Advertisement

Maya Protocol Exploit Drains $1.7 Million From Shared Liquidity

Founder Aaluxx said he would ‘work to fix and recover in full,’ while routing service LeoDex reported that Maya had activated a global halt.
Maya Protocol Exploit Drains $1.7 Million From Shared Liquidity

Maya Protocol was exploited for roughly $1.7 million after an attacker inflated accounting with a false subsidy, then added and removed liquidity to extract about 48.87 million CACAO and 98.82 LINK, according to blockchain security firm CertiK.

CertiK said the assets came from shared liquidity.

In a separate, third-party analysis, RedStone co-founder Marcin Kazmierczak described six bugs acting in sequence. He wrote that an outbound transaction was wrongly marked as missing, triggering a compensation routine that credited a pool with 49 million CACAO despite reserves of 168,000 CACAO. The transfer failed but the phantom balance remained, he said, after which the attacker deposited a small amount and took 99% of the pool.

MAYAChain is a decentralized cross-chain liquidity protocol that lets users contribute liquidity and swap across it without pegging or wrapping assets. Its official documentation says the network observes transactions sent to vaults on supported blockchains and coordinates the corresponding action.

LeoDex, a third-party routing service, reported that Maya’s team had activated a global halt. LeoDex said its own team would monitor the protocol and turn routes back on later.

Maya Protocol founder Aaluxx said the team would “work to fix and recover in full,” adding: “We carry on.”

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.