started · updated
Maya Protocol halts network after $1.7M exploit
Maya Protocol, a cross-chain decentralized exchange, has suspended its network following a sophisticated exploit that drained approximately $1.7 million in digital assets. The attack involved a chain of six interconnected software vulnerabilities related to trade accounts, outbound transaction processing, and liquidity pool calculations.
The attacker utilized a single transaction containing 23 messages to manipulate the protocol’s internal accounting. This allowed for the withdrawal of approximately 48.87 million CACAO tokens and roughly 20 BTC, valued at $1.4 million, alongside $300,000 in other assets. While $1.36 million was moved to external blockchains, approximately $291,000 in CACAO and trade-account positions remained on the MAYAChain.
The exploit caused significant market volatility, with the protocol’s native settlement token, CACAO, plummeting nearly 89% in value. Although the direct theft was estimated at $1.7 million, the total decline in liquidity pool value reached approximately $10.9 million due to the CACAO price collapse and subsequent arbitrage activity. The protocol’s co-founder, Aalux, confirmed the network halt to contain further losses while developers work on a fix.
Entities
Aalux · Asgard module · CACAO · CertiK · Maya Protocol · PeckShield · Vini Barbosa