MAYA Protocol halted its network after it was targeted by a security exploit estimated to have caused losses of about $1.7 million, an incident that once again highlighted the risks associated with multi-chain infrastructures and complex liquidity management systems.
The unidentified co-founder Aalux said the attacker took around 20 Bitcoin worth approximately $1.4 million, as well as an additional $300,000 in assets. He added that the protocol activated a network-wide shutdown to contain the damage and began working on a fix that will allow swap operations to resume later.
How did the exploitation happen?
According to an initial technical analysis published after the incident, the attack relied on six consecutive vulnerabilities involving trading accounts, handling outgoing transactions, and liquidity pool accounting. The attacker used a single transaction containing 23 messages to trigger a false theft alert, then artificially inflated a low-liquidity pool before withdrawing 48.87 million CACAO from Asgard, a unit of MAYAChain.
The report noted that about $1.36 million was moved to external blockchain networks, while the attacker retained approximately $291,000 worth of CACAO and trading positions linked to accounts on MAYAChain.
What does that mean for CACAO holders?
Independent security researcher Vini Barbosa reported that the price of CACAO fell by 88.7% during the incident, from about $0.115 to $0.013. This sharp drop reflects the magnitude of the shock that hit the market after the network stopped and confidence in its operating mechanisms declined.
The analysis also estimated a broader decrease in the value of the pools of about $10.9 million, but it clarified that this figure does not represent assets fully stolen by the attacker; it also includes arbitrage activity and the decline in the value of CACAO itself during the crisis.
For users, stopping the network effectively means a temporary freeze of operations until the investigation is completed and the necessary updates are issued. In such cases, the next steps typically focus on analyzing the path of the funds, patching the vulnerabilities, and assessing the incident’s impact on liquidity and open positions before the network is reopened.
The incident also highlights how a chain of small coding errors can turn into a major loss when they intersect with shallow liquidity pools and complex verification mechanisms—making a review of the security architecture a top priority before resuming full activity.
#أمن_سيبراني #بلوكتشين $BTC $CACAO
