Maya Protocol has halted its MAYAChain network after an exploit allowed an attacker to manipulate a liquidity pool and withdraw Bitcoin and other crypto assets.
MAYAChain is investigating how a faulty pool balance enabled the attacker to extract assets
Photo Credit: Unsplash/Shubham Dhage
The cross-chain liquidity protocol called Maya Protocol shut down its network, MAYAChain, as a result of multiple bugs in its software leading to the creation of a fake balance in one of its liquidity pools, which let the hacker steal close to $1.7 million (roughly Rs. 16.3 crore) worth of Bitcoin and other cryptocurrencies resulting in a total loss of around $11 million (roughly Rs. 105.3 crore). The anonymous co-founder of Maya Protocol, named “Aalux,” reported having been hacked on X and suffered losses of 20 BTC, which is around $1.4 million (roughly Rs. 13.4 crore), along with $300,000 (roughly Rs. 2.9 crore).
The protocol halted all trading to minimise the impact and noted that it is working on a solution before swaps can be carried out again. MAYAChain is a decentralised trading platform that enables people to swap crypto assets such as Bitcoin and Ethereum without using any centralised exchanges and is part of the Maya ecosystem. It uses the CACAO token as an anchor to the markets through which traders conduct swaps.
Sad news :confused:
Will work to fix and recover in full. We carry on. @Maya_Protocol pic.twitter.com/EYK9BeWWLI
The technical analysis showed that six software bugs were involved in this attack, all of which were necessary to exploit the vulnerability. This process started when MAYAChain mistakenly thought that the outgoing transaction was lost and executed the code aimed at compensating a liquidity pool that had been robbed. However, the safety measure failed to make the right calculation. The mechanism added about 49 million CACAO to the smaller pool despite the fact that there were only 168,000 CACAO in the reserve of MAYAChain.
The transaction was not executed, but a different flaw had caused the updated balance to be already saved in the network's records. Rather than undoing the update due to the failed transaction, MAYAChain proceeded to operate assuming the pool had indeed received the additional tokens. The attacker then deposited a small amount into this rigged pool and owned over 99 percent of the pool. Immediately after this, 48.87 million CACAO was withdrawn by this person, and they began exchanging these tokens with the help of MAYAChain's pools for Bitcoins and Ethers.
The protocol also said that it is looking forward to getting back its lost money through a bug bounty from the attacker. If not, it promised to make sure that roughly 20 BTC is replaced through investments in Aztec Chain and other means if the funds are not returned. Fixing the bug alone will not return the pools to their former condition. Most of the CACAO that was mined via the vulnerability is now in different MAYAChain markets, where it mixes with other tokens.
The second quarter of 2026 is already the most hacked quarter on record in terms of the number of attacks, with 83 hacks of crypto protocols, per an analysis from market insights provider Unfolded based on data from DefiLlama. KelpDAO's $293 million (roughly Rs. 2,805 crore) hack and Drift Protocol's $280 million (roughly Rs. 2,681 crore) exploit were the largest incidents of the quarter.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.