Cross-chain liquidity protocol Maya Protocol halted trading on its MAYAChain network after an attacker chained six software bugs into a single drain that stole about $1.7 million in bitcoin and other assets. Founder @AaluxxMyth said the attack extracted roughly 20 BTC ($1.34M) plus another $300,000 in ether and other tokens, while on-chain records show the attacker still held 8.87 million $CACAO in their wallet after the dust settled. The halt came in time to stop further loss, but the token collapse and arbitrage cascade had already ripped roughly $10.9 million out of Maya's pool value.
Why it matters
The exploit is a textbook case of how narrow bugs compound into protocol-wide failure. The chain started when MAYAChain mistook an outgoing transaction for missing, triggered theft-compensation code meant for liquidity pools, calculated the payout incorrectly, and credited roughly 49 million $CACAO to a small pool that only held about 168,000 CACAO in reserve. The transfer failed, but a second bug saved the inflated balance to state, a third kept the network operating as if it were real, and the attacker walked in with a dust deposit to capture 99% of the distorted pool and walk out with 48.87 million $CACAO. Each bug on its own looks defensible. The combination was lethal, and Maya's offer of a bug bounty in exchange for the returned funds underlines how few options a halted DEX has once its accounting state is poisoned.
Market impact
The wider damage dwarfed the direct theft. $CACAO traded around $0.115 before the exploit, fell as low as $0.013 (a drop of nearly 89%) and recovered only to about $0.03 after the chain halt. Roughly $6.4 million of the $10.9 million pool decline came from CACAO itself becoming less valuable, another $2.9 million from arbitrageurs buying the crater and pulling out BTC, ETH and stablecoins, and only about $1.65 million was the attacker's direct extraction. The Maya team is working on a software fix and says it will replace the 20 BTC through investments in Aztec Chain and other means if the funds are not returned.
Frequently asked questions
-
What happened in the Maya Protocol exploit?
Six software bugs chained together. MAYAChain mistook an outgoing transaction for missing, fired theft-compensation code that credited a 168,000-CACAO reserve pool with 49 million unbacked tokens, and saved the fake balance anyway. The attacker deposited dust, captured 99% of the pool, and walked out with 48.87M CACAO…
-
How much was actually stolen versus how much did the pools lose?
The attacker personally extracted roughly $1.65M, about $1.34M of it in 20.83 BTC and ~$300K in other tokens. Total pool value fell ~$10.9M, but only $1.65M was the direct theft. About $6.4M came from $CACAO becoming less valuable and $2.9M from arbitrageurs buying the cheap token and pulling out other assets.
-
Did CACAO recover after the exploit?
$CACAO traded around $0.115 before the exploit and fell as low as $0.013, an 89% drop. After Maya halted trading, the token partially recovered to around $0.03, still down roughly 74% from pre-exploit levels.
-
Will liquidity providers get their funds back?
Maya offered the attacker a bug bounty in exchange for returning the funds, and said it would replace the 20 BTC through investments in Aztec Chain and other means if the attacker does not cooperate. Restoring pool balances is the harder problem because the fraudulent CACAO was already swapped into other markets and…
-
Is Maya Protocol still halted?
Yes. Maya halted all swaps on MAYAChain to contain the damage and said it is working on a software fix before trading resumes. Rebuilding the pools will require more than a patch, since the inflated balance state has to be reconciled against legitimate liquidity providers.
CoinDesk