Maya Protocol Hack
What happened
Maya Protocol halted MAYAChain after a chained accounting exploit let an attacker drain about $1.7 million in bitcoin and other assets. A technical reconstruction found that an overwritten observed-transaction record caused a false theft condition; an uncapped compensation calculation then credited a thin pool with unfunded CACAO. The attacker acquired near-total ownership of the distorted pool and exchanged its inflated CACAO for real assets.
How it happened
- A batched deposit overwrote the shared observed-transaction record used for earlier actions, causing MAYAChain to treat a legitimate outbound transfer as missing.
- The false theft condition invoked a compensation path that credited roughly 49 million CACAO to a thin pool despite the reserve holding only about 168,000 CACAO.
- The funding transfer failed, but the inflated pool balance remained in state rather than being rolled back.
- The attacker added a small amount of liquidity, gained more than 99% of the distorted pool, withdrew 48.87 million CACAO, and swapped it for bitcoin and other assets.
- MAYAChain halted trading while the project investigated and worked on a fix.
Protocol details
Security review history
- Halborn View report
Evidence
- report @PeckShieldAlert incident report x.com
- report @coinminutesvn incident report x.com
- analysis DeFiLlama defillama.com
- analysis Maya Protocol exploit drains bitcoin and other assets as pool value drops by $11 million coindesk.com
- analysis MAYAChain $1.7M Slash Subsidy Pool Inflation Exploit (Explained) quillaudits.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.