Maya Protocol Exploit Triggers $1.7M Asset Drain; Pool Value Slides About $11M as CACAO Crashes
AI Market Summary
Maya Protocol halted MAYAChain after multiple bugs created a false pool balance, enabling an attacker to drain ~20.83 BTC plus other assets (~$1.7M) and triggering an estimated ~$10.9M decline in pool value. CACAO's sharp collapse and subsequent arbitrage amplified liquidity-provider losses beyond the direct theft. The incident highlights crosschain AMM smart-contract and accounting risks, likely tightening risk appetite for smaller DeFi venues short term.
Impact level
● Medium
Affected assets
BTC/USDT+0.35%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Cross-chain liquidity protocol Maya Protocol has paused its MAYAChain network after a cluster of software bugs created an artificial balance in a liquidity pool, enabling an attacker to siphon off nearly $1.7 million in bitcoin and other assets and setting off broader losses across the system.
Founder @AaluxxMyth said on X that the exploit involved 20 BTC worth about $1.4 million, plus roughly $300,000 in additional assets. The team halted trading to contain the incident and said swaps will remain offline until a fix is deployed.
MAYAChain is a smaller cross-chain swapping network within the Maya ecosystem. It allows users to exchange assets such as bitcoin and ether directly against onchain liquidity pools, using the CACAO token as the common intermediary.
A technical reconstruction of the incident found six separate bugs that, in combination, produced the exploit. The sequence began when MAYAChain incorrectly flagged an outgoing transaction as missing and activated code intended to compensate a liquidity pool after a theft. That safety routine miscalculated the reimbursement, crediting about 49 million CACAO to a small pool even though MAYAChain's reserve held only around 168,000 CACAO and could not fund the amount.
The attempted transfer failed, but another flaw meant the inflated balance was already written into the network's records. The system did not revert the state change after the payment failure and continued operating as if the pool truly contained the extra tokens.
With the pool now distorted, the attacker deposited a minimal amount and ended up controlling more than 99% of it. They then withdrew 48.87 million CACAO and swapped those tokens for bitcoin, ether and other assets held in MAYAChain liquidity pools. Onchain data shows 20.83 BTC, worth about $1.34 million, was transferred to the attacker's bitcoin address. The analysis estimated about $1.36 million in assets moved to external chains, while another 8.87 million CACAO remained in the attacker's MAYAChain wallet.
CACAO plunged as the attacker sold into the market. The token traded near $0.115 before the exploit, fell to as low as $0.013 (down nearly 89%), and later recovered to around $0.03.
The price collapse amplified losses beyond the attacker's direct take. As CACAO dumped, arbitrage traders bought the discounted token and exchanged it for bitcoin, ether, stablecoins and other assets from MAYAChain pools. The reconstruction estimated the attacker's extraction at about $1.65 million, including tokens still held onchain, while the much larger pool drawdown reflected arbitrage activity and CACAO's devaluation.
In total, the analysis estimated pool value fell by roughly $10.9 million during the event. About $6.4 million of that decline was attributed to CACAO's price drop, and another $2.9 million was linked to arbitrage flows. The report emphasized that the headline reduction in pool value should not be treated as the amount stolen.
MAYAChain said it hopes the attacker will return the funds in exchange for a bug bounty. The team added it would seek to replace the roughly 20 BTC through investments in Aztec Chain and other avenues if the funds are not returned. Even with a software fix, restoring the pools remains complex because much of the CACAO minted via the exploit was swapped into other MAYAChain markets and is now intermingled with liquidity providers' funds.