How Did The MAYAChain Exploit Happen?
Maya Protocol halted trading on its MAYAChain network after a series of software bugs created a false balance in a liquidity pool, allowing an attacker to extract nearly $1.7 million while triggering losses of about $10.9 million across the network’s pools.
The attacker obtained roughly 20 BTC, worth about $1.4 million at the time, along with approximately $300,000 in other assets. Maya Protocol stopped swaps after detecting the exploit and said trading would remain suspended while developers prepared a fix.
MAYAChain allows users to exchange assets such as Bitcoin and Ether across blockchains without routing trades through a centralized exchange. Liquidity providers deposit crypto into pools, while the protocol’s CACAO token acts as the common asset connecting different markets.
A technical reconstruction identified six software bugs that had to interact for the exploit to succeed. The chain of failures started when MAYAChain incorrectly determined that an outgoing transaction had gone missing and activated a mechanism designed to compensate a liquidity pool following a failed transfer.
The compensation calculation then credited roughly 49 million CACAO to a small pool even though the protocol’s reserve contained only about 168,000 CACAO and could not fund the payment.
Why Did A Failed Payment Create Spendable Tokens?
The attempted transfer failed because the reserve did not contain enough CACAO. Under normal conditions, that should have prevented the pool from receiving the new balance.
Instead, another software bug meant the inflated balance had already been written into MAYAChain’s records before the payment failed. The network did not reverse the bookkeeping change and continued operating as though the additional CACAO actually existed.
The attacker then deposited a small amount of liquidity into the distorted pool and obtained ownership of more than 99% of it. The attacker withdrew 48.87 million CACAO and began exchanging the tokens for Bitcoin, Ether and other assets held elsewhere in MAYAChain’s liquidity pools.
Onchain activity showed 20.83 BTC worth about $1.34 million moving to the attacker’s Bitcoin address. Assets transferred onto external blockchains totaled roughly $1.36 million, while another 8.87 million CACAO remained in the attacker’s MAYAChain wallet.
The attack therefore involved more than a simple theft from one pool. The false CACAO balance created purchasing power inside the network that could be exchanged against real assets supplied by liquidity providers.
Investor Takeaway
The attacker extracted about $1.65 million, but MAYAChain’s pools lost far more. The difference matters because most of the roughly $10.9 million decline came from CACAO’s price collapse and arbitrage activity rather than assets directly stolen by the attacker.
Why Did MAYAChain Lose Nearly $11 Million?
CACAO fell sharply as the attacker sold the newly obtained tokens into MAYAChain’s markets. The token traded near $0.115 before the exploit and dropped as low as $0.013, a decline of almost 89%, before recovering to around $0.03.
The price collapse caused losses beyond the assets directly removed by the attacker. Arbitrage traders bought CACAO after it became unusually cheap and exchanged it for Bitcoin, Ether, stablecoins and other assets held inside MAYAChain pools.
The technical reconstruction estimated that the attacker personally extracted about $1.65 million, including tokens that remained on-chain. Total pool value, however, declined by approximately $10.9 million during the incident.
About $6.4 million of that decline was attributed to CACAO losing value, while another $2.9 million resulted from traders exploiting price differences created by the dislocation. Treating the entire $10.9 million as stolen funds would therefore overstate the amount taken by the attacker.
The distinction also complicates recovery. Returning the attacker’s proceeds would restore only part of the economic damage because other assets have already moved through arbitrage trades and the value of CACAO itself has fallen sharply.
Can Maya Protocol Restore The Liquidity Pools?
Maya Protocol said it hopes the attacker will return the funds in exchange for a bug bounty. Founder AaluxxMyth said the team would work to “fix and recover in full” as developers investigate the failures and prepare the network to resume trading.
The team has also discussed replacing roughly 20 BTC through investments in Aztec Chain and other sources if the attacker does not return the assets.
Fixing the code, however, will not automatically restore liquidity providers to their pre-exploit balances. Much of the CACAO created through the faulty accounting was exchanged for other assets and is now intertwined with funds belonging to ordinary users.
The recovery process will therefore require more than patching the six software failures. Maya Protocol must determine how to rebuild depleted pools, account for losses caused by arbitrage and decide how liquidity providers will be compensated before normal trading can safely resume.
