Crypto

Maya Protocol Halts Network After Six Software Bugs Lead to $1.7M Exploit

Six code vulnerabilities allowed attacker to drain 20.83 BTC and inflate liquidity pool by 49.45 million CACAO

Cross-chain liquidity network Maya Protocol halted operations Tuesday after an attacker exploited six software flaws to manipulate a liquidity pool and extract roughly $1.7 million in Bitcoin and other assets. The protocol, which operates MAYAChain as a decentralized cross-chain swap platform built on Cosmos SDK, suspended network swaps to contain financial damage across its ecosystem.

In a post on X, Maya Protocol founder AaluxxMyth, also known as Maya, acknowledged the breach and confirmed that developers paused network activity to isolate the code vulnerabilities before restoring swap functionality. “No way to sugar coat this,” Maya wrote in the post. “We have likely been exploited by 20 BTC ($1.4M) and other assets ($300k).”

In a post-mortem report, the team behind Maya Protocol said the attacker exploited six bugs to inflate a liquidity pool by 49.45 million CACAO, then gained 99.93% control of the pool and withdrew 48.87 million CACAO.

“The attack used a single 23-message MsgDeposit transaction to trigger a false “theft” detection, inflate a low-liquidity pool’s CACAO balance via an uncapped slash subsidy, then immediately LP’d into and withdrew from the inflated pool to extract the value,” they wrote.

The rapid dumping of the inflated token supply caused the price of CACAO to collapse nearly 89%, falling from roughly $0.25 to $0.028 during the exploit window. According to decentralized finance tracking data from DefiLlama, the sudden drop in native token value contributed to an estimated $10.9 million decline in MAYAChain’s total value locked as liquidity providers experienced massive impermanent loss. As the attacker swapped the drained tokens for Bitcoin and other assets, the cascading price drop limited the total USD value the perpetrator could extract, leaving an estimated $1.36 million transferred to external blockchains and approximately $291,000 remaining on-chain.

The underlying code flaws had remained undetected in MAYAChain’s codebase for three to four years despite prior security audits conducted by blockchain security firms Halborn and Fable 5. Addressing the oversight, Maya stated that the team must adopt a strictly adversarial approach to code reviews going forward, adding, “We have to get even more adversarial and look for extremely simple code primitives.”

Maya Protocol published the suspected attacker’s primary Bitcoin address, which received 20.83 BTC valued at approximately $1.34 million. While the team offered a bug bounty in exchange for the return of the stolen funds, Maya outlined an alternative recovery plan if negotiations fail, noting that the protocol intends to recover the missing 20 BTC through investments in Aztec Chain and other financial reserves to reimburse the affected liquidity pool.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button