MAYAChain halts network after estimated $1.7M exploit

A preliminary analysis says six chained bugs let a 23-message transaction drain 48.87 million CACAO, sending the token down nearly 89%.

MAYAChain halts network after estimated $1.7M exploit

MAYAChain, a cross-chain liquidity protocol, halted its network following an exploit that drained an estimated $1.7 million in assets. Preliminary analysis indicates that an attacker leveraged six chained software bugs through a single 23-message transaction, successfully siphoning approximately 48.87 million CACAO tokens from the protocol. The network was subsequently suspended to prevent further losses while developers assess the full scope of the breach.

MAYAChain is a decentralized liquidity protocol built as a fork of THORChain, designed to facilitate cross-chain swaps without relying on centralized intermediaries. The protocol's native token, CACAO, serves as the backbone of its liquidity pools and economic security model. Like many decentralized finance platforms, MAYAChain operates open-source smart contract infrastructure, which, while transparent, can expose vulnerabilities to sophisticated attackers capable of identifying and chaining multiple flaws in sequence.

The immediate market reaction was severe, with CACAO losing nearly 89% of its value following news of the exploit. The incident adds to a growing list of DeFi protocol breaches in 2024 and 2025, reinforcing ongoing concerns about smart contract security and the risks associated with complex multi-chain architectures. Chained exploits, in which multiple smaller vulnerabilities are combined into a single attack vector, are increasingly being observed across the DeFi sector.

Observers will be monitoring MAYAChain's official communications regarding a potential network restart, any plans for user compensation, and the timeline for a full post-mortem security report.

Source: Cointelegraph

Read original article ↗