Maya Protocol, a Cosmos SDK-based liquidity network, has suspended all operations after an attacker exploited six separate software vulnerabilities to drain roughly $1.7 million in Bitcoin and other assets from the platform. The protocol's native token, CACAO, saw its price collapse by 88.7% in a single day, falling from approximately $0.115 to as low as $0.013 before staging a partial recovery. The attacker manipulated the protocol's liquidity pool accounting, generating an artificial payout of roughly 49 million CACAO tokens, which were then used to extract around 20.83 BTC and additional assets.
Exploit Details
According to Maya Protocol's pseudonymous co-founder Aalux, the exploit involved chaining together six distinct software flaws, allowing the attacker to inflate the recorded balance of a pool and generate the artificial payout. The team moved immediately to halt all activity on the MAYAChain network to prevent further losses while the investigation proceeded.
Broader Impact
The direct theft totaled roughly $1.7 million, but the broader damage to liquidity pools, amplified by the market reaction and CACAO's collapse, pushed total losses across the protocol to an estimated $11 million in value. The incident highlights the risks associated with cross-chain systems, which must track balances across multiple independent ledgers simultaneously.



