🟢 Verified 📰 News

An attacker's $1.7 million haul left an $11 million hole — why those are never the same number

· ✍️ altrookie editorial · 👁️ Read-only

Three days after an Aug. 18 exploit on Maya Protocol, a cross-chain liquidity protocol, the suspected Bitcoin address at…


Three days after an Aug. 18 exploit on Maya Protocol, a cross-chain liquidity protocol, the suspected Bitcoin address at the centre of it still held about 20.83 BTC and had spent none of it. That balance was worth roughly $1.59 million at the Bitcoin price at the time of reporting. The unresolved part is much larger: the affected pool was hit for about $10.9 million, and Maya has not publicly defined which of those losses it would restore or who absorbs the rest.

A technical reconstruction by SigIntZero attributed the exploit to six accounting and state-handling flaws chained inside a single 23-message transaction. Overwritten outbound state produced a false missing-transfer signal, which activated a compensation path that credited about 49.45 million CACAO to a thin ARB.LINK pool, even though Maya's reserve held only about 168,000 CACAO. The reserve transfer failed, but the inflated balance persisted. After adding a negligible amount of liquidity, the attacker received about 99.93% of that pool's ownership units, withdrew roughly 48.87 million CACAO, and swapped it into assets held by other MAYAChain pools.

SigIntZero estimated that about $1.36 million in assets moved to external chains and roughly $291,000 remained on MAYAChain, putting the total value under the attacker's control near $1.65 million to $1.7 million. The $10.9 million figure is a different kind of number. CryptoSlate's analysis attributed about $6.4 million of it to CACAO repricing and about $2.9 million to arbitrage, after the token fell from roughly $0.115 to $0.013, an 88.7% decline.

That gap is the part beginners most often miss. What an attacker walks away with and what everyone else loses are two separate numbers. Selling a large minted balance into a pool moves the token's price, and the price move reaches everyone still holding that token or providing liquidity against it, whether or not the attacker ever touched their funds. Arbitrage traders then close the remaining gaps between venues, taking value out along the way.

Maya's founder, Aaluxx, initially said the network had likely lost about 20 BTC, worth roughly $1.4 million at the time, plus about $300,000 in other assets, and said he would work to recover in full. Maya reportedly hopes for a bug-bounty return of the Bitcoin and, failing that, could seek to replace roughly 20 BTC through Aztec Chain investments and other means. Even if that Bitcoin comes back in full, it would cover only one part of the damage.

This is information, not advice, but the pattern is worth keeping. When you provide liquidity to a pool, you are exposed to the pool's accounting logic as well as to the price of the assets inside it. A promise that funds will be recovered usually refers to the traceable on-chain balance an attacker still holds, not the value that evaporated when a token repriced. Before trusting a recovery promise, look for a published plan that says which losses are covered and who pays for the rest. When no such plan exists yet, the honest description is that it is unresolved.