Unresolved $11 million liquidity crash leaves pools exposed as attacker still holds 20.83 BTC on Maya Protocol
The suspected Bitcoin address at the center of Maya Protocol’s Aug. 18 exploit still held about 20.8273 BTC with no outgoing spend on Aug. 21, while no published recovery plan accounted for the much larger estimated impa...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
The suspected Bitcoin address at the center of Maya Protocol’s Aug. 18 exploit still held about 20.8273 BTC with no outgoing spend on Aug. 21, while no published recovery plan accounted for the much larger estimated impact across the cross-chain liquidity protocol’s pools.
Related Reading MAYAChain's $1.36 million exploit spiraled into nearly $11 million of pool damagePublic Bitcoin data showed 20.82731228 BTC funded, zero spent, 11 confirmed transactions and none waiting in the mempool. Ten initial deposits totaling 20.82730682 BTC arrived at 17:32:18 UTC on Aug. 18, while a later 546-satoshi transaction raised the total slightly. At today's Bitcoin price, the balance was worth about $1.59 million.
Maya Protocol founder Aaluxx initially said the network had likely lost about 20 BTC, worth roughly $1.4 million at the time, plus about $300,000 in other assets. He said he would work to fix the incident and recover in full.
Related Reading The next DeFi drain could come from legacy contracts everyone forgot Why replacing 20 BTC would not make pools wholeA technical reconstruction by SigIntZero attributed the exploit to six accounting and state-handling flaws chained inside one 23-message transaction. It said overwritten outbound state produced a false missing-transfer signal, activating a compensation path that credited about 49.45 million CACAO to a thin ARB.LINK pool even though Maya’s reserve held only about 168,000 CACAO.
The reserve transfer failed, but the inflated balance persisted. After adding negligible liquidity, the attacker received about 99.93% of the pool’s ownership units and withdrew roughly 48.87 million CACAO before swapping into assets held by other MAYAChain pools.
SigIntZero estimated that about $1.36 million in assets moved to external chains and roughly $291,000 remained on MAYAChain, putting total attacker-controlled value near $1.65 million to $1.7 million.
Separately, the pool was impacted by $10.9 million. CryptoSlate analysis attributed about $6.4 million to CACAO repricing and about $2.9 million to arbitrage after the token fell from roughly $0.115 to $0.013, an 88.7% decline.
Maya reportedly hopes for a bug-bounty return and, failing that, could seek to replace roughly 20 BTC through Aztec Chain investments and other means. Even if that Bitcoin is returned or replaced, it would cover only one part of the damage. As of press time, Maya had not publicly defined which remaining losses it would restore or who would absorb the gap created by CACAO’s repricing and trades during the dislocation.
Related Reading DeFi hacks are turning high yields into a hidden liquidity taxThe post Unresolved $11 million liquidity crash leaves pools exposed as attacker still holds 20.83 BTC on Maya Protocol appeared first on CryptoSlate.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes
In decentralized finance, “audited” is often presented as a verdict on an entire project. In practice, an audit usually covers nam...
XRP’s 30% monthly rebound meets a $4.6 million liquidity trial inside XRPL’s $1.1 billion stablecoin boom
Stablecoins on the XRP Ledger swelled to $1.126 billion as XRP logged a 29.7% monthly rebound, putting the network's value-capture...
Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid
Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but a...
Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand
Blockstream is refusing to pay the Liquid attacker nearly 600 Bitcoin (roughly $50 million), escalating a dispute over how the cry...
L-BTC resumes trading with reserves covering just 85% of supply
SideSwap reopened its markets on Liquid while the network’s route back to Bitcoin remained closed. The split gives Liquid Bitcoin...
Osmosis took 74 days to discover 40-BTC Nomic exploit
An attacker minted over 40 BTC worth of Nomic’s nBTC out of thin air on June 25. It took Osmosis, whose allBTC later turned out to...