MAYAChain’s $1.36 million exploit spiraled into nearly $11 million of pool damage
MAYAChain suffered an $11 million liquidity pool collapse triggered by a single transaction that corrupted its core accounting logic, allowing an attacker to withdraw nearly 49 million CACAO tokens that should never have existed. The incident exposes a critical vulnerability in cross-chain liquidity protocols where a failure in one pool’s state management can cascade across an entire network’s interconnected markets.
- Attacker extracted $1.36 million in hard assets, including roughly 20.83 BTC, to external blockchains.
- False accounting created 49.45 million CACAO tokens despite reserve holding only 168,000 CACAO available.
- CACAO token price collapsed 88.7% from $0.115 to $0.013, triggering systemic repricing across all pools.
- $11 million estimated total impact across MAYAChain’s liquidity pools versus initial exploit value
- 88.7% CACAO price decline during incident versus pre-exploit trading levels
- 49.45 million CACAO tokens created by exploit versus 168,000 CACAO in actual reserve
MAYAChain, a cross-chain liquidity protocol, experienced a sophisticated exploit on August 18 that cascaded from a single corrupted transaction into network-wide damage approaching $11 million.
The attacker moved approximately $1.36 million in hard assets, led by 20.83 BTC, to external blockchains, while the broader impact across MAYAChain’s interconnected pools reached roughly eight times that figure.
The exploit’s severity reflected the protocol’s architecture: CACAO, MAYAChain’s native token, underpins all paired liquidity pools, meaning a failure in one pool’s accounting logic triggered repricing across the entire system as the token’s value collapsed.
As of August 20, MAYAChain’s official channels had published no confirmed recovery timeline, no patch deployment details, no final loss tally, and no compensation framework for affected liquidity providers.
One transaction’s 23 messages corrupted the reserve’s core accounting system
Independent researcher Vini Barbosa traced the exploit to a single MsgDeposit transaction containing 23 separate messages that systematically corrupted MAYAChain’s state tracking. The critical failure occurred when a final DONATE message overwrote earlier ObservedTxVoter state data, erasing the outbound height parameter used to match legitimate transactions between chains.
This overwrite caused MAYAChain to misclassify real, completed outbound transfers as missing, a condition that should trigger only when legitimate withdrawals fail to appear on external blockchains.
The protocol’s theft-detection safeguard, designed to compensate pools after genuinely missing transfers, automatically activated in response to the false signal. The compensation calculation then executed on the ARB pool without enforcing a cap on subsidy amounts relative to the pool’s actual depth or reserves.
Barbosa’s reconstruction showed the handler calculated 49.45 million CACAO in subsidy value, roughly 294 times the 168,000 CACAO tokens the reserve actually held. The system committed this inflated pool state to the ledger even though the module transfer itself failed due to insufficient reserve balance.
The attacker then exploited the committed but unfunded balance by depositing negligible liquidity into the distorted ARB pool and claiming approximately 99.93% of its ownership units. This dominant position in the pool enabled a withdrawal of roughly 48.87 million CACAO tokens that existed only as false accounting entries.
The exploit succeeded because the handler continued execution after the failed transfer, preserving the inflated balance rather than rolling back the transaction. No safeguard prevented the recorded balance from supporting a liquidity claim despite having no underlying reserve to fund it.
Pool failure triggered token collapse that repriced the entire network
CACAO’s role as the connector token across all of MAYAChain’s paired liquidity pools meant the attacker’s massive withdrawal forced immediate repricing across every market on the network. The token fell from approximately $0.115 to $0.013 during the incident, an 88.7% decline, as the inflated CACAO supply hit open markets and liquidity providers rushed to exit positions.
This price collapse wasn’t isolated to a single pool; it affected the measured value of CACAO held in every other pool on the platform, amplifying the initial exploit’s damage far beyond the $1.36 million in hard assets actually moved.
MAYAChain Protocol founder Aaluxx stated on August 18 that the team would resolve the incident and “recover in full,” but provided no timeline or mechanism details.
The cascade reflected a structural weakness in cross-chain liquidity designs: when one asset pair’s accounting fails catastrophically, the repricing it triggers becomes a second-order loss event for every other pool using that asset. Liquidity providers who had deposited assets into other MAYAChain pools faced sudden, involuntary revaluation as CACAO’s price collapsed.
The $1.36 million in direct theft understates the total damage because it excludes the value destruction experienced by unaffected pools through forced repricing of their CACAO-denominated positions.
Protocol lacked safeguards to prevent unfunded pool states from becoming withdrawable
The exploit exposed three consecutive defense failures in MAYAChain’s architecture. First, the protocol allowed a single transaction containing multiple messages to overwrite critical state parameters (the outbound height) that should have been protected from mid-transaction modification.
Second, the compensation handler calculated subsidy amounts without enforcing bounds relative to actual reserve depth, creating a pathway for the system to recognize value it could never fund. Third, and most critically, the system committed an inflated pool state to the ledger even after detecting the subsidy transfer itself had failed due to insufficient reserves.
Standard cross-chain bridge and liquidity protocols include atomic execution logic: if a module transfer fails, the entire transaction should fail and roll back, preventing committed state from diverging from actual asset balances. MAYAChain’s handler continued after the failed transfer, leaving the inflated CACAO balance in place as a recorded pool asset.
This decoupling of state from reality became withdrawable because the attacker could then add real liquidity to the distorted pool and claim ownership stakes based on false accounting. The combined failures, state corruption, unbounded subsidy calculation, and post-failure commitment, created a chain of events that no single safeguard could have prevented.
Compensation framework and recovery timeline remain undefined as of August 20
MAYAChain faced an immediate operational decision: whether to restart swaps on pools that may have been repriced unfairly, and how to allocate losses between liquidity providers who exited positions before the collapse and those who remained.
Aaluxx’s public commitment to “recover in full” suggested the team would attempt to compensate affected users, but the specific mechanism, whether through a treasury recovery fund, CACAO reissuance, emergency liquidity injection, or forced rebalancing of pools, remained unstated.
The absence of a published patch, confirmed restart date, asset-recovery total, loss-allocation framework, or compensation terms as of August 20 left institutional liquidity providers without clarity on their exposure or timeline for fund recovery.
For institutional investors considering exposure to MAYAChain or similar cross-chain liquidity protocols, the incident highlighted the risks inherent in protocols where a single pool’s accounting failure can trigger systemic repricing. The fact that a $1.36 million direct theft expanded into an $11 million network impact demonstrated how interconnected pool designs amplify tail risks.
Any recovery plan would likely require network governance decisions to determine whether liquidity providers should absorb losses proportionally, or whether the protocol would use treasury assets or token reissuance to restore the lost value.
Watch for MAYAChain’s formal announcement of the deployed patch, the confirmed mainnet restart date for swaps, and the published loss-allocation framework. The team’s choice between proportional loss-sharing versus full compensation through treasury deployment will signal whether MAYAChain can restore institutional confidence or faces sustained capital flight.