Twenty-point-eight-three bitcoin left MAYAChain’s pools and landed in an attacker’s wallet. That’s about $1.34 million. It’s also the smallest number in this story.
The bigger one is $10.9 million, which is roughly how far the value of MAYAChain’s liquidity pools fell during the incident. Those two figures are not the same thing, and the gap between them is the most instructive part of what happened here.
Maya Protocol, the cross-chain liquidity protocol behind the network, halted MAYAChain after a chain of software bugs conjured a false balance in one of its pools. Founder @AaluxxMyth said on X that the protocol was exploited for 20 BTC ($1.4 million) plus roughly $300,000 of other assets. Trading stopped. A fix is in progress before swaps resume.
“Sad news 😕 Will work to fix and recover in full. We carry on. @Maya_Protocol” the founder said.
The compensation code did the damage
A technical reconstruction of the attack counted six bugs that had to work together. Not one catastrophic flaw. Six, in sequence.
It started when MAYAChain decided an outgoing transaction had gone missing. That triggered code written for a specific scenario: compensating a liquidity pool after a theft. The pool is the pile of crypto that makes trades possible, and the safety mechanism exists to top it back up.
The mechanism calculated the compensation wrong. It credited roughly 49 million CACAO to a small pool. MAYAChain’s reserve held about 168,000 CACAO. The payment could never have been funded.
So the transfer failed, which should have been the end of it. But another bug had already written the new balance into the network’s records. And rather than reversing the change after the payment failed, MAYAChain kept running as though the pool genuinely held the extra tokens.
A tiny deposit bought 99% of a pool
Here’s where it gets cheap for the attacker. They deposited a small amount into the distorted pool and walked away owning more than 99% of it.
Then the withdrawal: 48.87 million CACAO, immediately swapped for bitcoin, ether and whatever else was sitting in MAYAChain’s other pools.
Onchain records show the 20.83 BTC worth about $1.34 million going to the attacker’s bitcoin address. The analysis put assets moved onto outside blockchains at about $1.36 million. Another 8.87 million CACAO stayed in the attacker’s MAYAChain wallet, which is the part that hasn’t been cashed out.
Total personally extracted by the attacker, including tokens still held on-chain: about $1.65 million.
What CACAO did next
The token traded around $0.115 before the exploit. It fell as low as $0.013. That’s a drop of nearly 89%, and it has since recovered to around $0.03.
CACAO is the common asset connecting MAYAChain’s markets, the hub token every pool pairs against. When the attacker sold into the network, the price of that hub collapsed. And a collapsed hub token is an open invitation.
Arbitrage traders did what arbitrage traders do. They bought the suddenly cheap CACAO and traded it for the bitcoin, ether, stablecoins and other assets still sitting in MAYAChain’s pools. Nothing about that is an exploit. It’s a price dislocation being closed by people who noticed it first.
Why $10.9 million isn’t the theft figure
Break the $10.9 million pool decline apart and the picture changes. Roughly $6.4 million of it reflects CACAO simply becoming less valuable. Another $2.9 million came from traders arbitraging the dislocation.
That leaves the attacker’s own take as a fraction of the headline number. It matters because “an $11 million hack” and “a $1.65 million theft that triggered an $11 million repricing” describe two different events, and only one of them is what happened.
It also matters for anyone doing the mental math on hub-and-spoke designs. When one token underwrites every pool on a network, a bug in the accounting for that token doesn’t stay contained to one pool.
The recovery plan, such as it is
MAYAChain said it hopes the attacker will return the funds in exchange for a bug bounty. That’s the standard opening move and it works often enough to be worth trying.
The fallback is more concrete. The team said it would work on replacing the roughly 20 BTC through investments in Aztec Chain and other means if the funds aren’t returned.
Note the scope of that commitment. It covers the 20 BTC. It doesn’t cover the $6.4 million in CACAO devaluation or the $2.9 million that arbitrage traders extracted, and there’s no obvious mechanism by which it could.
Fixing the code doesn’t refill the pools
This is the uncomfortable part for liquidity providers. Patching six bugs restores the software. It doesn’t restore anyone’s deposits.
Much of the CACAO minted through the exploit was swapped into other MAYAChain markets. It’s now mixed with tokens belonging to ordinary liquidity providers, which means untangling who owns what isn’t a matter of reverting a transaction.
MAYAChain is a smaller cross-chain trading network, the kind that lets you swap bitcoin for ether without routing through a centralized exchange first. That’s the whole pitch, and the pitch is a good one. Traders swap against pools of crypto deposited into the network by people who chose to put their assets there.
Those people are now waiting on a bug bounty appeal to an anonymous attacker and a plan involving investments in Aztec Chain.
If you’re providing liquidity on a hub-token network, the question worth asking isn’t whether the code has been audited. It’s what happens to your position when the hub token drops 89% in an afternoon and the arbitrage bots arrive before you do. On MAYAChain, the answer cost $2.9 million.