Maya Protocol Freezes MAYAChain After Six-Bug Pool Inflation; ~$1.7M Drained as CACAO Craters

Maya Protocol halted swaps after a six-bug exploit inflated a pool and siphoned ~$1.7M. CACAO plunged ~89% as liquidity fell ~$10.9M despite prior audits missing issues.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

August 19, 2026

A design gap—not a flashy new attack surface—sidelined MAYAChain on August 19. An attacker chained together six long-dormant bugs to fabricate CACAO balances in a low-liquidity pool, seize near-total control, and exit with Bitcoin and other assets. The maneuver worked because a protection mechanism meant to penalize “theft” could be gamed without limits.

According to the team’s post-mortem, a single MsgDeposit transaction with 23 messages triggered a false theft event and unlocked an uncapped slash subsidy. That subsidy inflated the pool by 49.45 million CACAO, after which the attacker briefly added liquidity, captured 99.93% of the pool, and withdrew 48.87 million CACAO. By swapping into BTC and other assets, they realized roughly $1.65 million in value—about $1.36 million bridged out to external chains and approximately $291,000 left on-chain. Maya later highlighted a Bitcoin address receiving 20.83 BTC—near $1.34 million at the time.

Maya Protocol paused operations to contain the damage and pledged to patch before resuming swaps. The founder acknowledged an estimated 20 BTC (~$1.4 million) plus ~$300,000 in other assets were taken. As the attacker exited into harder assets, CACAO sold off sharply; the token fell nearly 89% and MAYAChain’s total liquidity value slid by roughly $10.9 million. Paradoxically, that collapse limited the final haul: once the pool’s native unit reprices, the exploiter’s marginal extraction falls.

Here’s the part worth dwelling on: the exploit did not rely on obscure cryptography or exotic cross-chain relays. It abused accounting invariants—specifically, unbounded subsidy logic—inside a permissionless AMM. When a system’s internal “safety” mint can be provoked to subsidize balances without a hard cap or time-lock, a determined actor can manufacture inventory and then arbitrage it out. Many teams audit complex modules and miss the trivial seams: integer caps, message ordering, and state assumptions around edge-case alerts like “theft.” Maya admitted the bugs lived in code for three to four years despite audits by Halborn and Fable 5, and said they intend to adopt a more adversarial posture focused on “extremely simple code primitives.”

The human layer matters too. In crises, users often stampede for hard collateral, amplifying slippage and turning accounting mistakes into price cascades. The attacker leaned into that reflex: dump the inflated asset, capture BTC, and let market mechanics do the rest. Once trust in a pool’s internal math flickers, liquidity providers tend to pull capital or demand steep risk premiums, which can prolong recovery even after a fix ships.

Operationally, Maya took a familiar path: halt, diagnose, request a white-hat return, and outline a restitution backstop. The team said it will seek the funds’ return in exchange for a bug bounty. Failing that, they plan to recover roughly 20 BTC via investments in Aztec Chain and “other means” and return it to the affected pool. Publishing the suspected BTC address applies pressure, but it also signals a willingness to negotiate—a tradeoff many DeFi teams now consider pragmatic.

Notably, the project did not speculate on whether AI assisted the attack. The sophistication here arguably lay in patience and composability: combining six modest bugs, a crafted 23-message deposit, and an economic lever that few scrutinize until stress hits. It’s the sort of exploit that slips through standard audit scopes and reminds teams to pair formal verification and fuzzing with runtime circuit breakers—caps on subsidies, rate limits on pool composition changes, and monitors that flag sudden dominance shifts like a jump to 99% LP share.

Context suggests this isn’t an isolated stress test. Recent months saw a $292 million drain from a cross-chain bridge tied to KelpDAO after social engineering compromised session keys; roughly $18 million lost at Arbitrum-based Ostium via a compromised oracle signer and price feed manipulation; and about $24 million siphoned from an AFX Trade USDC bridge. Different vectors, same lesson: key management, oracle assumptions, and accounting “safety” modules fail in surprisingly ordinary ways.

Maya Protocol’s core value proposition—non-custodial swaps between assets like Bitcoin and Ethereum—still resonates. But cross-chain liquidity only scales if the economic invariants are as hardened as the cryptography. Capping subsidies, bounding message effects per block, and treating low-liquidity pools as privileged risk zones would go a long way. The market will watch how quickly those controls land—and whether CACAO’s liquidity recovers—before trusting MAYAChain’s math again.