Maya Protocol suspended its cross-chain liquidity operations after an attacker exploited a series of software vulnerabilities, draining approximately $1.7 million in Bitcoin and other assets from its ecosystem. The network halted swaps to prevent further losses and investigate the breach.
Details of the Exploit
Maya Protocol, which operates MAYAChain, uncovered the security incident on Tuesday. The team identified six distinct bugs that enabled the creation of a false balance in one of its liquidity pools. This vulnerability allowed the attacker to inflate the pool’s holdings by nearly 49.5 million CACAO tokens and gain almost total control before withdrawing 48.87 million CACAO.
In a detailed post-mortem, the development team explained that the exploit involved a single transaction containing 23 specific deposit messages. This triggered a faulty theft detection mechanism, manipulated an uncapped slash subsidy, and allowed the attacker to both supply and remove assets from the compromised pool, extracting significant value.
The incident caused a sharp decline in CACAO’s price. The token lost nearly 89% of its value as liquidity pools were drained by around $10.9 million. Due to the severity of the exploit, total losses reached an estimated $1.65 million in major cryptocurrencies, including $1.36 million swiftly moved across blockchains and $291,000 left on-chain.
Team Response and Investigation
AaluxxMyth, widely known as Maya and a founder of the protocol, addressed the situation on X, stating the team acted quickly to limit further exploitation. “No way to sugar coat this. We have likely been exploited by 20 BTC ($1.4M) and other assets ($300k),” Maya posted, acknowledging the seriousness of the breach.
The post-mortem detailed that the attacker deployed a single transaction to create a false “theft” detection, then took advantage of a low-liquidity pool’s vulnerability. This process resulted in massive asset extraction and nearly complete control of the affected pool.
Despite previous audits by Halborn and Fable 5, Maya stated that the vulnerabilities had remained undetected for three to four years. The team committed to adopting even more adversarial review practices, emphasizing the ongoing challenge of securing decentralized networks.
Maya Protocol published the suspected attacker’s Bitcoin address, which received 20.83 BTC valued at roughly $1.34 million. The team indicated it is open to recovering the assets through a bug bounty if the funds are returned. Otherwise, Maya plans to recover the lost assets by investing in Aztec Chain and other channels, aiming to restore the affected pool.
The team credited the Maya community for their support and resilience, expressing gratitude and signaling an intent to rebuild and improve the protocol’s security standards after the incident.
Wider Impact and Industry Context
The exploit follows several notable decentralized finance attacks. In April, attackers obtained about $292 million from KelpDAO’s cross-chain bridge by compromising a developer’s session keys. Other incidents include Ostium losing $18 million on Arbitrum due to a manipulated price feed and AFX Trade experiencing a $24 million exploit through its USDC bridge.
The recent sequence of high-profile exploits underscores the ongoing risks facing cross-chain liquidity protocols and highlights the importance of continuous monitoring and robust technical safeguards. With sudden network decisions or altcoin listings often moving the market in seconds, traders are increasingly seeking efficient solutions. Many now adopt privacy-focused platforms such as CryptoAppsy, which streamline charts, news, and portfolio data into a single interface—offering real-time information and smart price alerts without requiring user accounts.





USDT
AAPL
