Key Insights
- Crypto hack news: Maya Protocol halted after a $1.7 million exploit.
- Attacker withdrew 48.87 million CACAO after manipulating pool accounting.
- CACAO fell 88.7% as arbitrage deepened broader pool-value losses.
On August 18, Maya Protocol suspended MAYAChain following an exploit involving six interconnected software vulnerabilities. This crypto hack incident resulted in approximately $1.7 million in losses controlled by the attacker. According to Maya co-founder Aalux, the team managed to limit further damage and commenced remediation efforts.
The event was notable because a single transaction leveraged multiple accounting and execution flaws simultaneously. The perpetrator converted the manipulated protocol balances into ETH as its native asset.">Ether, Bitcoin, stablecoins, and RUNE. Furthermore, this situation differed from a typical crypto scam, as software bugs rather than user deception drove the financial damage.
Crypto Hack News: MAYAChain Halts After Six-Bug Exploit
Aalux stated that the attacker absconded with about 20 Bitcoin alongside an additional $300,000 worth of assets. He noted that Maya enforced a global protocol pause immediately upon uncovering the security breach. Subsequently, the development team began preparing patches prior to re-enabling token swaps.

Independently, CertiK Alert estimated the damages to be close to $1.7 million. Their evaluation classified the occurrence as a smart contracts instead of banks and brokers.">decentralized finance exploit rather than a wallet compromise or phishing attack. This distinction is important because the vulnerability targeted pool accounting and protocol logic directly.
Security researcher Vini Barbosa reported that a chain of six distinct bugs facilitated the exploit. His analysis indicated that a single transaction featured 23 messages and initiated the vast majority of the malicious activity. The execution sequence impacted liquidity-pool calculations, trade accounts, and outbound transaction processing.
Barbosa calculated that the attacker siphoned approximately $1.36 million to external blockchain networks. He put the total impact on the protocol near $11 million when factoring in secondary market effects. This broader total encompassed CACAO depreciation and arbitrage activity rather than just stolen funds.
How the Exploit Manipulated Pool Accounting
According to Barbosa’s technical overview, batched deposit messages overwrote an existing ObservedTxVoter entry. The final donation payload superseded prior voter information and reset the outbound block height, altering how MAYAChain assessed subsequent outbound transactions.
Consequently, the outbound matcher applied an erroneous height when evaluating legitimate transfers. Barbosa noted that the network incorrectly marked valid outbounds as missing, which triggered theft-detection mechanisms inside the protocol.
A subsequent vulnerability involved valuation calculations within a low-liquidity ARB.LINK pool. Barbosa pointed out that the subsidy math lacked a proper cap linked to the actual depth of the pool, generating roughly 49.45 million units of CACAO in accounting value.
An additional execution error occurred when the pool state was committed before a module transfer finished. Because the reserve only held about 168,000 CACAO, the funding step failed. Although the error handler logged the issue, it proceeded without rolling back the prior state modification.
The assailant then injected a negligible amount of liquidity into the inflated pool. Barbosa explained that this small position achieved 99.93% ownership before the attacker withdrew 48.87 million CACAO, later converting a portion of those funds into external digital assets.
Crypto Hack News: CACAO Crash Deepened Pool Losses
Barbosa observed CACAO plummet from roughly $0.115 to $0.013 during the security incident, marking an 88.7% collapse across fewer than 240 blocks. This severe repricing magnified the deficits sustained by pools pairing CACAO with other digital currencies.
CoinGecko statistics later positioned CACAO near $0.123 on August 19, demonstrating a rebound from the lows recorded during the exploit. Thin liquidity and disrupted trading environments made direct comparisons across different market venues difficult during the network stoppage.
Preliminary analysis cited by CoinDesk placed the wider drop in pool values at roughly $10.9 million. This figure accounted for CACAO repricing and arbitrage dynamics, meaning it did not reflect tokens directly held by the hacker.
This differentiation also restricts direct comparisons to traditional crypto scam loss metrics. Exploit accounting often incorporates secondary market consequences, unrecovered protocol balances, and stolen funds—metrics that evaluate entirely distinct categories of harm.
Crypto Hack News: Recovery Work and Next Network Step
Aalux confirmed that Maya intends to pursue code fixes and asset recovery. His public remarks also verified that the network blackout remained active as part of the ongoing containment strategy. At the time of the update, Maya had not announced a confirmed restart schedule.
Maya’s official documentation highlights network solvency and security protections as foundational components of the protocol. The incident demonstrated how interacting safety protocols can still falter when specific edge cases align. The preliminary investigation concentrated on these combined execution pathways.
Barbosa noted that this specific attack vector is not viable on THORChain. His assessment was limited to the precise bug sequence outlined in Maya’s initial review and did not rule out the presence of entirely separate vulnerabilities.
Moving forward, the primary milestones to watch for are the release of a technical patch or Maya’s network relaunch. Observers should also monitor whether the development team releases definitive loss accounting figures to clarify outstanding protocol liabilities and recovered funds.
Frequently Asked Questions
What caused the Maya Protocol exploit?
The exploit was driven by six interconnected software flaws that manipulated pool accounting and protocol logic, rather than user deception.
How much money was lost in the Maya Protocol hack?
Direct attacker-controlled losses are estimated at approximately $1.7 million, while wider pool-value impacts reached nearly $11 million due to market effects.
Did MAYAChain shut down after the attack?
Yes, Maya co-founders implemented a global network halt immediately following the exploit to contain the damage and prepare security fixes.
How did the exploit affect the CACAO token?
CACAO plummeted 88.7% during the incident, falling from about $0.115 to $0.013 before later showing signs of recovery.




