Maya Protocol, also known as MAYAChain, halted its network after an attacker chained six bugs to manipulate pool accounting and drain about $1.7 million in shared liquidity. Investigators said the exploit began when an outbound transaction was incorrectly treated as missing, triggering a compensation routine that falsely credited roughly 49 million CACAO to a pool that held only about 168,000 CACAO in reserves. Because the failed transfer was not properly rolled back, the attacker could add a small amount of liquidity, dominate the inflated pool, and withdraw about 48.87 million CACAO along with roughly 98.82 LINK before swapping assets into BTC, ETH, and other tokens.
The incident caused damage beyond the direct theft, with reports that liquidity pool value fell by roughly $10.9 million to $11 million overall and the CACAO token price plunged nearly 89% before partially recovering. Maya Protocol said trading was fully stopped to contain the attack, while project representatives said they would work to fix the flaw, recover funds, and reimburse the stolen 20 BTC if the attacker does not return assets under a possible bug bounty arrangement. Public statements from the team also pointed to treasury resources, including funds invested in Aztec Chain, as a potential source for reimbursement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Maya Protocol's team said it would work to fix the vulnerability and recover funds in full. The team also said it hoped the attacker might return the assets via a bug bounty arrangement and intended to reimburse the stolen 20 BTC from invested funds and other sources if needed.
After the exploit, Maya Protocol activated a global halt and fully stopped trading on MAYAChain to limit further damage. LeoDex reported the halt, and founder Aaluxx/AaluxxMyth confirmed the incident and response.
An attacker exploited Maya Protocol/MAYAChain using a chain of six bugs that falsely inflated pool accounting and enabled the theft of roughly $1.7 million in assets. Reported stolen amounts included about 48.87 million CACAO, 98.82 LINK, and roughly 20 BTC plus other assets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.