Cross-chain decentralized exchange Maya Protocol suspended operations on Wednesday after an attacker exploited multiple software vulnerabilities to extract an estimated $1.7 million in cryptocurrency assets.
The pseudonymous co-founder of Maya Protocol, Aalux, reported that the attacker stole approximately 20 Bitcoin, valued at $1.4 million, alongside an additional $300,000 in other digital assets. In response, the protocol implemented a global network halt, contained the breach, and began developing a patch to restore swap functionality.
A preliminary technical review attributed the incident to six interconnected bugs affecting trade accounts, outbound transaction processing, and liquidity pool calculations. The attacker executed a single transaction containing 23 messages, triggering a false theft detection mechanism. This allowed the attacker to inflate a low-liquidity pool and withdraw 48.87 million CACAO tokens from Maya’s Asgard module.
Of the total stolen amount, approximately $1.36 million was bridged to external blockchains, while the attacker retained roughly $291,000 in CACAO tokens and trade-account positions within MAYAChain. Independent blockchain security researcher Vini Barbosa confirmed that CACAO’s price declined by 88.7%, dropping from approximately $0.115 to $0.013 during the exploit.
The analysis estimated a broader $10.9 million reduction in pool value, though this figure includes arbitrage-driven price movements and CACAO’s devaluation rather than assets directly stolen by the attacker.










