Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million
The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.