Maya Protocol Halted After $1.7M Exploit
A cross-chain protocol halted operations after an attacker exploited six software flaws to drain Bitcoin and other assets.

The update
Maya Protocol halted its MAYAChain network Tuesday after an attacker exploited six software flaws to drain roughly $1.7 million in Bitcoin and other assets. The team identified the attack as a single 23-message transaction that triggered a false “theft” detection, inflated a low-liquidity pool’s balance via an uncapped subsidy, and allowed the attacker to withdraw the inflated value.
Why it matters
The incident highlights the complexity of securing cross-chain liquidity networks. The attacker gained 99.93% control of the affected pool, causing the CACAO token to plummet nearly 89% and wiping out about $10.9 million in liquidity pool value. The protocol’s founder stated the team is focused on fixing the vulnerabilities and rebuilding.
What to watch
Watch for the protocol’s timeline on resuming swaps and any updates on whether the stolen funds can be recovered. The team has not yet confirmed if AI was used in the attack.
Sources
- decrypt.co — Financial figures ($1.7M stolen, $10.9M pool drop) and technical details of the six-bug exploit.
- coindesk.com — Context on the cross-chain nature of the protocol and the mechanics of the pool inflation.



