← Radar

Incident case file

Sign in to watch

Maya Protocol Six-Bug MAYAChain Exploit — Uncapped Slash Subsidy Drain

Incident date 2026-08-17Last updated Aug 26, 2026

1 views

PausedMAYAChainBitcoinArbitrumProtocol logic flaw — chained six-bug accounting exploit (uncapped slash subsidy)Cluster: MAYA-LGC-2026-08

Estimated loss

$1.4M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

BTC consolidation address: bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646 (20.82730682 BTC, confirmed via mempool.space, P2WPKH, 10 UTXOs, zero outgoing transactions). MAYAChain native address: maya1dl3yrfpedyr5jfr0r86s2apjltnjqgszmwsv8x (confirmed via on-chain swap history showing 8 outbound swaps of 4,000,000 CACAO each, blocks 17,978,000-17,978,008).

Funds moved to

Attacker extracted ~48.87M CACAO and 98.82 ARB.LINK from an inflated MAYAChain liquidity pool, converting the bulk into 20.82730682 BTC (~$1,343,367) via 8 sequential swaps of 4,000,000 CACAO each (blocks 17,978,000-17,978,008), consolidated at bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646. Also extracted 6.0275 ARB.ETH (~$11,452) and 99.92 ARB.LINK (~$1,400). Approximately 8,874,269.11 CACAO (~$287,651) remained unconverted in the attacker's native MAYAChain wallet. No funds have moved off-chain s

Linked

Exploit executed via a single MsgDeposit transaction containing 23 messages at block 17,977,941. The final DONATE message overwrote a prior ObservedTxVoter record, corrupting the outbound-transaction matcher (handler_common_outbound.go). This triggered a false 'theft detection' mechanism, which credited an uncapped slash subsidy (helpers.go) of ~49.45M CACAO into a low-liquidity ARB.LINK pool holding only ~0.11 LINK. State was committed before the corresponding funding transfer executed (helpers

Chronology

1 beat
  1. T0 (Aug 18, ~17:30 UTC): Attacker submits a single 23-message MsgDeposit transaction at block 17,977,941, triggering the chained six-bug exploit. T+1 min: Block 17,977,971 — attacker adds/withdraws liquidity, extracting ~48.87M CACAO and 98.82 ARB.LINK after gaining 99.93% ownership of the artificially inflated ARB.LINK pool. T+2-3 min: Blocks 17,977,998-17,978,008 — attacker executes 8 sequential swaps of 4,000,000 CACAO each, converting the bulk of extracted value into 20.82730682 BTC, consolidated at bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646. T+4 min: Block 17,978,094 — CACAO price bottoms at $0.013, down 88.7% from its pre-exploit price of $0.115, within under 240 blocks. Within the hour: Maya Protocol halts the network globally as a precaution. Founder @AaluxxMyth posts publicly: 'Sad news. Will work to fix and recover in full,' and signals intent to fund partial compensation via proceeds from an upcoming Aztec Chain investment, and offers a whitehat bounty to the attacker for return of funds. Aug 19, 06:10 UTC: @PeckShieldAlert publicly confirms the exploit at ~$1.7M total value, citing the BTC consolidation address holding the majority of extracted funds (~$1.34M in BTC). Aug 19-21: CertiK and Defimon publish independent technical breakdowns confirming the six-bug chain and the exact block-by-block extraction sequence. As of Aug 21, the network remains halted/paused, no funds have been returned, and the attacker's BTC and residual CACAO holdings remain untouched.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)