Maya Protocol Pools Lose $11M Following Major Crypto Exploit

A series of six connected software bugs enabled an attacker to artificially add nearly 50 million CACAO to a MAYAChain liquidity pool without the reserves to support the tokens, allowing real crypto assets to be drained from the network.

Maya Protocol halted its MAYAChain network after the vulnerabilities created a false pool balance. The exploit resulted in nearly $1.7 million worth of bitcoin and other assets being extracted, while the wider market disruption pushed total pool losses to about $11 million.

Maya Protocol founder Aaluxx said the attacker took around 20 BTC, worth roughly $1.4 million, along with approximately $300,000 in additional assets. Trading was suspended to contain the incident as the team worked on a software fix and recovery plan.

MAYAChain is a cross-chain liquidity network within the Maya ecosystem that allows users to swap assets such as bitcoin and ether without using centralized exchanges. Its trades are supported by liquidity pools, while CACAO acts as the common asset linking different markets.

A technical review found that six bugs worked together to create the exploit. The attack began after MAYAChain mistakenly classified an outgoing transaction as missing and activated a recovery mechanism designed to reimburse a liquidity pool after a theft.

The mechanism miscalculated the compensation and attempted to add roughly 49 million CACAO to a small pool. At the time, the network held only around 168,000 CACAO in reserves, leaving it unable to fund the transfer.

Although the transfer failed, another vulnerability allowed the inflated balance to be written into the network’s records. The system also failed to undo the balance after the failed payment, leaving MAYAChain to treat the newly created tokens as genuine.

The attacker then deposited a small amount into the manipulated pool, giving them control of more than 99% of its liquidity. They withdrew 48.87 million CACAO and swapped the tokens for bitcoin, ether and other cryptocurrencies held in MAYAChain pools.

Onchain data showed that 20.83 BTC, worth about $1.34 million, was transferred to the attacker’s bitcoin address. Around $1.36 million in assets were moved onto external blockchains, while another 8.87 million CACAO remained in the attacker’s MAYAChain wallet.

CACAO subsequently suffered a severe price crash as the attacker sold the tokens. The token dropped from about $0.115 before the exploit to as low as $0.013, an almost 89% decline, before recovering to roughly $0.03.

The broader damage was amplified by traders taking advantage of the price collapse.

As CACAO became sharply undervalued, arbitrageurs bought the token and exchanged it for bitcoin, ether, stablecoins and other assets available in MAYAChain’s liquidity pools.

The investigation estimated that the attacker personally extracted approximately $1.65 million, including tokens still held on-chain. However, the total reduction in pool value was substantially higher because CACAO lost most of its value and arbitrage traders removed additional assets.

The analysis estimated that MAYAChain’s pools lost around $10.9 million in value during the incident. About $6.4 million of that decline was linked to CACAO’s falling price, while approximately $2.9 million resulted from arbitrage activity.

Maya Protocol said it is seeking to recover the stolen assets by offering the attacker a bug bounty. If the roughly 20 BTC is not returned, the team plans to replace the bitcoin through investments in Aztec Chain and other measures.

Repairing the vulnerabilities will not immediately make liquidity providers whole. Much of the CACAO generated during the exploit was exchanged through other MAYAChain pools, mixing it with assets supplied by legitimate users.