Maya Protocol lost close to $10.9 million on August 19. The attacker walked off with about $1.65 million of it. That gap is the actual story, and most of the day's coverage rounded it away by picking one number and running with it.
The target was MAYAChain, a cross-chain swap network. An attacker strung six separate bugs together and pushed a single transaction carrying 23 messages into the protocol. That transaction fooled Maya Protocol's accounting into reading an ordinary deposit as a theft. The false theft flag fired a slashing routine, and the subsidy that routine paid had no cap on it. So the pool balance ballooned by 49.45 million CACAO, the network's own token. Maya Protocol's genuine reserve behind that pool sat near 168,000 tokens, per CoinDesk. The inflated figure was roughly 294 times the real one.
From there the withdrawal was simple. Holding 99.93 percent of the pool, the attacker pulled 48.87 million CACAO, plus 20.83 BTC worth about $1.4 million and another $300,000 in assorted assets. Around $1.36 million was bridged out to other chains. Roughly $291,000 stayed in on-chain positions.
Most of the $11 million was destroyed, not carried away
The headline loss and the theft are two different quantities, and the table below shows why they drifted so far apart.
| Component | Approximate value |
|---|---|
| Assets the attacker actually took | $1.65 million |
| Value erased by CACAO's price collapse | $6.4 million |
| Value lost to arbitrage around the break | $2.9 million |
| Total pool loss | $10.9 million |
CACAO fell about 89 percent during the incident, from near $0.115 to as low as $0.013. That collapse, plus the arbitrage traders who piled in as the peg to real reserves snapped, accounts for more than $9 million of the damage. None of that money reached the attacker. It came out of the liquidity providers who had parked assets in the pools, and it will not come back at the old price. A mint that nets a small sum while wrecking a much larger one is a pattern worth watching; Harmony's bridge mint told a similar story earlier this month.
The bugs were older than most of the audits
Decrypt reported that the flaws went unspotted through audits by Halborn and Fable for three to four years. These were not fresh mistakes shipped last week. They were structural gaps in how Maya Protocol handled trade accounts, outbound transactions, and pool math, and they only mattered once someone found the sequence that chained them. Cross-chain accounting keeps producing this shape of failure, from a single memo field on the Coreum bridge to the larger Drift Protocol loss that drained pooled deposits.
Maya Protocol halted MAYAChain to stop the bleeding, and its founder said the team would work to fix and recover in full. There is a bug bounty on the table, and a proposal to replace roughly 20 BTC through Aztec Chain investments if the funds are not returned. Swaps have no firm restart date. For anyone tracking the recovery, the number that matters is not the $11 million on the front pages. It is the $1.65 million the attacker can still move.