Maya Protocol exploited via six-vulnerability chain draining ~$11M in Bitcoin and other assets, forcing operational halt.
Security & Exploits ·
Maya Protocol ceased operations after an attacker exploited a chain of six vulnerabilities to drain approximately $11 million from the platform. The exploit allowed the attacker to credit a liquidity pool with nearly 50 million improperly-funded tokens, resulting in the removal of roughly $1.4 million in Bitcoin alongside other assets. The incident highlights the persistent smart-contract risks embedded in cross-chain trading systems, where multiple flaws can combine to bypass security controls and extract substantial value from user deposits.
The mechanics of the attack centered on the attacker's ability to manipulate token crediting across the protocol's pools. By chaining together six separate vulnerabilities, the attacker was able to inflate the pool's apparent value and withdraw real assets—particularly Bitcoin—while the protocol remained unaware of the fraudulent nature of the credited tokens. This cascading failure pattern is characteristic of exploits targeting systems where individual safeguards, though present, are not designed to contain attacks that exploit their interaction.
What remains unclear is whether the protocol team has identified the root cause of each flaw and what timeline exists for recovery or remediation. No public post-mortem or remediation plan has been announced to date. The halting of operations protects remaining liquidity but leaves questions about user compensation and the viability of the protocol's resumption.