrage losses no one has publicly agreed to…

Maya Protocol's Aug. 18 exploit has metastasized from a ~$1.36M direct theft into roughly $11M of pool damage, with the suspected attacker still holding 20.8273 BTC untouched and no public restoration plan accounting for the spread. Founder Aaluxx initially framed the loss as ~20 BTC plus ~$300K in other assets, a figure Maya now says it could replace through Aztec Chain investments and a hoped-for bug-bounty return. But a CryptoSlate reconstruction pegs the bulk of the damage at ~$6.4M in CACAO repricing and ~$2.9M in post-dislocation arbitrage after the token collapsed 88.7% from $0.115 to $0.013.

Why it matters

A SigIntZero technical post-mortem attributes the drain to six accounting and state-handling flaws chained inside one 23-message transaction. Overwritten outbound state produced a false missing-transfer signal, activating a compensation path that credited ~49.45M CACAO to a thin ARB.LINK pool even though Maya's reserve held only ~168,000 CACAO. The reserve transfer failed but the inflated balance persisted, letting the attacker absorb ~99.93% of the pool's ownership units and walk out with ~48.87M CACAO. The $11M figure is a function of one exploit being executed against a structurally thin pool, where a single oracle dislocation cascades into repricing across every CACAO-denominated book on MAYAChain.

Market impact

Even if the 20.83 BTC is returned or replaced, Maya has not publicly defined who absorbs the CACAO repricing hit or the ~$2.9M arbitrage gap. On-chain data shows 11 confirmed transactions funding the address and zero spending as of Aug. 21, with the balance worth roughly $1.59M at current BTC prices. CACAO's 88.7% drop in hours is the kind of single-venue dislocation that ripples through cross-chain DEXs: liquidity providers in CACAO pools on connected chains face mark-to-market losses without a defined backstop, and the protocol's governance credibility takes a hit whether or not the BTC is ultimately recovered.

Related tokens
$BTC

Frequently asked questions

  1. How much did the Maya Protocol exploit actually cost?

    The direct theft is estimated at $1.36M in assets moved to external chains plus ~$291K still on MAYAChain, but the broader pool damage reaches roughly $11M once CACAO repricing and post-dislocation arbitrage are included.

  2. Why did CACAO's price drop 88.7% during the exploit?

    The attacker withdrew ~48.87M CACAO after capturing ~99.93% of a thin ARB.LINK pool's ownership units, then swapped into assets held by other MAYAChain pools. The sell pressure against CACAO-denominated books drove the token from ~$0.115 to ~$0.013 in hours.

  3. Can Maya Protocol recover the lost funds?

    Maya has signaled it may replace the ~20 BTC through Aztec Chain investments and is hoping for a bug-bounty return, but has not published a plan to restore the ~$6.4M in CACAO repricing losses or the ~$2.9M arbitrage hit. The 20.83 BTC held by the attacker is still untouched on-chain.

  4. What technical flaw enabled the Maya Protocol exploit?

    A SigIntZero reconstruction attributes the drain to six accounting and state-handling flaws chained inside one 23-message transaction. Overwritten outbound state produced a false missing-transfer signal that credited ~49.45M CACAO to a pool whose reserve held only ~168,000 CACAO.

  5. What is the exposure for liquidity providers on connected chains?

    CACAO pool LPs on cross-chain DEXs connected to MAYAChain face mark-to-market losses from the token's 88.7% decline without a defined backstop. Maya has not publicly committed to covering the repricing gap, leaving LP exposure open-ended.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 57m ago
Open original →