Login
Sign Up
Woofun AI reports that a sophisticated exploit on MAYAChain resulted in the extraction of approximately $1.36 million in hard assets, a breach that cascaded into nearly $11 million in total liquidity pool damage due to a critical accounting glitch involving the CACAO token. The incident, detailed by security researcher Barbosa, exposed structural vulnerabilities in Maya Protocol's cross-chain liquidity network, where the failure of one pool's accounting logic propagated through the entire system's value recording mechanisms.
The financial discrepancy between the direct theft and the total system impact highlights the severity of the exploit's secondary effects. While the attacker successfully moved roughly $1.36 million in external assets, including approximately 20.83 BTC, the broader damage estimate of $11 million captures the cascading failure within the network's liquidity pools. This larger figure is not merely a reflection of stolen funds but represents the compounded loss from false accounting entries that created an artificial, massive CACAO balance. The divergence between the $1.36 million in hard assets removed and the $11 million in total pool damage underscores how a localized theft can trigger systemic devaluation across interconnected markets.
The mechanism behind this false accounting involved the creation of a huge CACAO balance that became withdrawable despite lacking underlying reserve support. This artificial inflation allowed the attacker to manipulate the pool's state, leading to a subsequent repricing of CACAO that devastated the network's remaining liquidity. The core issue was that an accounting entry, which the reserve could never fund, was transformed into a valid liquidity position. This structural flaw meant that the value recorded in the pool did not correspond to actual assets, enabling the attacker to leverage the distorted balance against the rest of the network's markets.
The technical trigger for this cascade was a 'wrong height' error that caused MAYAChain to misclassify legitimate outbound transfers as missing transactions. This misclassification activated the protocol's theft-detection logic, which is designed to compensate a pool after a missing transfer is identified.
However, instead of preventing loss, this logic initiated a compensation path that calculated a subsidy for a near-empty ARB pool without bounding the amount to the pool's actual depth. The system's failure to validate the subsidy against available reserves allowed the exploit to proceed unchecked.
Woofun AI data shows. The subsidy calculation failure was particularly severe in the ARB pool, where the system recorded roughly 49.45 million CACAO of value despite the reserve holding only about 168,000 CACAO. This massive discrepancy occurred because the reserve lacked enough tokens to complete the module transfer, yet the new pool state had already been committed to the ledger. According to Barbosa, the handler continued processing after the failed transfer, leaving the inflated balance in place. This error effectively created a liability far exceeding the asset base, setting the stage for the attacker's extraction.
The attacker executed the final phase of the exploit by adding a negligible amount of liquidity to the distorted pool, thereby receiving about 99.93% of its ownership units. This dominant position enabled the withdrawal of roughly 48.87 million CACAO, a sum that was entirely unsupported by the actual reserves. The sequence of events—from the overwritten height producing false theft detection to the excessive subsidy surviving in pool records—demonstrates how a single point of failure can be leveraged to claim ownership of non-existent assets. The recorded balance thus supported a liquidity claim that was mathematically impossible under normal operating conditions.
The immediate market reaction was a catastrophic collapse in the CACAO token price, which fell from about $0.115 to $0.013 during the incident, representing an 88.7% drop. Since CACAO represents one side of MAYAChain's paired liquidity pools, this sharp decline in dollar value reduced the measured worth of CACAO inventory across the entire system, even for tokens that remained inside pools. The exploit-created balance and trades executed against distorted pool prices added another layer of impact, as the devaluation of CACAO directly eroded the value of other assets paired with it in the liquidity pools.
Recovery complexity is further compounded by the lack of a final ledger as of Aug. 20, which would divide the total damage among hard-asset extraction, CACAO repricing, and trading losses. The original attacker's external haul and the value lost across the pools are separate measures, with one following assets sent out of MAYAChain and the other capturing how an accounting failure changed the value and composition of remaining liquidity. Maya has yet to publish a confirmed restart time, deployed patch version, or final pool calculation, leaving the exact dollar allocation for each category pending. This ambiguity makes it difficult to determine the precise scope of the loss for each participant.
For liquidity providers, the distinction between these loss categories determines what recovery would require, as replacing 20.83 BTC would restore only one set of assets. A full recovery has at least three parts: returning or replacing hard assets, repairing pool balances, and defining how the remaining impact is allocated among liquidity providers and other participants. By Aug. 20, Maya's public channels had yet to supply the liquidity-provider compensation scope needed to turn the recovery promise into a defined settlement. Unlike THORChain, which does not appear to carry the same complete path of vulnerabilities, MAYAChain's loss multiplier is as much an accounting and market structure story as a theft story. The decisive update will be Maya's definition of 'full': which assets return, how pool balances are rebuilt, and who absorbs the value changes and trades that recovery cannot simply rewind.