A suspected Bitcoin address at the center of Maya Protocol’s August 18 exploit still held about 20.83 BTC with no outgoing transactions as of August 21, while the cross-chain liquidity protocol has yet to detail who absorbs the far larger estimated damage across its pools.
The exploit drained an initial $1.36 million in assets, but a technical reconstruction by security researcher SigIntZero estimated the broader impact at approximately $10.9 million when accounting for repricing and arbitrage damage across Maya’s liquidity pools. The suspected address received ten initial deposits totaling 20.827 BTC at 17:32 UTC on August 18 and has spent nothing since.
Six Chained Flaws in One Transaction
SigIntZero attributed the exploit to six accounting and state-handling flaws chained inside a single 23-message transaction. The attack overwritten outbound transfer state, producing a false missing-transfer signal that activated a compensation path. This credited roughly 49.45 million CACAO tokens to a thin ARB.LINK pool, even though Maya’s reserve held only about 168,000 CACAO at the time.
The reserve transfer ultimately failed, but the inflated balance persisted on-chain. After adding negligible liquidity, the attacker received approximately 99.93% of the pool’s ownership units and withdrew roughly 48.87 million CACAO before swapping into assets held by other MAYAChain pools.
Founder Pledges Full Recovery
Maya Protocol founder Aaluxx initially said the network had likely lost about 20 BTC, worth roughly $1.4 million at the time, plus about $300,000 in other assets. He said he would work to fix the incident and recover in full.
According to CryptoSlate, Maya reportedly hopes for a bug-bounty return of the stolen funds. Failing that, the protocol could seek to replace roughly 20 BTC through Aztec Chain investments and other means. Even if that Bitcoin is returned or replaced, it would cover only a fraction of the estimated $10.9 million in wider pool damage.
The exploit highlights a persistent vulnerability in cross-chain DeFi protocols, where complex state management and automated compensation mechanisms can be chained together to amplify losses far beyond the initially stolen amount. Similar architectural patterns have been exploited in previous bridge and liquidity pool incidents across the broader DeFi ecosystem.
The Maya Protocol team has not published a detailed post-mortem or recovery timeline. Liquidity providers in affected pools face ongoing uncertainty as the protocol works through potential resolution paths, with no concrete plan yet announced for compensating the broader pool damage beyond the direct theft.
discussion