Six bugs in a row: how MAYAChain lost 20 BTC and $10.9 million in pool value

six bugs in a row how mayachain lost 20 btc and 10 9 million in pool value An attacker's wallet ended up holding 20.83 bitcoin pulled out of MAYAChain's pools, worth roughly $1.34 million. It is also the smallest number in this story.

An attacker’s wallet ended up holding 20.83 bitcoin pulled out of MAYAChain’s pools, worth roughly $1.34 million. It is also the smallest number in this story.

The larger one is $10.9 million, approximately the amount by which the value of MAYAChain’s liquidity pools fell during the incident. Those two figures measure different things, and the distance between them is the most instructive part of what happened.

Maya Protocol, the cross-chain liquidity protocol behind the network, halted MAYAChain after a sequence of software bugs produced a phantom balance in one of its pools. Writing on X, founder @AaluxxMyth put the losses at 20 BTC ($1.4 million) plus roughly $300,000 in other assets. Trading was suspended. A fix is in progress before swaps resume.

“Sad news 😕 Will work to fix and recover in full. We carry on. @Maya_Protocol” the founder said.

The compensation code did the damage

A technical reconstruction of the attack tallied six bugs that had to work in concert. Not one catastrophic flaw. Six, in sequence.

The chain began when MAYAChain concluded that an outgoing transaction had gone missing. That conclusion invoked code written for one narrow situation: compensating a liquidity pool after a theft. A pool is the stock of crypto that makes trades possible, and the safeguard exists to top it back up.

The mechanism got the compensation math wrong. It credited roughly 49 million CACAO to a small pool. MAYAChain’s reserve held about 168,000 CACAO. There was never any way to fund that payment.

The transfer therefore failed, which should have closed the matter. But a second bug had already committed the new balance to the network’s records. Rather than unwinding the change once the payment fell through, MAYAChain carried on as though the pool genuinely held the extra tokens.

A tiny deposit bought 99% of a pool

This is the point at which things got cheap for the attacker. They put a small amount into the distorted pool and walked away owning more than 99% of it.

Then came the withdrawal: 48.87 million CACAO, promptly swapped for bitcoin, ether and whatever else was parked in MAYAChain’s other pools.

Onchain records show the 20.83 BTC, worth about $1.34 million, moving to the attacker’s bitcoin address. The analysis pegged assets moved onto outside blockchains at about $1.36 million. A further 8.87 million CACAO remained in the attacker’s MAYAChain wallet, and that is the portion that hasn’t been cashed out.

Counting the tokens still held on-chain, the attacker personally extracted about $1.65 million.

What CACAO did next

Ahead of the exploit the token changed hands near $0.115. It sank as low as $0.013, a decline of nearly 89%, and has since climbed back to around $0.03.

CACAO is the shared asset linking MAYAChain’s markets, the hub token that every pool is paired against. When the attacker sold into the network, the price of that hub collapsed. And a collapsed hub token is an open invitation.

Arbitrage traders behaved exactly as arbitrage traders do. They snapped up the suddenly cheap CACAO and traded it for the bitcoin, ether, stablecoins and other assets still sitting in MAYAChain’s pools. None of that is an exploit. It is a price dislocation being closed by the people who noticed it first.

Why $10.9 million isn’t the theft figure

Take the $10.9 million pool decline apart and the picture shifts. Roughly $6.4 million of it is simply CACAO becoming less valuable. Another $2.9 million came from traders arbitraging the dislocation.

What remains, the attacker’s own take, is only a slice of the headline number. The distinction matters, because “an $11 million hack” and “a $1.65 million theft that triggered an $11 million repricing” describe two different events, and only one of them is what happened.

It matters, too, for anyone doing the mental math on hub-and-spoke designs. Where a single token underwrites every pool on a network, a bug in the accounting for that token will not stay confined to one pool.

The recovery plan, such as it is

MAYAChain said it hopes the attacker will hand the funds back in exchange for a bug bounty. That is the standard opening move, and it succeeds often enough to be worth trying.

The fallback is firmer. The team said it would work on replacing the roughly 20 BTC through investments in Aztec Chain and other means if the funds are not returned.

Note how narrow that commitment is. It covers the 20 BTC. It does not cover the $6.4 million in CACAO devaluation or the $2.9 million that arbitrage traders extracted, and no obvious mechanism exists by which it could.

Fixing the code doesn’t refill the pools

For liquidity providers, this is the uncomfortable part. Patching six bugs restores the software. It does not restore anyone’s deposits.

A large share of the CACAO minted through the exploit was swapped into MAYAChain’s other markets. It now sits mingled with tokens belonging to ordinary liquidity providers, which means untangling who owns what is not a matter of reverting a transaction.

MAYAChain is one of the smaller cross-chain trading networks, the sort that lets you swap bitcoin for ether without routing through a centralized exchange first. That is the whole pitch, and the pitch is a good one. Traders swap against pools of crypto deposited into the network by people who chose to put their assets there.

Those people are now waiting on a bug bounty appeal to an anonymous attacker and a plan involving investments in Aztec Chain.

If you are providing liquidity on a hub-token network, the question worth asking is not whether the code has been audited. It is what becomes of your position when the hub token drops 89% in an afternoon and the arbitrage bots arrive before you do. On MAYAChain, that answer cost $2.9 million.