Maya Protocol halted MAYAChain after an exploit distorted pool accounting and let an attacker remove real assets from the cross-chain liquidity network.

The conservative verified version is narrower than the headline pool-loss number. CoinDesk reported that the attacker extracted about $1.7 million in bitcoin and other assets, including roughly 20 BTC, while the broader pool impact was closer to $10.9 million after CACAO's price collapse and arbitrage across affected markets. Maya Protocol founder Aaluxx said publicly that the team would work to fix the issue and recover in full.

The reported attack path matters because it was not described as a single private-key compromise. A technical reconstruction cited by CoinDesk said several software failures combined: the chain treated an outgoing transaction as missing, applied compensation logic to a liquidity pool, saved an inflated pool balance even though the reserve could not fund it, and allowed the attacker to withdraw against that false accounting state.

That sequence turned a bookkeeping failure into a market-wide liquidity event. Once the pool state was distorted, swaps and arbitrage pulled assets out of other markets while CACAO sold off sharply. CoinDesk reported that some exploited CACAO remained on-chain, while external assets had already moved to other blockchains.

MayaScan still identifies MAYAChain as the protocol's public explorer, which makes the halt notable for users who rely on the network for cross-chain swaps. The next key facts are whether the attacker returns funds, how the team patches the accounting path, and how liquidity providers are treated once swaps resume.