▼ Bear
Impact
99 · High
Maya Protocol: Hackers exploited 6 vulnerabilities, causing 1.7 billion won in damages and network disruptions
CACAOBTC
Decrypt · Aug 19, 08:22 PMView original ↗
The cross-chain liquidity network Maya Protocol has been targeted by a large-scale hacking attack, in which approximately six software vulnerabilities were exploited simultaneously, resulting in the theft of approximately $1.65 million worth of cryptocurrency and a complete shutdown of the MAYAChain network's operations. The founder, AaluxxMyth (referred to as Maya), acknowledged the incident directly in a post on X (formerly Twitter), stating, "There is no way to sugarcoat this. It is highly likely that approximately 20 BTC (worth $1.4 million) and other assets (worth approximately $300,000) have been stolen.".
According to a post-analysis report released by the team, the attacker executed the entire attack through a single MsgDeposit transaction consisting of 23 messages. Specifically, the attacker triggered a false "theft" detection mechanism, artificially inflating the CACAO balance in a low-liquidity pool to 4.945 million by using unlimited slash subsidies. Subsequently, the attacker participated in the inflated pool as an LP, secured a 99.93% stake, and immediately withdrew 4.887 million CACAO.
During the process of the attacker swapping the stolen CACAO tokens for Bitcoin and other cryptocurrencies, the price of CACAO plummeted by approximately 89%, resulting in a decrease of approximately $1.09 million in the overall value of the MAYAChain liquidity pool. The estimated total loss is around $1.65 million. Of this amount, $1.36 million (including 20.83 BTC) was transferred to external blockchains, while the remaining approximately $291,000 is still present on the blockchain.
The team stated that despite undergoing security audits by both Halborn and Fable 5, these six vulnerabilities remained undetected for 3 to 4 years. Maya said, "We need to adopt a more aggressive approach to identify even the most basic code vulnerabilities," and added that they would strengthen the entire code review system. The team also stated that they have not yet determined whether AI was used in the attacks.
Maya Protocol has called for the return of funds, stating that it will reveal the attacker's Bitcoin address and offer a bug bounty if the funds are returned. If the funds are not returned, the team plans to self-finance approximately 20 BTC through investments in the Aztec Chain and other means to compensate the affected liquidity pool.
This incident is one of the recent, large-scale DeFi exploits. In April, approximately $29.2 million was stolen from the KelpDAO cross-chain bridge due to a social engineering attack. In July, the Ostium perpetual exchange, which operates on Arbitrum, suffered losses of approximately $18 million due to the theft of an oracle signing key. Following these incidents, AFX Trade also experienced a breach of approximately $24 million, resulting from an attack targeting its USDC bridge.
This is an AI summary. Read the full article at the source.