Maya Protocol shut down its cross-chain community on Wednesday after an attacker drained roughly $1.7 million from the cross-chain platform utilizing a series of six software program bugs. Pseudonymous co-founder Aalux shared on X that the attacker walked away with about 20 Bitcoin, value near $1.4 million, plus one other $300,000 in extra belongings. The workforce activated a worldwide halt inside hours to cease the bleeding and has since began constructing a repair so swaps can resume.
How the Attacker Chained Six Bugs to Drain the Asgard Module
In keeping with a preliminary technical evaluation shared by Aalux, the attacker didn’t depend on one flaw. They chained collectively six separate bugs touching Maya’s commerce accounts, its outbound transaction system, and the way it calculates liquidity pool values. All of it occurred inside a single transaction full of 23 messages.
The attacker first tripped Maya’s theft-detection system in a manner that allow the exploit slip via undetected. From there, they focused a pool with skinny liquidity and artificially inflated its worth. That transfer allow them to pull 48.87 million CACAO tokens out of Maya’s Asgard module, the a part of the protocol that holds belongings used to settle cross-chain swaps.
Maya Protocol exists to let customers commerce native belongings throughout completely different blockchains with out going via a centralized alternate, which makes these vault and accounting programs the spine of your entire community.
Impartial blockchain safety researcher Vini Barbosa reviewed the findings and famous the worth injury on the token itself. CACAO fell 88.7%, dropping from roughly $0.115 to $0.013 in the course of the assault. Barbosa’s evaluation additionally pointed to a wider $10.9 million drop in pool worth, although it famous that determine blends in arbitrage exercise and CACAO’s personal value collapse reasonably than reflecting funds the attacker really took.
What This Means for Maya Protocol Customers
For those who maintain funds on Maya or have an open place via the protocol, swaps are at present paused whereas the workforce works via the repair. The preliminary accounting places about $1.36 million as already moved to exterior blockchains, which means it’s successfully gone for now, whereas roughly $291,000 stays tied up within the attacker’s CACAO holdings and trade-account positions on MAYAChain.
Anybody following altcoin tasks constructed round cross-chain liquidity ought to watch how Maya’s Asgard vault design will get patched, since liquidity-pool accounting bugs aren’t distinctive to Maya. In a separate however related state of affairs previously, the Balancer exploit drained that unrelated DeFi protocol via its personal rounding-logic flaw and ultimately pressured it to restructure.
You possibly can examine our altcoin information hub for ongoing protection of how DeFi protocols deal with safety incidents like this one.
The Repair Maya Protocol Nonetheless Must Ship
Aalux stated the worldwide halt contained the injury and gave builders room to analyze the affected elements. No timeline has been given but for when swaps will resume, and the protocol has not stated whether or not the six chained bugs have all been patched or whether or not some fixes are nonetheless in progress.
What this implies for you: If a cross-chain swap or DeFi protocol you employ will get exploited, search for an official assertion from the workforce earlier than assuming your funds are affected, since incidents like this one usually hit particular swimming pools or modules reasonably than your entire platform.
This text is for informational functions solely and doesn’t represent monetary recommendation. Do your individual analysis earlier than making any funding selections.
