Cross-blockchain liquidity network Maya Protocol halted all network operations after an attacker exploited six bugs simultaneously. This series of exploits allowed the perpetrator to drain $1.7 million worth of crypto assets from their ecosystem. The project’s founder, using the pseudonym AaluxxMyth or “Maya”, confirmed the details of the loss in an announcement. “We were likely exploited for about 20 BTC ($1.4 million) and other assets ($300,000),” they wrote.
The incident had an immediate impact on the project’s market value. The price of their native token, CACAO, plummeted sharply shortly after the exploit was announced. Maya Protocol operates MAYAChain, a decentralized network that facilitates crypto swaps across various blockchains without involving centralized exchanges. According to Google News records, this breach marks the 16th crypto hacking incident to occur within the month of August alone.
Balance Engineering Through Message Manipulation
The attack was carried out systematically by targeting internal security detection mechanisms. The attacker inserted a single MsgDeposit transaction containing 23 messages to trigger a false theft alert in the system. This condition was then exploited by the perpetrator to inflate balances in the low-liquidity CACAO pool.
To multiply the balance, the attacker exploited a vulnerability in the uncapped slash subsidy system. Through this loophole, the perpetrator inflated the pool with 49.45 million CACAO. This figure immediately gave the attacker control of 99.93% of the pool share. After gaining majority control, the attacker registered as a liquidity provider and immediately withdrew 48.87 million CACAO from the inflated pool. The withdrawal trail led to a suspected attacker’s Bitcoin address, which was recorded receiving 20.83 BTC, equivalent to $1.34 million.
Bugs Lingering for Years
One standout aspect of the incident is the age of the bugs themselves. The six exploited security vulnerabilities had gone undetected in the protocol for the past three to four years. This occurred despite the fact that Maya Protocol’s codebase had previously cleared security audits by two assessment firms, Halborn and Fable 5.
Currently, the Maya Protocol development team is drafting a plan to cover the losses. They plan to recover around 20 BTC through their investments in Aztec Chain and several other means. The gathered funds will be returned in full to the pools affected by the exploit.
If the hacker is reluctant to return the funds, the Maya Protocol team still hopes for a final compromise. They have offered to resolve the incident through a bug bounty scheme as a middle ground to save the remaining assets.
Reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




