Maya Protocol Exploited for About $1.7 Million in Chained Six-Bug Attack

Maya Protocol was exploited for roughly $1.7 million after an attacker chained together six separate bugs, according to a detailed technical breakdown shared by security researcher Vini B. The analysis describes a sequence that moved through deposit handling, transaction tracking, outbound processing and liquidity accounting before ending in a large withdrawal from the protocol.https://twitter.com/vinibarbosabr/status/2089827189768212659
The report says the attack began with batched MsgDeposit calls that clobbered ObservedTxVoter, then used an outbound matcher with the wrong height, an uncapped slash subsidy on a near-empty pool and a SetPool step that ran before SendFromModule without rollback protection.
In that blockchain, the attacker added negligible liquidity, ended up with 99.93% ownership of the affected pool and then withdrew 48.87 million CACAO, according to the post.
Primary extraction included BTC and smaller assets
Beyond the CACAO withdrawal, the breakdown says the primary extraction included 20.83 BTC along with smaller assets. It also identifies an attacker address, maya1dl3yrfpedyr5jfr0r86s2apjltnjqgszmwsv8x, and says the protocol was globally halted after the exploit path was carried out.
The technical note stresses that the same vector would not be possible on THORChain, a distinction that appears aimed at clarifying the specific conditions that allowed the attack on Maya Protocol. The sequence described in the post presents the exploit as a compound failure rather than a single bug, with each step setting up the next.
The report’s figures and mechanics align with the broader account of a protocol-level incident, but the most useful detail for users is the structure of the attack itself: six issues, linked in sequence, created a path that allowed the attacker to drain value from a low-liquidity setup before the system was stopped.






