A series of six interconnected software flaws allowed MAYAChain to create an artificial balance of nearly 50 million tokens in a liquidity pool that did not have enough reserves to back them, ultimately enabling an attacker to withdraw real crypto assets.
Cross-chain liquidity platform Maya Protocol suspended its MAYAChain network after the bugs generated a fake balance in one of its pools. The exploit enabled the attacker to drain nearly $1.7 million worth of bitcoin and other cryptocurrencies, while the resulting market disruption reduced the network’s total pool value by roughly $11 million.
Maya Protocol founder Aaluxx said on X that the attacker took about 20 BTC, valued at roughly $1.4 million, along with approximately $300,000 in other assets. The protocol halted trading to limit further losses and said its team was working on a fix and recovery plan before resuming swaps.
MAYAChain is a smaller cross-chain trading network within the wider Maya ecosystem. It allows users to exchange assets such as bitcoin and ether directly rather than routing trades through centralized exchanges. Users trade against liquidity pools funded with cryptocurrencies, while CACAO serves as the network’s common settlement asset.
A technical analysis of the incident found that six separate bugs combined to make the exploit possible. The sequence started when MAYAChain incorrectly determined that an outgoing transaction had failed to arrive and activated a recovery mechanism designed to compensate a liquidity pool following a theft.
However, the compensation mechanism calculated the amount incorrectly. It attempted to credit approximately 49 million CACAO to a relatively small pool, even though MAYAChain had only around 168,000 CACAO in reserves and lacked the funds needed to cover the transfer.
Although the transfer itself failed, another software flaw allowed the inflated balance to be recorded in the network’s state. Because the system failed to roll back the balance after the unsuccessful payment, MAYAChain continued treating the pool as if the newly created tokens were legitimate.
The attacker then deposited a small amount of CACAO into the manipulated pool, gaining control of more than 99% of its liquidity. They subsequently withdrew 48.87 million CACAO and exchanged the tokens for bitcoin, ether and other assets held in MAYAChain’s liquidity pools.
Blockchain data showed that 20.83 BTC, worth approximately $1.34 million at the time, was transferred to the attacker’s bitcoin address. The investigation estimated that about $1.36 million in assets had been moved to external blockchains, while another 8.87 million CACAO remained in the attacker’s MAYAChain wallet.
CACAO’s market value collapsed as the attacker began selling the artificially created tokens. The token had been trading near $0.115 before the exploit but plunged to approximately $0.013, an almost 89% decline, before recovering to around $0.03.
The impact extended well beyond the assets directly withdrawn by the attacker.
As CACAO’s price collapsed, arbitrage traders moved in to purchase the token at heavily discounted prices and exchange it for bitcoin, ether, stablecoins and other cryptocurrencies available in MAYAChain’s liquidity pools.
The technical analysis estimated that the attacker extracted around $1.65 million in total, including tokens that remained on-chain. However, the overall decline in pool value was substantially larger because of the token’s collapse and subsequent arbitrage activity.
As a result, the roughly $11 million decline in MAYAChain pool value should not be interpreted as the amount directly stolen. The analysis estimated that pool value dropped by approximately $10.9 million during the incident, with around $6.4 million attributed to CACAO’s price decline and another $2.9 million linked to arbitrage traders exploiting the resulting price imbalance.
MAYAChain said it hopes to recover the stolen funds by offering the attacker a bug bounty in exchange for their return. The team also said it plans to replace the approximately 20 BTC through investments in Aztec Chain and other sources if the assets cannot be recovered.
Fixing the underlying software vulnerabilities alone will not restore the affected liquidity pools. Much of the CACAO generated during the exploit was exchanged through other MAYAChain markets, meaning those tokens are now mixed with assets deposited by legitimate liquidity providers.

More Stories
Bitcoin Shows 8 of 12 Capitulation Signals, but VanEck Says Bottom Is Still Ahead
Bitcoin Holds Six-Week Range as Global Bond Yields Reach Multi-Decade Highs
OpenAI Falls Behind Anthropic as Losses Mount and Frontier Training Paused