Maya Protocol Halts Operations After Multi-Bug Exploit Drains CACAO Tokens and Cross-Chain Assets

Maya Protocol, a decentralized cross-chain liquidity network that facilitates native swaps of assets such as Bitcoin and Ethereum without centralized intermediaries or wrapped tokens, experienced a major security breach in mid-August 2026.

An attacker combined multiple software vulnerabilities to manipulate the protocol’s internal accounting, withdraw a substantial volume of the native CACAO token, and extract real assets from shared liquidity pools.

The attack relied on a single intricate transaction that packaged 23 messages.

This transaction activated a sequence of six distinct flaws related to trade-account handling, outbound transaction processing, and liquidity-pool mathematics.

It began when the system incorrectly classified legitimate outgoing transfers as missing or stolen.

This false alert engaged a compensation mechanism (sometimes called a slash subsidy) that was intended to protect liquidity providers.

Because the subsidy calculation lacked proper upper limits and interacted poorly with other code paths, the protocol recorded an artificial credit of roughly 49.45 million CACAO tokens to a thinly capitalized pool—specifically the Arbitrum Chainlink (ARB.LINK) pool—even though those tokens did not exist in the reserves.

The protocol’s reserve contained only about 168,000 CACAO, so the attempted funding transfer failed.

A critical bookkeeping error left the inflated balance permanently recorded.

The attacker then deposited a minimal quantity of liquidity into the distorted pool, obtaining more than 99 percent ownership.

They immediately withdrew approximately 48.87 million CACAO from the Asgard vault module, which holds assets used to settle cross-chain swaps.

Armed with the large CACAO position, the attacker swapped the tokens for Bitcoin, Ether, and other assets residing in Maya’s pools.

On-chain evidence shows that roughly 20.83 BTC (valued at approximately $1.34–1.4 million at the time) was sent to an external Bitcoin address under the attacker’s control.

Total direct proceeds for the exploiter are estimated between $1.65 million and $1.7 million, encompassing both assets moved to external blockchains and residual holdings that remained inside the Maya ecosystem.Secondary market effects were considerably larger.

CACAO’s price plunged nearly 89 percent, dropping from around $0.115 to a low near $0.013 before partially recovering toward $0.03.

Combined with subsequent arbitrage that further drained pools, the overall decline in the value of Maya’s liquidity pools reached an estimated $10.9–11 million—far exceeding the amount directly extracted by the attacker.

In response, the Maya Protocol team, led by pseudonymous co-founder AaluxxMyth, publicly confirmed the incident and promptly enacted a network-wide halt on MAYAChain to stop further losses.

The team has committed to identifying and patching the underlying defects, exploring recovery avenues (including a potential white-hat bounty), and working to restore liquidity.

Discussions have also referenced using proceeds from related ecosystem projects to help replenish affected pools if necessary.

The episode highlights the risks inherent in complex cross-chain systems, where the interaction of several relatively narrow code issues can produce outsized damage.

As developers continue remediation and prepare to resume operations, the incident underscores the necessity of more aggressive adversarial testing and stronger isolation between state-update, compensation, and liquidity-calculation modules in decentralized finance infrastructure.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend