Maya Protocol Stops After Exploit Hits $11 Million in Pools
MAYAChain’s cross-chain pools were disrupted by six software bugs; along with bitcoin and Ether, the CACAO price also played a big role in the damage.

Key Takeaways
- Maya Protocol shut down MAYAChain after an exploit in which software bugs created a fake balance in a liquidity pool.
- The attacker stole about 20 BTC and other assets; total damage in the pools came to about $11 million.
- The team is working on a fix and wants to resume swaps only after the security issues are resolved.
Cross-chain liquidity protocol Maya Protocol has shut down its MAYAChain network after a series of software bugs created a fake balance in a liquidity pool. That allowed an attacker to siphon off nearly $1.7 million (€1.5 million) in bitcoin and other assets, while total damage in the pools came to about $11 million (€9.5 million).
Founder AaluxxMyth said on X that 20 BTC were stolen, worth about $1.4 million (€1.2 million), plus another roughly $300,000 (€259,200) in other assets. According to the team, trading has been halted to limit the damage, and a fix is being worked on before swaps resume.
How the Attack Worked
MAYAChain is a smaller cross-chain trading network within the broader Maya ecosystem. Users can swap assets like Bitcoin and Ether there without first going through a centralized crypto exchange. The pools are funded with crypto, while CACAO is the shared asset that connects those markets.
A technical reconstruction shows that six bugs had to line up before the attack could succeed. It started when MAYAChain thought an outgoing transaction had disappeared and triggered code meant to compensate a liquidity pool after a theft.
That safety feature, however, calculated the compensation incorrectly. About 49 million CACAO was added to a small pool, while MAYAChain’s reserve held only around 168,000 CACAO and therefore could not cover that payment. The transfer failed, but another bug caused the new balance to already be saved in the network’s records.
Damage Kept Growing
After that, the attacker deposited a small amount into the disrupted pool and ended up controlling more than 99 percent of that pool. Then 48.87 million CACAO was withdrawn directly and converted into Bitcoin, Ether, and other assets in MAYAChain’s pools.
On-chain data shows that 20.83 BTC, worth about $1.34 million (€1.2 million), was sent to the attacker’s bitcoin address. The analysis also confirmed that about $1.36 million (€1.2 million) in assets was moved to external blockchains, while another 8.87 million CACAO remained in the attacker’s MAYAChain wallet.
CACAO itself crashed during the attack. The token was trading around $0.115 (€0.099) before the exploit and fell to a low of $0.013 (€0.011), a drop of nearly 89 percent, before recovering to about $0.03 (€0.026). That caused extra damage, because arbitrage traders bought the suddenly cheap token and swapped it back into Bitcoin, Ether, stablecoins, and other assets from the pools.
Why This Matters
The case shows how vulnerable cross-chain liquidity can be when multiple failures happen at the same time. Maya Protocol, like other cross-chain networks, uses a setup based on the Cosmos SDK and a Threshold Signature Scheme to have transactions signed jointly, but that does not prevent errors in accounting or compensation mechanisms.
For European crypto readers, the key point is that total damage is not the same as the amount stolen directly. Maya Protocol estimates that pool value fell by about $10.9 million (€9.4 million), of which roughly $6.4 million (€5.5 million) was tied to the lower CACAO price and another $2.9 million (€2.5 million) to arbitrage on the price disruptions. The team hopes the attacker will return the funds in exchange for a bug bounty and says otherwise it wants to replace the roughly 20 BTC through investments in Aztec Chain and other means.