Key Takeaways:
- MAYAChain halted trading after an exploit drained 20.83 BTC and 48.87M CACAO.
- Six software bugs credited a pool with 49M unfunded CACAO tokens.
- CACAO plunged 89% to $0.013, cutting pool value by $10.9 million.
Key Takeaways:

An exploit drained about $1.7 million in bitcoin and other assets from MAYAChain, the Cosmos-based cross-chain trading protocol, on Aug. 19. The attacker withdrew 20.83 BTC worth about $1.4 million plus roughly $300,000 of other assets, AaluxxMyth, co-founder of Maya Protocol, said on X.
Six software bugs worked together to credit a liquidity pool with nearly 50 million CACAO tokens that were never properly funded, letting the attacker drain real assets, according to a technical reconstruction. The chain began when MAYAChain mistakenly decided an outgoing transaction had gone missing and triggered code meant to compensate a liquidity pool after a theft. That safety mechanism calculated the compensation incorrectly, adding roughly 49 million CACAO to a small pool even though the reserve held only about 168,000 CACAO and could not fund the payment.
The transfer failed, but another bug meant the new balance had already been saved in the network's records. Instead of reversing the change, MAYAChain continued operating as though the pool really contained the extra tokens. The attacker then deposited a small amount into the distorted pool, owned more than 99 percent of it, and withdrew 48.87 million CACAO before swapping those tokens for bitcoin, ether and other assets. On-chain records show 20.83 BTC was sent to the attacker's bitcoin address, while another 8.87 million CACAO remained in the attacker's MAYAChain wallet.
CACAO collapsed as the attacker sold into the network. The token traded around $0.115 before the exploit and fell as low as $0.013, a drop of nearly 89 percent, before recovering to around $0.03. The total hit to MAYAChain's pools reached about $10.9 million, though roughly $6.4 million of that reflected CACAO becoming less valuable and another $2.9 million came from traders arbitraging the price dislocation, the reconstruction estimated.
MAYAChain halted all trading to contain the damage and said it is working on a fix before swaps resume. The team said it hopes the attacker will return the funds in exchange for a bug bounty, and would work on replacing the roughly 20 BTC through investments in Aztec Chain if the funds are not returned. The protocol's bug bounty program on Immunefi caps critical vulnerability payouts at $35,000.
The incident is the first major loss-of-funds event for the THORChain fork since its mainnet went live in April 2023, and lands roughly three months after THORChain itself was drained of about $10.8 million on May 15. Blockchain security firm PeckShield flagged the breach, which hit a protocol with roughly $15 million in total value locked, per DeFiLlama data. The exploit heightens scrutiny on cross-chain infrastructure after eight major bridge and cross-chain attacks drained a combined $328.6 million through mid-May, and may weigh on risk appetite for similar protocols.
This article is for informational purposes only and does not constitute investment advice.