MayaChain halted after exploit drains about $1.7 million in crypto
CoinDesk's reconstruction says a sequence of accounting and transfer bugs created a false pool balance; CACAO fell nearly 89% as the network paused trading.
By The Third AnglePublished 3 min read
Illustrative computing hardware for a report on a software exploit; the image does not depict MayaChain's systems or the incident. Photo: Unsplash · Unsplash License
Maya Protocol halted its MAYAChain network after an attacker exploited a sequence of software bugs and drained about $1.7 million in bitcoin and other assets, according to CoinDesk's report. The outlet said its reconstruction of the incident, combined with onchain records, found that the attacker took roughly $1.65 million while the value of Maya's liquidity pools fell by about $10.9 million during the fallout.
Maya Protocol's official account said trading was stopped while the team worked on a fix and recovery. The protocol's public documentation describes halt controls that can pause trading when an unauthorized transaction is detected, but it does not itself establish the amounts involved in this incident.
A false balance became a real withdrawal
CoinDesk's technical reconstruction says the attack began when MAYAChain treated an outgoing transaction as missing and triggered a compensation process. A calculation error then credited a pool with about 49 million CACAO even though the reserve held only about 168,000 CACAO.
The transfer did not fund successfully, but a separate accounting failure left the inflated balance in the network's records. The attacker deposited a small amount, gained more than 99% of the distorted pool and withdrew 48.87 million CACAO before exchanging the tokens for bitcoin, ether and other assets, the reconstruction said.
Pool damage is not the same as stolen funds
CACAO fell from about $0.115 before the exploit to roughly $0.013, a decline of nearly 89%, before partially recovering. Arbitrage traders then exchanged the dislocated token for assets in other pools, widening the damage to liquidity providers.
That distinction matters. The report estimates the attacker personally extracted about $1.65 million, while the larger pool-value decline also reflected the token's collapse and trading around the dislocation. Maya Protocol said it hopes to recover the funds through a bug bounty and would work on replacing about 20 BTC if the assets are not returned.
The next public checkpoint is the team's repair and recovery plan. A software fix may stop another exploit, but it cannot by itself restore assets that were swapped out of the affected pools or resolve how losses will be allocated among liquidity providers.