Maya Protocol Hack Drains 20 BTC in $1.7M Exploit

Maya Protocol Hack Drains 20 BTC in $1.7M Exploit

Last Updated:
Maya Protocol Hack Drains 20 BTC in $1.7M Exploit
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Maya Protocol lost 20 BTC as six flaws chained together triggered a $1.7M exploit.
  • The attacker moved $1.36M externally while $291K stayed on MAYAChain.
  • The $10.9M pool decline largely reflects valuation changes rather than stolen funds. 

Maya Protocol halted its network after an attacker chained six software flaws together, draining roughly $1.7 million in Bitcoin and other digital assets. The breach involved about 20 BTC worth roughly $1.4 million, plus another $300,000 in assets.

While the incident led to a larger decline in the value held across Maya’s liquidity pools, the preliminary findings show that the attacker did not extract the full amount reflected in that decline.

Maya Protocol Exploit Used Six Linked Flaws

The Maya Protocol exploit unfolded via a single transaction comprising 23 messages, according to a preliminary technical analysis shared by the pseudonymous co-founder Aalux. The attacker combined weaknesses involving trade accounts, outbound transaction processing, and liquidity pool calculations.

The sequence began when the attacker incorrectly triggered the protocol’s theft-detection mechanism, then manipulated a pool with limited liquidity. By inflating the pool’s value, the attacker withdrew 48.87 million CACAO tokens from Maya’s Asgard module.

Those modules hold assets used to process cross-chain swaps. The attack therefore affected several parts of Maya Protocol’s transaction and accounting systems within the same sequence.

Aalux said the network-wide halt stopped the incident and prevented further losses while developers investigated the affected components and prepared a fix.

Maya Hack Triggers $10.9M Pool Drop 

Approximately $1.36 million was moved to external blockchains, while another $291,000 remained under the attacker’s control within MAYAChain through CACAO holdings and trade-account positions. This means the attacker directly controlled about $1.65 million in value.

However, the total decline in Maya Protocol’s liquidity pools reached roughly $10.9 million. According to the technical findings, most of this drop reflects changes in pool valuations rather than funds actually extracted by the attacker. The response mirrors emergency actions seen in other cross-chain exploits. 

In June, Axelar disabled bridge routes connected to Secret Network after about $4.7 million in bridged assets were taken through an exploit involving a Secret-side ICS-20 smart contract.

Related: What Happens If You Buy Bitcoin Before the Bottom Is Confirmed?

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.