
MAYAChain halts network after estimated $1.7M exploit
A preliminary analysis says six chained bugs let a 23-message transaction drain 48.87 million CACAO, sending the token down nearly 89%.

[Update 09:25 UTC, Aug. 19: Adds details on the exploit mechanics and its impact on MAYAChain’s liquidity pools.
Update 06:57 UTC, Aug. 20: Adds comments from Maya Protocol co-founder Aalux.]
Cross-chain decentralized exchange (DEX) Maya Protocol halted its network after an attacker exploited a series of software flaws to obtain an estimated $1.7 million in crypto.
On Wednesday, Maya Protocol’s pseudonymous co-founder Aalux said the attacker stole about 20 Bitcoin worth $1.4 million and another $300,000 in assets. They said the halt prevented further damage and the team had started working on a fix to resume swaps.
A preliminary technical analysis shared by Aalux attributed the incident to six chained bugs involving trade accounts, outbound transaction handling and liquidity pool calculations.
While the analysis put the attacker’s haul at about $1.7 million, it estimated that MAYAChain’s pools lost about $10.9 million in value, including losses from arbitrage and CACAO’s collapse.
Aalux told Cointelegraph that the team had contacted the attacker through a message embedded in a Bitcoin OP_RETURN transaction. He said they would personally donate $200,000 and work to raise additional funds, with the aim of recovering as much of the losses as possible and potentially compensating affected users in full.
How the MAYAChain exploit unfolded
Maya Protocol is a cross-chain network built from THORChain’s open-source code and designed to complement it. CACAO is MAYAChain’s gas and settlement token and is paired with supported assets in its liquidity pools.
According to the analysis, the transaction overwrote records tracking outbound transfers, causing transfers to be classified as missing. This activated a theft-protection mechanism, which miscalculated compensation for Maya’s low-liquidity Arbitrum Chainlink (ARB.LINK) pool and incorrectly credited it with 49.45 million CACAO.
Related: BitBox patches ‘severe’ wallet flaws that could put funds at risk
The transfer intended to fund that credit failed because Maya’s reserve held insufficient CACAO, but the inflated pool balance remained. The attacker then added negligible liquidity, acquired 99.93% of the pool and withdrew 48.87 million CACAO from Asgard, which holds protocol assets.
Independent blockchain security researcher Vini Barbosa summarized the findings and noted that CACAO fell by 88.7%, from approximately $0.115 to $0.013 during the incident.
Aalux said the team would seek the return of the stolen funds through a bug bounty and work to restore liquidity.
Magazine: ‘Fabricated rumors’ about BitMart founder, Binance bStocks dominate: Asia Express



