Crypto
Home›Crypto›Market Structure›MAYAChain exploit expands pool damage after false acco…
MAYAChain exploit expands pool damage after false accounting
The attacker moved about $1.36 million in hard assets off external chains, while the liquidity pools saw an estimated impact approaching $11 million as CACAO collapsed.
MAYAChain, a cross-chain liquidity network run by Maya Protocol, faced an exploit in which an attacker moved about $1.36 million in hard assets to external chains, while the estimated impact across the network's liquidity pools approached $11 million.
CryptoSlate reported that the damage stemmed from a chain-reaction inside the pools. False accounting created a large CACAO balance, the inflated balance became withdrawable, and CACAO's subsequent collapse repriced the network's remaining liquidity.
The underlying issue was traced by independent researcher Vini Barbosa to a MsgDeposit transaction with 23 messages. In his reconstruction, a final DONATE message overwrote earlier state, including the outbound height used to match transactions, causing legitimate outbound transfers to be misclassified as missing.
According to the reconstruction, the misclassified transfers triggered theft-detection compensation logic that calculated an excessive subsidy for a near-empty ARB pool. The reserve held only about 168,000 CACAO, but the module recorded roughly 49.45 million CACAO, enabling the attacker to add negligible liquidity, take about 99.93% of pool ownership units, and withdraw roughly 48.87 million CACAO. As of the Aug. 20 reporting cutoff, MAYAChain's official channels had not yet published a confirmed swap restart, final loss allocation, or comprehensive compensation terms for liquidity providers. Founder Aaluxx said the team aimed to fix the incident and recover in full.