Skip to content
August 19, 2026
Nifty 50+0.62%
Sensex+0.55%
S&P 500-0.18%
Subscribe
Analysis

Crypto Hack News: Maya Protocol Loses $1.7M in Six-Bug Attack

Maya Protocol suffered a $1.7 million exploit after an attacker leveraged six interconnected software vulnerabilities, forcing a global network halt and causing CACAO to temporarily plummet.

Crypto Hack News: Maya Protocol Loses $1.7M in Six-Bug Attack

Key Insights

  • Crypto hack news: Maya Protocol halted after a $1.7 million exploit.
  • Attacker withdrew 48.87 million CACAO after manipulating pool accounting.
  • CACAO fell 88.7% as arbitrage deepened broader pool-value losses.

Maya Protocol paused MAYAChain on August 18 following an exploit that leveraged six interconnected software vulnerabilities. This security incident resulted in roughly $1.7 million worth of losses controlled by the attacker. Maya co-founder Aalux stated that the team successfully contained further damage and initiated recovery efforts.

The event was notable because a single transaction exploited multiple accounting and execution flaws simultaneously. The perpetrator converted the manipulated protocol balances into Bitcoin, Ether, RUNE, and stablecoins. Furthermore, this incident was distinct from a crypto scam because it stemmed from software vulnerabilities rather than user deception.

Crypto Hack News: MAYAChain Halts After Six-Bug Exploit

According to Maya co-founder Aalux noting the details, the culprit made off with approximately 20 Bitcoin and an additional $300,000 in assets. He explained that Maya enacted a global network halt immediately upon detecting the breach, after which the team began drafting patches before allowing swaps to resume.

CertiK Alert independently estimated the financial damage to be close to $1.7 million, categorizing the event as a decentralized finance exploit rather than a phishing attack or wallet compromise. This distinction is critical because the attack directly targeted protocol logic and pool accounting structures.

Independent security researcher Vini Barbosa reported that a chain of six separate bugs enabled the exploit. His analysis highlighted that one transaction contained 23 messages and drove the majority of the activity. The malicious sequence directly impacted trading accounts, outbound transaction processing, and liquidity-pool calculations.

Barbosa pointed out that the attacker transferred roughly $1.36 million out to external blockchains. He calculated the total protocol impact to be around $11 million when factoring in secondary market effects, which included arbitrage activity and the depreciation of CACAO alongside stolen funds.

How the Exploit Manipulated Pool Accounting

Barbosa’s technical breakdown explained that batched deposit messages overwrote an ObservedTxVoter record. The final donation message replaced previous voter data and reset the outbound height, thereby altering how MAYAChain validated subsequent outbound transactions.

Consequently, the outbound matcher relied on an incorrect height parameter when reviewing legitimate transfers, mistakenly classifying valid outbounds as missing. This false positive triggered the protocol’s internal theft-detection mechanisms.

A subsequent bug targeted a low-liquidity ARB.LINK pool and its asset valuation math. Barbosa noted that the subsidy calculation lacked a cap proportional to the actual depth of the pool, generating about 49.45 million units of CACAO in artificial accounting value.

Another execution flaw occurred when a state change was committed to the pool before a module transfer could finish. Barbosa noted that because the reserve only held about 168,000 CACAO, the funding attempt failed. Although the handler logged the error, it proceeded without reversing the earlier state modification.

The attacker then contributed a tiny amount of liquidity to the artificially inflated pool, achieving a 99.93% ownership stake before withdrawing 48.87 million CACAO. A portion of these tokens was subsequently swapped for external assets.

Crypto Hack News: CACAO Crash Deepened Pool Losses

During the incident, Barbosa observed CACAO plummet from approximately $0.115 down to $0.013—an 88.7% drop occurring in fewer than 240 blocks. This rapid repricing heavily exacerbated losses across liquidity pools pairing CACAO with other cryptocurrencies.

CoinGecko metrics later indicated that CACAO recovered to trade near $0.123 on August 19, suggesting a rebound from its exploit-driven low. However, thin liquidity and suspended trading made direct comparisons across trading venues difficult during the halt.

CoinDesk’s preliminary reporting placed the broader drop in pool values at roughly $10.9 million. Because that figure incorporated arbitrage and CACAO repricing consequences, it did not represent funds directly pocketed by the hacker.

This distinction also prevents direct parallels with standard crypto scam loss figures. Exploit accounting often amalgamates stolen capital, unrecovered protocol balances, and secondary market volatility, each of which measures a completely different tier of damage.

Crypto Hack News: Recovery Work and Next Network Step

Aalux confirmed that Maya intends to patch the flawed codebase and pursue recovery options, reiterating that the network shutdown remained an active part of the response strategy. No definitive timeline for restarting the network had been provided in the cited updates.

Maya’s documentation highlights network solvency and security checks as foundational protocol features. This exploit demonstrated that even robust safeguards can fail when multiple edge cases align simultaneously, a dynamic highlighted in the preliminary reviews.

Barbosa added that the specific attack vector utilized here was not applicable to THORChain. His assessment was limited to the exact bug sequence identified in Maya’s preliminary audit and did not guarantee the absolute absence of unrelated vulnerabilities.

Going forward, key milestones for the protocol include an official network restart or the release of a technical patch, alongside any final accounting updates from the team detailing recovered funds and remaining protocol liabilities.

The post Crypto Hack News: Maya Protocol Loses $1.7M in Six-Bug Attack appeared first on The Coin Republic.

Related stories

Comments 0 responses

Join the discussion

Comments are moderated and appear after review.