Maya Protocol Hacked: Six Flaws, $11 Million Gone
A cross-chain trading network has been drained of $11 million in bitcoin and other digital assets after an attacker exploited a chain of six separate security flaws in Maya Protocol's liquidity infrastructure, according to CoinDesk.
A cross-chain trading network has been drained of $11 million in bitcoin and other digital assets after an attacker exploited a chain of six separate security flaws in Maya Protocol's liquidity infrastructure, according to CoinDesk.
The mechanism was precise and damaging: the protocol's code credited a liquidity pool with nearly 50 million tokens that were never actually deposited, creating a phantom balance that the attacker then used to withdraw real, funded assets from the other side of the pool. Six distinct vulnerabilities had to align for the exploit to work — and they did.
Maya Protocol operates as a cross-chain decentralised exchange, routing trades across multiple blockchains including Bitcoin. Its core promise is trustless, permissionless trading without a centralised custodian. That promise is now suspended pending a post-mortem and patch cycle that the team has not yet publicly scheduled.
The exploit arrives at an awkward moment for decentralised finance broadly — Bitcoin is holding near $64,000 and institutional attention has returned to the sector after months of outflows. Hacks of this architecture, where the flaw is not one vulnerability but a cascade of six, are particularly difficult to catch in audit cycles that typically stress-test individual components rather than their interaction.
No user funds have been publicly guaranteed as recoverable. The pool value, according to CoinDesk, dropped $11 million in the window of the attack.
Six flaws. Each one survivable alone. Together, they emptied the room.