Maya Protocol Loses $1.7M in Six-Bug Chained Exploit
Security & Exploits ·
An attacker manipulated pool accounting to seize 99.93% ownership of Maya Protocol pools before draining CACAO and LINK.
Maya Protocol was exploited for $1.7M after an attacker chained together six separate bugs to manipulate the protocol's pool accounting, according to a report cited on x.com. The manipulation allowed the attacker to accumulate 99.93% ownership of the affected pools, effectively giving them control over the bulk of deposited liquidity.
With near-total pool ownership secured, the attacker drained holdings of CACAO and LINK, the two assets named in the disclosed breakdown of stolen funds. The exploit's six-bug structure indicates the attack was not a single-point failure but a sequence of vulnerabilities strung together to reach the final accounting manipulation.
A separate account of the incident corroborates the $1.7M figure and adds that the stolen funds were subsequently bridged to Bitcoin, suggesting the attacker moved quickly to convert the drained assets out of their original form. Two distinct sources have now reported on the exploit, both converging on the same dollar figure while describing overlapping but not identical details of the attack chain.
The mechanics of a six-bug chained exploit typically mean that no single patch would have prevented the loss; each vulnerability on its own may have been contained, but their combination let the attacker escalate from a minor foothold to majority control of pool shares. That level of ownership — 99.93% — effectively let the attacker treat the pool's assets as their own for the purposes of withdrawal.
What remains unclear from the available reporting is the specific identity of the six bugs, whether Maya Protocol has paused affected pools or issued a post-mortem, and whether any portion of the $1.7M has been recovered or frozen following the bridge to Bitcoin. It is also not yet established whether the exploited code path affected only the CACAO and LINK pools or extended to other assets on the protocol.