Maya Protocol Halts After $1.7 Million Exploit Drains Bitcoin and Assets

Maya Protocol Halts After $1.7 Million Exploit Drains Bitcoin and Assets

Maya Protocol shut down its cross-chain trading network after an attacker chained together six software flaws to drain roughly $1.7 million in bitcoin and other assets, according to the project’s pseudonymous co-founder.

The attacker stole about 20 bitcoin (BTC), worth $1.4 million, plus another $300,000 in other assets, Aalux, Maya Protocol’s pseudonymous co-founder, said. The protocol triggered a global halt, contained further damage, and began working on a fix to resume swaps, he said.

The incident adds Maya to a string of recent DeFi exploits keeping cross-chain bridge security under scrutiny.

A preliminary technical analysis shared by Aalux attributed the exploit to six chained bugs involving trade accounts, outbound transaction handling, and liquidity pool calculations. The attacker used a single transaction containing 23 messages. That sequence triggered a false theft detection, artificially inflated a low-liquidity pool, and let the attacker withdraw 48.87 million CACAO tokens from Maya’s Asgard module.

The mechanism was straightforward at the code level. A pool was credited with tens of millions of tokens that were never properly funded. The attacker then pulled real bitcoin and other assets against that inflated balance.

The analysis calculated that about $1.36 million was transferred to external blockchains. Roughly $291,000 in CACAO and trade-account positions on MAYAChain remained with the attacker.

CACAO, the network’s native token, slid 88.7%, from approximately $0.115 to $0.013 during the incident, according to researcher Vini Barbosa, cited by Cointelegraph.

A wider $10.9 million decline in pool value was reported in the same analysis. That figure included arbitrage activity and CACAO’s devaluation, not just assets stolen by the attacker. The numbers track different things: $1.7 million covers what the attacker took, while $10.9 million reflects broader pool-value erosion.

Aalux said the protocol is working on a fix to resume swaps. No timeline for restarting the network has been stated. The identity of the attacker remains unknown.

> ABOUT_THE_AUTHOR _

James Chatfield

// Senior News Editor

I lead the editorial team covering digital assets and blockchain regulation at CryptoWatchDaily. After earning a Journalism degree from The University of Sheffield, I spent a decade reporting on traditional finance before shifting focus to crypto. I value accuracy and clarity over hype. When I’m not tracking market movements, I enjoy distance running and collecting vintage sci-fi novels.

VIEW_PROFILE >>