Maya Protocol exploited via six software vulnerabilities, resulting in $1.4M Bitcoin theft and network halt.
Security & Exploits ·
Maya Protocol halted MAYAChain after attackers leveraged six software bugs to drain approximately $1.7 million in Bitcoin and other assets from the cross-chain liquidity network. The exploit involved a transaction designed to artificially inflate a liquidity pool's CACAO balance by roughly 49.45 million tokens, granting the attacker control of over 99% of that pool and enabling withdrawal of 48.87 million CACAO. As stolen tokens were converted to Bitcoin and other cryptocurrencies, CACAO's value fell sharply—nearly 89%—which constrained the total amount extracted. The team identified the attacker's Bitcoin address receiving approximately 20.83 BTC worth $1.4 million, with additional assets valued at roughly $300,000 also taken.
The vulnerabilities remained undetected for three to four years despite prior security audits, according to Maya Protocol's post-mortem analysis. The attack exploited uncapped subsidy mechanisms and false detection systems built into the pool's mechanics. Network founder AaluxxMyth announced the team would fix the flaws before resuming operations and committed to a more rigorous code review process going forward, noting the need to examine "extremely simple code primitives" more adversarially.
The team offered a bug bounty in hopes of recovering the stolen funds but stated it would pursue alternative recovery methods—including investments in Aztec Chain—if the assets remained unreturned. No determination has been made regarding whether artificial intelligence was involved in crafting the exploit.