A combination of six software vulnerabilities allowed MAYAChain to artificially inflate a liquidity pool by nearly 50 million CACAO, despite the network lacking sufficient reserves to support the tokens. The flaw ultimately enabled an attacker to withdraw real cryptocurrencies from the protocol.
Cross-chain liquidity network Maya Protocol halted MAYAChain after the exploit created an invalid balance in one of its pools. The attacker drained nearly $1.7 million in bitcoin and other digital assets, while the broader fallout caused liquidity pools to lose around $11 million in value.
Maya Protocol founder Aaluxx said on X that approximately 20 BTC, worth about $1.4 million, along with roughly $300,000 in other assets, had been taken. The protocol paused all trading as a precaution while developers worked on a fix and recovery efforts.
MAYAChain is a cross-chain trading network within the broader Maya ecosystem. It allows users to swap assets such as bitcoin and ether without relying on centralized exchanges. Trades are executed against liquidity pools funded by users, with CACAO serving as the network’s primary connecting asset.
A technical investigation found that six separate vulnerabilities combined to enable the attack. The sequence began after MAYAChain incorrectly concluded that an outgoing transaction had gone missing. The network then activated a recovery function intended to compensate a liquidity pool following a theft.
The recovery mechanism, however, calculated the compensation incorrectly. It credited nearly 49 million CACAO to a relatively small pool even though the network had only about 168,000 CACAO in reserves and could not actually fund the transfer.
While the transfer failed, a separate bug allowed the inflated balance to remain recorded in the network’s state. Because the system did not reverse the change after the failed transaction, MAYAChain continued operating as though the additional tokens were legitimate.
The attacker exploited the distorted pool by depositing a small amount of CACAO and obtaining more than 99% of its liquidity. They then withdrew 48.87 million CACAO and converted the tokens into bitcoin, ether and other assets held across MAYAChain’s pools.
Onchain data showed that 20.83 BTC, worth roughly $1.34 million, was transferred to the attacker’s bitcoin address. The investigation found that approximately $1.36 million in assets moved to external blockchains, while 8.87 million CACAO remained in the attacker’s MAYAChain wallet.
The exploit also triggered a sharp collapse in CACAO’s price. The token fell from about $0.115 before the attack to as low as $0.013, representing a decline of nearly 89%, before recovering to around $0.03.
The losses were not limited to the cryptocurrency directly taken by the attacker.
As CACAO plunged, arbitrage traders purchased the token at depressed prices and exchanged it for bitcoin, ether, stablecoins and other assets available in MAYAChain’s liquidity pools.
The technical analysis estimated that the attacker extracted roughly $1.65 million, including CACAO that remained on the network. However, the overall decline in pool value was much greater because of CACAO’s price collapse and the subsequent arbitrage activity.
The estimated $10.9 million decline in pool value therefore does not represent the amount stolen. Around $6.4 million of the loss resulted from CACAO’s falling price, while approximately $2.9 million was attributed to traders taking advantage of the price imbalance.
MAYAChain said it is seeking the return of the stolen funds by offering the attacker a bug bounty. If the roughly 20 BTC cannot be recovered, the team said it intends to replace the bitcoin through investments in Aztec Chain and other measures.
Resolving the software flaws will not automatically restore the affected liquidity pools. A significant portion of the CACAO created during the exploit was exchanged across MAYAChain markets and has since become mixed with assets deposited by legitimate liquidity providers.

































