EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

MAYAChain software vulnerability causes false balances and may trigger…

2026-08-20 00:23:00
Bookmark

How did the MAYAChain vulnerability incident happen?

The Maya protocol suspended transactions on its MAYAChain network after multiple software vulnerabilities resulted in false balances in a liquidity pool. The attackers extracted nearly $1.7 million, while causing a cumulative loss of approximately $10.9 million in various pools across the network. The attackers obtained about 20 bitcoins (worth about $1.4 million at the time), as well as about $300,000 in other assets. The Maya protocol stopped redemption after detecting the vulnerability and said transactions would remain suspended while developers prepare the fix.

MAYAChain allows users to exchange assets such as Bitcoin and Ethereum across blockchains without having to trade through a centralized exchange. Liquidity providers deposit cryptocurrencies into the pool, while the agreed CACAO tokens serve as common assets connecting different markets. Technical refactoring found that six software vulnerabilities had to interact for the attack to succeed. The chain of failure begins when MAYAChain mistakenly determined that an outgoing transaction was missing and triggered a mechanism designed to compensate for a liquidity pool damaged by a failed transfer. Compensation calculations subsequently credited approximately 49 million CACAOs to a small pool, although there were only approximately 168,000 CACAOs in the agreement reserve and it was simply impossible to pay the amount.

Why does a failed payment create usable tokens?

Due to insufficient CACAO in the reserve, the transfer attempt ended in failure. Under normal circumstances, this should prevent the pool from obtaining a new balance. However, another software flaw meant that the inflated balance was written to MAYAChain's records before the payment failed. The network did not revoke this accounting change, but continued to operate as if the extra CACAO really existed. The attacker then deposited a small amount of liquidity into the distorted pool and gained more than 99% ownership of the pool. The attackers extracted 48.87 million CACAOs and began exchanging these tokens for bitcoins, ether and other assets held in other liquidity pools of MAYAChain.

On-chain activity showed that 20.83 bitcoins worth approximately US$1.34 million were transferred to the attacker's Bitcoin address. The total amount of assets transferred to the external blockchain was approximately US$1.36 million, and another 8.87 million CAOs remained in the attacker's MAYAChain wallet. Therefore, the attack was not just a mere theft from a pool. False CACAO balances create purchasing power within the network, which can be redeemed for real assets provided by liquidity providers.

Investors revealed that

The attackers withdrew approximately US$1.65 million, but the losses of MAYAChain pools went far beyond that. The difference is important because most of the approximately $10.9 million losses came from CACAO price collapse and arbitrage activities, rather than assets stolen directly by attackers.

Why did MAYAChain lose nearly US$11 million?

CACAO prices fell sharply as attackers sold their newly acquired tokens on the MAYAChain market. The token traded at approximately $0.115 before the attack, then fell to $0.013, a drop of nearly 89%, before recovering to approximately $0.03. The price collapse caused losses that exceeded the assets directly taken by the attackers. Carry traders buy CACAO after it becomes abnormally cheap and convert it into Bitcoin, Ethereum, stablecoins and other assets held in the MAYAChain pool.

Technical refactoring estimates that the attacker personally withdrew approximately US$1.65 million, including tokens that remained on the chain. However, the total value of the pools dropped by approximately $10.9 million during the incident. About $6.4 million of this was attributed to the devaluation of CACAO, and another $2.9 million came from traders taking advantage of price differences caused by price chaos. Therefore, treating the entire $10.9 million as stolen funds would exaggerate the amount actually obtained by the attacker. This difference also complicates recovery efforts. Returning the proceeds to the attackers can only repair some of the economic losses, as other assets have been transferred through carry trades and the value of CACAO itself has fallen significantly.

Can the Maya protocol restore liquidity pools?

The Maya protocol said it hopes that attackers can return funds in exchange for a vulnerability bounty. Founder AaluxxMyth said the team will work hard to "fully repair and restore" while developers are investigating the glitch and preparing to resume online transactions. The team also discussed that if the attacker did not return the assets, it would invest in Aztec Chain and other channels to make up for the loss of approximately 20 bitcoins.

However, the fix code does not automatically restore the liquidity provider's balance to its pre-attack state. Most of the CACAO generated through erroneous bookkeeping has been converted into other assets and is now intertwined with ordinary users 'funds. So, the recovery process goes beyond just patching these six software vulnerabilities. The Maya protocol must determine how to rebuild the depleted pool, account for losses caused by arbitrage, and decide how to compensate liquidity providers before normal trading can safely resume.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP