Maya Protocol Hacked for $1.7M — CACAO Token Plunges 88%

Kitto

@kitto

The cross-chain liquidity protocol Maya Protocol has suffered a exploit involving a chain of six software bugs, resulting in the theft of approximately $1.7 million in assets. As a result of the attack, the native token CACAO saw its price plummet by over 88%, and the total pool value evaporated by about $11 million due to arbitrage and token depreciation. All swap functions on the protocol are currently suspended.

According to analyses by security firms PeckShield and DeFIemon, the attacker exploited a vulnerability in the deposit handler via a single deposit message. This triggered a malfunction in the outbound matching system, causing a critical error that distributed tens of millions of CACAO in subsidies to a specific pool. The attacker then seized the funds from the Asgard module. It has been confirmed that about 20 BTC of the stolen funds remain frozen in the attacker's wallet.

This incident marks the 16th cross-chain security breach in August alone. As a project that started as a fork of THORChain and built its own cross-chain liquidity, this chain of bugs is a painful blow for the Maya Protocol. It serves as a stark reminder that in complex cross-chain infrastructure, a single design error can lead to the collapse of entire liquidity pools. We will have to watch how the development team resolves this vulnerability and works to restore the network.


Related Links

No comments yet.