×

Crypto Exploit Strikes Maya Protocol, Wiping $11M From Pools

Crypto Exploit Strikes Maya Protocol, Wiping $11M From Pools

Six separate software vulnerabilities combined to create a fake balance of nearly 50 million CACAO in a MAYAChain liquidity pool, giving an attacker a path to convert the unauthorized tokens into genuine crypto assets.

Maya Protocol shut down MAYAChain after the exploit compromised one of its liquidity pools. The attacker extracted nearly $1.7 million in bitcoin and other cryptocurrencies, while the wider fallout erased about $11 million from the value of the network’s pools.

Maya Protocol founder Aaluxx said roughly 20 BTC, worth about $1.4 million, was stolen along with around $300,000 in other assets. The protocol suspended trading to contain the incident and said developers were working on repairs and fund recovery.

MAYAChain is part of the broader Maya ecosystem and provides cross-chain swaps for assets including bitcoin and ether without requiring users to rely on centralized exchanges. Transactions are supported by liquidity pools, with CACAO serving as the common token connecting the network’s markets.

According to a technical analysis, the exploit relied on six bugs operating in sequence. The initial problem occurred when MAYAChain mistakenly treated an outgoing transaction as missing and activated a mechanism intended to compensate a liquidity pool after a theft.

The compensation calculation was flawed, causing the system to credit almost 49 million CACAO to a small pool. MAYAChain’s reserves contained only about 168,000 CACAO, meaning the network had nowhere near enough funds to cover the supposed payment.

The transaction failed, but another vulnerability allowed the inflated balance to remain in the system. A separate flaw prevented the balance from being reversed, leaving the network to recognize the newly generated CACAO as legitimate pool assets.

The attacker exploited the distorted balance by making a small deposit and obtaining more than 99% ownership of the pool. They then withdrew 48.87 million CACAO and exchanged the tokens for bitcoin, ether and other cryptocurrencies held in MAYAChain pools.

Onchain data showed 20.83 BTC, valued at roughly $1.34 million, was transferred to the attacker’s bitcoin address. The investigation estimated that about $1.36 million in assets were moved to other blockchains, while 8.87 million CACAO remained in the attacker’s MAYAChain wallet.

CACAO’s price plunged as the attacker sold the tokens into the market. From roughly $0.115 before the exploit, the token dropped to about $0.013, representing a decline of nearly 89%, before rebounding toward $0.03.

The broader losses were amplified by arbitrage traders who moved in after the price collapse.

As CACAO became significantly cheaper, arbitrageurs purchased it and swapped the tokens for bitcoin, ether, stablecoins and other cryptocurrencies held in MAYAChain’s liquidity pools.

The attacker’s direct extraction was estimated at approximately $1.65 million, including tokens that remained on-chain. But the total damage to pool value was considerably larger because CACAO’s collapse and arbitrage activity drained additional value.

The analysis estimated that MAYAChain’s pools lost roughly $10.9 million during the incident. About $6.4 million of the decline came from CACAO’s falling market value, while approximately $2.9 million was attributed to arbitrage trades.

Maya Protocol said it is offering a bug bounty to encourage the attacker to return the stolen assets. If the roughly 20 BTC cannot be recovered, the team said it plans to replace the bitcoin through investments in Aztec Chain and other measures.

Eliminating the vulnerabilities will not be enough to fully replenish the affected pools. Much of the CACAO generated during the exploit was exchanged through other MAYAChain markets, mixing it with cryptocurrencies deposited by legitimate liquidity providers.

Share this content:

Copyright © 2025 CoinsNewz