BlockBeats News, August 19th: The cross-chain liquidity protocol Maya Protocol experienced a security vulnerability attack, causing its MAYAChain network to halt transactions due to a series of software bugs.
The attacker exploited six vulnerabilities in combination, leading to network misreporting, artificially inflating a liquidity pool by about 49 million CACAO tokens, while the pool's actual reserve was only about 168,000 CACAO tokens. Subsequently, the attacker used low-cost asset deposits to obtain over 99% share of the pool and withdrew about 48.87 million CACAO tokens, exchanging them for BTC, ETH, and other assets.
On-chain data shows the attacker transferred roughly 20.83 BTC (approximately $1.34 million) and other assets, totaling a direct profit of around $1.65 million, with about 8.87 million CACAO tokens still remaining in the attacker's wallet.
Impacted by the attack, the value of the MAYAChain pool plummeted by approximately $10.9 million. However, analysis indicates that not all of it was stolen assets: around $6.4 million in losses came from the plummeting CACAO price, and about $2.9 million resulted from fund losses due to arbitrage trades.
Following the incident, the CACAO price dropped from around $0.115 to a low of $0.013, marking a nearly 89% decline, before rebounding to approximately $0.03.
The founder of Maya Protocol stated that the team has halted all transactions to contain losses, is working on fixing the vulnerabilities, and hopes the attacker will return the funds through a bug bounty mechanism. If the funds cannot be recovered, the team plans to replenish the loss of about 20 BTC by investing in Aztec Chain and other methods.

