Maya Protocol loses $1.7 million in liquidity exploit
Maya Protocol hit by $1.7 million exploit
Maya Protocol, a decentralized network that allows users to swap assets across different blockchains, lost approximately $1.7 million in an exploit. The attacker manipulated the protocol’s accounting system to drain shared liquidity pools.
Blockchain security firm CertiK reported that the attacker inflated the protocol’s accounting records with a false subsidy, then added and removed liquidity to extract about 48.87 million CACAO tokens and 98.82 LINK tokens.
How the attack worked
According to a third-party analysis by RedStone co-founder Marcin Kazmierczak, six bugs acted in sequence to enable the exploit. One key issue was an outbound transaction incorrectly marked as missing, which triggered a compensation routine. This routine credited a pool with 49 million CACAO despite the pool only holding 168,000 CACAO. The transfer failed, but the inflated balance remained, allowing the attacker to deposit a small amount and withdraw 99% of the pool’s value.
Protocol halts operations
LeoDex, a routing service that connects users to Maya Protocol, reported that Maya’s team activated a global halt to stop further transactions. LeoDex said its team would monitor the situation and restore routes later.
Maya Protocol founder Aaluxx stated on social media that the team would “work to fix and recover in full” and added, “We carry on.”
What is confirmed
- The exploit drained roughly $1.7 million from Maya Protocol’s shared liquidity pools.
- The attacker extracted 48.87 million CACAO and 98.82 LINK tokens.
- Maya Protocol activated a global halt to prevent further losses.
- The team has committed to fixing the issue and recovering funds.
What is still unclear
- Whether the stolen funds can be fully recovered.
- The exact timeline for restoring protocol operations.
- Specific details on how the bugs will be fixed to prevent future exploits.
Why this matters for users
Maya Protocol allows users to swap assets across blockchains without wrapping or pegging them, making it a key part of decentralized finance (DeFi). The exploit highlights risks in shared liquidity pools, where funds from multiple users are combined. Users should be aware that even well-established protocols can face security vulnerabilities.