Key facts
- Maya Protocol halted its network due to a crypto exploit.
- An attacker stole an estimated $1.7 million in Bitcoin and other assets.
- The exploit involved six chained software bugs, including issues with trade accounts and liquidity pool calculations.
- The CACAO token experienced an 88.7% price drop following the incident.
- Maya Protocol has implemented a network halt and is working on a fix.
Maya Protocol, a cross-chain decentralized exchange, has halted its network after an attacker exploited a series of software vulnerabilities to steal an estimated $1.7 million in cryptocurrency. The incident involved approximately 20 Bitcoin, valued at $1.4 million, and an additional $300,000 in other assets.
Aalux, a pseudonymous co-founder of Maya Protocol, stated that the network was halted to contain further damage and that a fix is being developed to resume operations. The exploit was reportedly enabled by six chained bugs affecting trade accounts, outbound transaction handling, and liquidity pool calculations. The attacker allegedly used a single transaction with 23 messages to trigger a false theft detection, inflate a low-liquidity pool, and withdraw 48.87 million CACAO tokens from Maya's Asgard module.
According to the analysis, approximately $1.36 million was transferred to external blockchains, while the attacker retained about $291,000 in CACAO and trade-account positions on MAYAChain. Blockchain security researcher Vini Barbosa noted that the CACAO token's price plummeted by 88.7% during the event, falling from around $0.115 to $0.013. While the analysis estimated a broader $10.9 million decline in pool value, this figure included arbitrage activity and CACAO's devaluation, not solely assets stolen by the attacker.