The cross-chain decentralized exchange (DEX) Maya Protocol has halted its network after an attacker exploited a series of software vulnerabilities and made off with approximately $1.7 million worth of crypto assets.
On Wednesday, pseudonymous Maya Protocol co-founder Aalux reported that the attacker stole about 20 Bitcoin worth $1.4 million and an additional $300,000 in other assets. He stated that the protocol completely halted the network, prevented further damage, and began patching the vulnerabilities to resume swaps.
A preliminary technical analysis published by Aalux links the incident to six interconnected bugs in trading accounts, outbound transaction processing, and pool liquidity calculations. According to the analysis, the attacker used a single transaction with 23 messages to trigger a false theft detection, artificially inflate a low-liquidity pool's volume, and withdraw 48.87 million CACAO tokens from the Maya Asgard module.
The report says about $1.36 million was transferred by the attacker to external blockchains. A further approximately $291,000 in CACAO and trading positions on MAYAChain remained with the attacker.
Independent blockchain security researcher Vini Barbosa summarized the outcome, noting that CACAO dropped 88.7% during the incident—from around $0.115 to $0.013.
According to the analysis, the total value locked (TVL) in the pools decreased by $10.9 million. However, this figure includes arbitrage activity and CACAO depreciation, not just the assets stolen by the attacker.
Related Material: BitBox Fixed 'Serious' Wallet Vulnerabilities That Could Have Put Funds at Risk
end-content




