The cross-chain liquidity protocol called Maya Protocol shut down its network, MAYAChain, as a result of multiple bugs in its software leading to the creation of a fake balance in one of its liquidity pools, which let the hacker steal close to $1.7 million (roughly Rs. 16.3 crore) worth of Bitcoin and other cryptocurrencies resulting in a total loss of around $11 million (roughly Rs. 105.3 crore). The anonymous co-founder of Maya Protocol, named “Aalux,” reported having been hacked on X and suffered losses of 20 BTC, which is around $1.4 million (roughly Rs. 13.4 crore), along with $300,000 (roughly Rs. 2.9 crore).
MAYAChain Reviews Exploit After Manipulated Pool Balance Enables Asset Withdrawals
The protocol halted all trading to minimise the impact and noted that it is working on a solution before swaps can be carried out again. MAYAChain is a decentralised trading platform that enables people to swap crypto assets such as Bitcoin and Ethereum without using any centralised exchanges and is part of the Maya ecosystem. It uses the CACAO token as an anchor to the markets through which traders conduct swaps.
The technical analysis showed that six software bugs were involved in this attack, all of which were necessary to exploit the vulnerability. This process started when MAYAChain mistakenly thought that the outgoing transaction was lost and executed the code aimed at compensating a liquidity pool that had been robbed. However, the safety measure failed to make the right calculation. The mechanism added about 49 million CACAO to the smaller pool despite the fact that there were only 168,000 CACAO in the reserve of MAYAChain.
The transaction was not executed, but a different flaw had caused the updated balance to be already saved in the network’s records. Rather than undoing the update due to the failed transaction, MAYAChain proceeded to operate assuming the pool had indeed received the additional tokens. The attacker then deposited a small amount into this rigged pool and owned over 99 percent of the pool. Immediately after this, 48.87 million CACAO was withdrawn by this person, and they began exchanging these tokens with the help of MAYAChain’s pools for Bitcoins and Ethers.
The protocol also said that it is looking forward to getting back its lost money through a bug bounty from the attacker. If not, it promised to make sure that roughly 20 BTC is replaced through investments in Aztec Chain and other means if the funds are not returned. Fixing the bug alone will not return the pools to their former condition. Most of the CACAO that was mined via the vulnerability is now in different MAYAChain markets, where it mixes with other tokens.
The second quarter of 2026 is already the most hacked quarter on record in terms of the number of attacks, with 83 hacks of crypto protocols, per an analysis from market insights provider Unfolded based on data from DefiLlama. KelpDAO’s $293 million (roughly Rs. 2,805 crore) hack and Drift Protocol’s $280 million (roughly Rs. 2,681 crore) exploit were the largest incidents of the quarter.
