Telegram NewsSubmit game
Six bugs had to line up: how MAYAChain lost 20 BTC and $11 million in pool valueImage Source: Sanity

Six bugs had to line up: how MAYAChain lost 20 BTC and $11 million in pool value

George Tsagkarakis 5 min read
Contents 7 sections
We may include affiliate links in our content, meaning we could earn a commission—or receive blockchain-based assets—if you click a link and make a purchase or take a specific action. Additionally, we use generative AI to help draft and refine our posts for clarity and grammar. All content is fact-checked and reviewed by a human editor before publication.

Twenty-point-eight-three bitcoin left MAYAChain’s pools and landed in an attacker’s wallet. That’s about $1.34 million. It’s also the smallest number in this story.

The bigger one is $10.9 million, which is roughly how far the value of MAYAChain’s liquidity pools fell during the incident. Those two figures are not the same thing, and the gap between them is the most instructive part of what happened here.

Maya Protocol, the cross-chain liquidity protocol behind the network, halted MAYAChain after a chain of software bugs conjured a false balance in one of its pools. Founder @AaluxxMyth said on X that the protocol was exploited for 20 BTC ($1.4 million) plus roughly $300,000 of other assets. Trading stopped. A fix is in progress before swaps resume.

“Sad news 😕 Will work to fix and recover in full. We carry on. @Maya_Protocol” the founder said.

The compensation code did the damage

A technical reconstruction of the attack counted six bugs that had to work together. Not one catastrophic flaw. Six, in sequence.

It started when MAYAChain decided an outgoing transaction had gone missing. That triggered code written for a specific scenario: compensating a liquidity pool after a theft. The pool is the pile of crypto that makes trades possible, and the safety mechanism exists to top it back up.

The mechanism calculated the compensation wrong. It credited roughly 49 million CACAO to a small pool. MAYAChain’s reserve held about 168,000 CACAO. The payment could never have been funded.

So the transfer failed, which should have been the end of it. But another bug had already written the new balance into the network’s records. And rather than reversing the change after the payment failed, MAYAChain kept running as though the pool genuinely held the extra tokens.

A tiny deposit bought 99% of a pool

Here’s where it gets cheap for the attacker. They deposited a small amount into the distorted pool and walked away owning more than 99% of it.

Then the withdrawal: 48.87 million CACAO, immediately swapped for bitcoin, ether and whatever else was sitting in MAYAChain’s other pools.

Onchain records show the 20.83 BTC worth about $1.34 million going to the attacker’s bitcoin address. The analysis put assets moved onto outside blockchains at about $1.36 million. Another 8.87 million CACAO stayed in the attacker’s MAYAChain wallet, which is the part that hasn’t been cashed out.

Total personally extracted by the attacker, including tokens still held on-chain: about $1.65 million.

What CACAO did next

The token traded around $0.115 before the exploit. It fell as low as $0.013. That’s a drop of nearly 89%, and it has since recovered to around $0.03.

CACAO is the common asset connecting MAYAChain’s markets, the hub token every pool pairs against. When the attacker sold into the network, the price of that hub collapsed. And a collapsed hub token is an open invitation.

Arbitrage traders did what arbitrage traders do. They bought the suddenly cheap CACAO and traded it for the bitcoin, ether, stablecoins and other assets still sitting in MAYAChain’s pools. Nothing about that is an exploit. It’s a price dislocation being closed by people who noticed it first.

Why $10.9 million isn’t the theft figure

Break the $10.9 million pool decline apart and the picture changes. Roughly $6.4 million of it reflects CACAO simply becoming less valuable. Another $2.9 million came from traders arbitraging the dislocation.

That leaves the attacker’s own take as a fraction of the headline number. It matters because “an $11 million hack” and “a $1.65 million theft that triggered an $11 million repricing” describe two different events, and only one of them is what happened.

It also matters for anyone doing the mental math on hub-and-spoke designs. When one token underwrites every pool on a network, a bug in the accounting for that token doesn’t stay contained to one pool.

The recovery plan, such as it is

MAYAChain said it hopes the attacker will return the funds in exchange for a bug bounty. That’s the standard opening move and it works often enough to be worth trying.

The fallback is more concrete. The team said it would work on replacing the roughly 20 BTC through investments in Aztec Chain and other means if the funds aren’t returned.

Note the scope of that commitment. It covers the 20 BTC. It doesn’t cover the $6.4 million in CACAO devaluation or the $2.9 million that arbitrage traders extracted, and there’s no obvious mechanism by which it could.

Fixing the code doesn’t refill the pools

This is the uncomfortable part for liquidity providers. Patching six bugs restores the software. It doesn’t restore anyone’s deposits.

Much of the CACAO minted through the exploit was swapped into other MAYAChain markets. It’s now mixed with tokens belonging to ordinary liquidity providers, which means untangling who owns what isn’t a matter of reverting a transaction.

MAYAChain is a smaller cross-chain trading network, the kind that lets you swap bitcoin for ether without routing through a centralized exchange first. That’s the whole pitch, and the pitch is a good one. Traders swap against pools of crypto deposited into the network by people who chose to put their assets there.

Those people are now waiting on a bug bounty appeal to an anonymous attacker and a plan involving investments in Aztec Chain.

If you’re providing liquidity on a hub-token network, the question worth asking isn’t whether the code has been audited. It’s what happens to your position when the hub token drops 89% in an afternoon and the arbitrage bots arrive before you do. On MAYAChain, the answer cost $2.9 million.

Share this article
George Tsagkarakis

George Tsagkarakis, known as Staycalm4now is a professional author in the crypto gaming industry since early 2018. He has experienced all the growth of Blockchain Gaming and helped multiple projects achieve their goals and established a player base. He is the co-founder of egamers.io and now the Founder and owner of CryptoGames.gg He is also the COO of MyStage, an…

More from Blockchain News

Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted