MAYAChain's attacker moved about $1.36 million in hard assets to external chains, while the estimated impact across the network's liquidity pools approached $11 million.

The $1.36 million figure tracks assets that left the system, including roughly 20.83 $BTC. The larger estimate captures a cascade inside the pools: false accounting created a huge CACAO balance, that balance became withdrawable, and CACAO's subsequent collapse repriced the network's remaining liquidity.

Maya Protocol operates MAYAChain as a cross-chain liquidity network where users trade against pooled assets. Its CACAO token connects those markets, which allowed a failure that began in one pool to spread through the value recorded elsewhere.

Founder Aaluxx said on Aug. 18 that the team would fix the incident and “recover in full.” As of the Aug. 20 reporting cutoff, Maya's official channels had not yet published a confirmed swap restart, the patch deployed on mainnet, an asset-recovery total, a final loss allocation, or comprehensive compensation terms for liquidity providers.

How an unfunded balance became withdrawable

The exploit turned an accounting entry that the reserve could never fund into a liquidity position the attacker could use.

Independent researcher Vini Barbosa traced most of the activity to one MsgDeposit transaction containing 23 messages. In his reconstruction, the final DONATE message overwrote earlier ObservedTxVoter state, including the outbound height used to match transactions.

That wrong height made MAYAChain classify legitimate outbound transfers as missing. The classification activated theft-detection logic designed to compensate a pool after a missing transfer.

The compensation path then calculated a subsidy for a near-empty ARB pool without bounding the amount to the pool's depth. Barbosa said the calculation recorded roughly 49.45 million CACAO of value even though the reserve held only about 168,000 CACAO.

The reserve lacked enough tokens to complete the module transfer, but the new pool state had already been committed. According to Barbosa, the handler continued after the failed transfer and left the inflated balance in place.

The attacker added a negligible amount of liquidity to the distorted pool and received about 99.93% of its ownership units, enabling a withdrawal of roughly 48.87 million CACAO.

The overwritten height produced false theft detection, the false signal generated an excessive subsidy, the failed subsidy survived in pool records, and the recorded balance then supported a dominant liquidity claim.

Barbosa's reconstruction attributes the exploit to that combined path. He put hard assets moved to external chains at about $1.36 million, led by 20.83 $BTC. His estimate for the network-wide impact was close to $11 million.

The token fell from about $0.115 to $0.013 during the incident, an 88.7% drop.

CACAO represents one side of MAYAChain's paired liquidity pools. A sharp decline in its dollar price reduces the measured value of CACAO inventory across the system, even when those tokens remain inside a pool.

The exploit-created balance and trades executed against distorted pool prices added another layer of pool impact.

A diagram shows a 23-message transaction triggering a false theft signal, CACAO repricing, and nearly $11 million in network-wide impact.

The original attacker's external haul and the value lost across the pools are separate measures. One follows assets sent out of MAYAChain, while the other captures how an accounting failure changed the value and composition of liquidity that remained available to providers.

Maya had yet to publish a final ledger dividing the total among hard-asset extraction, CACAO repricing, and trades made during the dislocation. The scale and direction of the multiplier are clear, while an exact dollar allocation for each category remains pending.

For liquidity providers, that distinction determines what recovery would require. Replacing 20.83 $BTC would restore one set of assets, while pool accounting, CACAO valuation, and the allocation of trading losses would still need their own treatment.

What “recover in full” has to cover

A full recovery has at least three parts: returning or replacing hard assets, repairing pool balances, and defining how the remaining impact is allocated among liquidity providers and other participants.

Maya's network-halt documentation says HALTTRADING stops trading while MAYAChain can continue producing blocks. Chain liveness shows that consensus is running, but swap availability depends on the trading controls.

By Aug. 20, Maya's public channels had yet to supply the confirmed restart time, deployed patch version, recovered-asset total, final pool calculation, and liquidity-provider compensation scope needed to turn the recovery promise into a defined settlement.

MAYANode's public history shows that its Trade Accounts implementation drew from THORChain merge requests. That establishes shared development lineage around Trade Accounts.

The complete MAYAChain exploit depended on several conditions aligning across transaction state, outbound matching, subsidy calculations, pool-state ordering, and rollback behavior. Public documentation as of press time did not demonstrate that THORChain carries that same complete path.

MAYAChain's loss multiplier is as much an accounting and market structure story as a theft story. The attacker moved about $1.36 million in hard assets, but the false balance changed pool ownership and arrived alongside an 88.7% collapse in the token connecting the network's markets.

For liquidity providers, the decisive update will be Maya's definition of “full”: which assets return, how pool balances are rebuilt, and who absorbs the value changes and trades that recovery cannot simply rewind.