Key Insights Crypto hack news: Maya Protocol halted after a $1.7 million exploit. Attacker withdrew 48.87 million CACAO after manipulating pool accounting. CACAO fell 88.7% as arbitrage deepe
Key Insights
- Crypto hack news: Maya Protocol halted after a $1.7 million exploit.
- Attacker withdrew 48.87 million CACAO after manipulating pool accounting.
- CACAO fell 88.7% as arbitrage deepened broader pool-value losses.
Maya Protocol halted MAYAChain on Aug. 18 after an attacker exploited six linked software flaws. The crypto hack news event caused about $1.7 million in attacker-controlled losses. Maya co-founder Aalux said the team contained further damage and began recovery work.
The incident mattered because one transaction exploited several accounting and execution weaknesses together. The attacker converted manipulated protocol balances into Bitcoin, Ether, RUNE and stablecoins. The case also differed from a crypto scam because software flaws, not user deception, drove losses.
Crypto Hack News: MAYAChain Halts After Six-Bug Exploit
Maya co-founder Aalux said the attacker took about 20 Bitcoin and another $300,000 in assets. He said Maya implemented a global halt after detecting the exploit. The team then started preparing fixes before restoring swaps.

Maya Protocol Crypto Hack News | Source. X
CertiK Alert separately estimated losses near $1.7 million. Its assessment placed the incident among decentralized finance exploits rather than phishing or wallet compromise. That distinction matters because the attack targeted protocol logic and pool accounting.
Independent security researcher Vini Barbosa said six bugs formed the exploit chain. His review said one transaction contained 23 messages and triggered most activity. The sequence affected trade accounts, outbound transaction handling and liquidity-pool calculations.
Barbosa said the attacker extracted about $1.36 million to external blockchains. He estimated total protocol impact near $11 million after market effects. That broader figure included arbitrage activity and CACAO depreciation, not only stolen assets.
How the Exploit Manipulated Pool Accounting
Barbosa’s technical summary said batched deposit messages overwrote an ObservedTxVoter record. The final donation message replaced earlier voter data and reset the outbound height. That altered how MAYAChain evaluated later outbound transactions.
The outbound matcher then used an incorrect height when checking legitimate transfers. Barbosa said the system classified real outbounds as missing. That false result activated theft-detection logic inside the protocol.
The next bug involved a low-liquidity ARB.LINK pool and its valuation calculation. Barbosa said the subsidy calculation lacked a cap tied to actual pool depth. That calculation created roughly 49.45 million CACAO in accounting value.
Another execution flaw was committed in the pool state before a module transfer completed. Barbosa said the reserve held only about 168,000 CACAO, so funding failed. The handler logged the error but continued without reversing the earlier state update.
The attacker then added negligible liquidity to the inflated pool. Barbosa said that position gained 99.93% ownership before the attacker withdrew 48.87 million CACAO. The attacker later converted part of those tokens into external assets.
Crypto Hack News: CACAO Crash Deepened Pool Losses
Barbosa tracked CACAO falling from about $0.115 to $0.013 during the incident. That represented an 88.7% decline within fewer than 240 blocks. The sharp repricing amplified losses across pools holding CACAO against other assets.
CoinGecko data later showed CACAO near $0.123 on Aug. 19. The price data indicated a recovery from the reported exploit low. Thin liquidity and disrupted trading complicated direct comparisons across venues during the halt.
The broader pool-value decline reached about $10.9 million, CoinDesk reported from the preliminary analysis. That number included arbitrage and CACAO repricing effects. It therefore did not represent assets directly controlled by the attacker.
The distinction also limits comparisons with a conventional crypto scam loss estimate. Exploit accounting can include stolen assets, unrecovered protocol balances, and secondary market effects. Those categories measure different forms of damage.
Crypto Hack News: Recovery Work and Next Network Step
Aalux said Maya would work toward fixing the affected code and recovering losses. His public statement also confirmed the network halt remained part of the response. Maya had not published a verified restart time in the cited update.
Maya documentation describes network solvency and security controls as core protocol functions. The exploit showed that interacting safeguards could still fail when several edge cases aligned. The preliminary review focused on those combined execution paths.
Barbosa said the same attack vector was not currently possible on THORChain. That assessment concerned the specific bug sequence described in Maya’s preliminary review. It did not establish that unrelated vulnerabilities were absent.
The next verifiable development is Maya’s network restart or a technical patch announcement. Traders can also watch whether the team publishes final loss accounting. Those updates should clarify recovered assets and remaining protocol liabilities.
The post Crypto Hack News: Maya Protocol Loses $1.7M in Six-Bug Attack appeared first on The Coin Republic.