Cross-chain liquidity network Maya Protocol halted operations Tuesday after an attacker exploited six software flaws to drain roughly $1.7 million in Bitcoin and other assets.
Myriad: Bitcoin's next move? Click to make your prediction."No way to sugar coat this," Maya wrote in a post. "We have likely been exploited by 20 BTC ($1.4M) and other assets ($300k)."
The exploit tested us. Our response is resilience. We’re focused on actions, solutions, and rebuilding stronger. Behind the scenes, we’re still cooking.
“The attack used a single 23-message MsgDeposit transaction to trigger a false "theft" detection, inflate a low-liquidity pool's CACAO balance via an uncapped slash subsidy, then immediately LP'd into and withdrew from the inflated pool to extract the value,” they wrote.
As the attacker swapped the tokens for Bitcoin and other assets, CACAO’s price collapsed, limiting the amount ultimately extracted. The team estimated the attacker took roughly $1.65 million in crypto assets, including $1.36 million moved to external blockchains and about $291,000 remaining on-chain.
Maya Protocol published the suspected attacker’s Bitcoin address, which received 20.83 BTC worth about $1.34 million. The team estimated roughly $1.65 million was taken in total and said it hopes the funds will be returned in exchange for a bug bounty.
If not, Maya said the team plans to recover the roughly 20 BTC through investments in Aztec Chain and "other means" and return it to the affected pool.


















