Maya Protocol, a cross-chain decentralized exchange built from THORChain’s open-source code, halted its network after an attacker reportedly exploited multiple software weaknesses to siphon roughly $1.7 million worth of crypto assets. The protocol’s pseudonymous co-founder, Aalux, said the immediate goal of the shutdown was to stop further damage while the team worked toward a fix to resume swaps.
In a preliminary technical account posted to X, Aalux described the theft as involving about 20 bitcoin (valued at $1.4 million) alongside approximately $300,000 in other assets. The post also argued that the exploit’s impact extended beyond the direct theft, with MayaChain’s liquidity pools losing far more value amid downstream effects.
Key takeaways
- Maya Protocol halted operations after a reported $1.7 million exploit tied to a chain of software bugs across trade accounting and liquidity pool calculations.
- The attacker’s reported actions appear to have manipulated how withdrawals and compensation were computed for a low-liquidity pool.
- While the hack haul was estimated at about $1.7 million, a technical analysis cited pool losses of roughly $10.9 million linked to arbitrage activity and the collapse of MAYAChain’s gas/settlement token, CACAO.
- The protocol attributed the incident to six interconnected issues, including how outbound transfers were tracked and how credits were applied to pools.
What Maya Protocol said happened
Maya Protocol operates as a cross-chain swapping system, and the incident centered on MAYAChain liquidity pools and protocol-controlled reserves. In the ecosystem, CACAO serves as the gas and settlement token and is paired with supported assets in liquidity pools.
Aalux’s preliminary analysis, shared on X, attributed the incident to six “chained bugs.” The description focused on three main areas: trade accounts, outbound transaction handling, and liquidity pool math. According to the account, the exploit overwrote records that track outbound transfers, causing transfers to be treated as missing. That classification triggered a theft-protection mechanism—but the mechanism then miscalculated what compensation should be for Maya’s low-liquidity ARB.LINK pool on Arbitrum.
The miscalculation allegedly resulted in an incorrect credit of 49.45 million CACAO to the affected pool. Even though the transfer meant to back up that credit reportedly failed due to the reserve holding insufficient CACAO, the inflated pool balance remained on-chain.
The pool manipulation and reported extraction
With the pool balance allegedly overstated, the attacker then added only negligible liquidity—an approach intended to convert the manipulated accounting state into control of the pool. Aalux’s technical write-up says the attacker was able to obtain 99.93% of the pool and then withdraw 48.87 million CACAO from Asgard, described as the system holding protocol assets.
Blockchain security researcher Vini Barbosa summarized the findings and pointed to the token price impact during the incident. Barbosa reported that CACAO fell by 88.7%, dropping from roughly $0.115 to about $0.013 as the exploit unfolded.
As a result, readers should separate two different outcomes: the attacker’s direct asset extraction (estimated by Aalux at about $1.7 million) and the broader market/liquidity damage that followed once the token and pool states deteriorated.
Why the losses may have exceeded the theft
Even though the attacker’s reported haul was around $1.7 million, Aalux’s analysis suggested a significantly larger loss footprint across MAYAChain liquidity pools—estimated at about $10.9 million in value. The write-up attributed the higher figure to effects such as arbitrage and the collapse of CACAO.
This distinction matters for investors and users because it highlights how cross-chain DEX incidents can propagate. When a token’s price and liquidity conditions break down quickly, the system can experience cascading effects: arbitrageurs may rebalance across venues, and pool accounting changes can trigger a feedback loop of reduced depth and further price pressure. In other words, even if the attacker’s withdrawal amount is limited, the protocol’s liquidity environment can still suffer outsized damage.
Aalux also said the protocol intended to pursue recovery of the stolen funds via a bug bounty process and work to restore liquidity, alongside efforts to resume swaps once the underlying issues were fixed.
What to watch next
With Maya Protocol currently halted, the next signals to monitor are (1) whether the team can restore correct liquidity pool accounting and outbound transfer tracking, and (2) whether CACAO and impacted pools recover without triggering additional exploit pathways. Until a full post-incident fix and recovery plan is confirmed, the key uncertainty remains how comprehensively the exploited logic has been patched and how fast liquidity can return.






