Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,674.37▲ 2.20%NASDAQ26,180.46▲ 1.33%DOW53,277.01▲ 2.02%GOLD4,694.90▲ 15.42%WTI85.68▼ 4.06%BRENT93.18▼ 3.72%EUR/USD1.1682▲ 2.68%USD/JPY158.88▼ 3.02%DXY98.85▼ 2.59%BTC$77,300▲ 1.73%ETH$2,453▲ 3.34%SOL$94.23▲ 2.25%TOTAL CRYPTO$2.61T▼ 0.99%

Maya Protocol Exploit Leaves $11M in Pool Damage Unresolved

Suspected attacker still holds 20.83 BTC three days after exploiting six chained accounting flaws in Maya Protocol, with wider pool repricing damage estimated at $10.9 million

Partner Surfshark VPN

A suspected Bitcoin address at the center of Maya Protocol’s August 18 exploit still held about 20.83 BTC with no outgoing transactions as of August 21, while the cross-chain liquidity protocol has yet to detail who absorbs the far larger estimated damage across its pools.

The exploit drained an initial $1.36 million in assets, but a technical reconstruction by security researcher SigIntZero estimated the broader impact at approximately $10.9 million when accounting for repricing and arbitrage damage across Maya’s liquidity pools. The suspected address received ten initial deposits totaling 20.827 BTC at 17:32 UTC on August 18 and has spent nothing since.

Six Chained Flaws in One Transaction

SigIntZero attributed the exploit to six accounting and state-handling flaws chained inside a single 23-message transaction. The attack overwritten outbound transfer state, producing a false missing-transfer signal that activated a compensation path. This credited roughly 49.45 million CACAO tokens to a thin ARB.LINK pool, even though Maya’s reserve held only about 168,000 CACAO at the time.

The reserve transfer ultimately failed, but the inflated balance persisted on-chain. After adding negligible liquidity, the attacker received approximately 99.93% of the pool’s ownership units and withdrew roughly 48.87 million CACAO before swapping into assets held by other MAYAChain pools.

Founder Pledges Full Recovery

Maya Protocol founder Aaluxx initially said the network had likely lost about 20 BTC, worth roughly $1.4 million at the time, plus about $300,000 in other assets. He said he would work to fix the incident and recover in full.

According to CryptoSlate, Maya reportedly hopes for a bug-bounty return of the stolen funds. Failing that, the protocol could seek to replace roughly 20 BTC through Aztec Chain investments and other means. Even if that Bitcoin is returned or replaced, it would cover only a fraction of the estimated $10.9 million in wider pool damage.

The exploit highlights a persistent vulnerability in cross-chain DeFi protocols, where complex state management and automated compensation mechanisms can be chained together to amplify losses far beyond the initially stolen amount. Similar architectural patterns have been exploited in previous bridge and liquidity pool incidents across the broader DeFi ecosystem.

The Maya Protocol team has not published a detailed post-mortem or recovery timeline. Liquidity providers in affected pools face ongoing uncertainty as the protocol works through potential resolution paths, with no concrete plan yet announced for compensating the broader pool damage beyond the direct theft.

SourcesCryptoSlate; SigIntZero technical analysis; mempool.space on-chain data
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Bitcoin Tumbles as Market Maker Short Triggers Liquidations Read →