
Six interconnected software flaws enabled an attacker to create nearly 50 million CACAO in a MAYAChain liquidity pool without sufficient reserves, ultimately allowing the fraudulent tokens to be exchanged for real crypto assets.
Maya Protocol suspended MAYAChain after the exploit generated an artificial pool balance. The attack drained almost $1.7 million in bitcoin and other cryptocurrencies, while the resulting market disruption reduced the value of the network’s pools by roughly $11 million.
Maya Protocol founder Aaluxx said the attacker extracted about 20 BTC, worth approximately $1.4 million, plus another $300,000 in other assets. The protocol stopped trading to prevent further damage and began working on a fix and recovery strategy.
MAYAChain is a cross-chain trading network within the Maya ecosystem that enables users to swap assets such as bitcoin and ether without going through centralized exchanges. Users trade against liquidity pools, with CACAO functioning as the ecosystem’s shared asset.
A technical reconstruction of the incident found that six separate vulnerabilities combined to make the attack possible. It started when MAYAChain incorrectly determined that an outgoing transaction had disappeared and activated a recovery process intended to reimburse a liquidity pool following a theft.
That process calculated the compensation incorrectly, adding nearly 49 million CACAO to a small pool even though MAYAChain had only about 168,000 CACAO available in its reserves.
The payment failed, but another bug allowed the inflated balance to be permanently recorded. A further flaw prevented the system from rolling back the balance, causing the network to continue treating the nonexistent tokens as part of the pool.
The attacker then deposited a small amount of CACAO and gained control of more than 99% of the manipulated pool. They withdrew 48.87 million CACAO before swapping the tokens for bitcoin, ether and other assets held across MAYAChain.
Blockchain records indicate that 20.83 BTC, worth around $1.34 million, was transferred to the attacker’s bitcoin address. About $1.36 million in assets were moved to external blockchains, while 8.87 million CACAO remained in the attacker’s MAYAChain wallet.
The exploit triggered a steep collapse in CACAO’s price. The token fell from approximately $0.115 before the attack to a low near $0.013, losing almost 89% of its value, before recovering to around $0.03.
The damage was then compounded by arbitrage activity.
With CACAO trading at a sharply discounted price, traders bought the token and exchanged it for bitcoin, ether, stablecoins and other cryptocurrencies held in MAYAChain’s pools.
The attacker was estimated to have directly extracted around $1.65 million, including CACAO still held on-chain. However, the total impact on pool value was much larger because of the token’s collapse and the subsequent arbitrage trades.
The technical analysis estimated that MAYAChain pools lost approximately $10.9 million in value. Around $6.4 million was attributed to CACAO’s depreciation, while roughly $2.9 million resulted from arbitrageurs exploiting the distorted prices.
Maya Protocol said it is offering the attacker a bug bounty in an effort to recover the stolen funds. If the approximately 20 BTC is not returned, the team said it will seek to replace the bitcoin through investments in Aztec Chain and other sources.
Fixing the vulnerabilities alone will not fully restore the affected pools. A large amount of CACAO created during the exploit was exchanged across MAYAChain markets, where it became mixed with assets belonging to legitimate liquidity providers.





