Maya Protocol halted its network after an attacker drained $1.7 million, including 20 Bitcoin, from the decentralized exchange. The exploit leveraged six chained bugs in the protocol's smart contracts, forcing an emergency shutdown to prevent further illicit transfers from liquidity pools.
On-chain analysis shows the attacker executed a series of complex transactions, systematically siphoning funds from multiple liquidity pools. The multi-stage attack targeted the protocol's cross-chain swap functionality, bypassing security checks and draining 20 BTC (worth roughly $1.28 million at $64,168 per coin) along with $416,640 in other cryptocurrencies or stablecoins.
The incident exposes persistent security vulnerabilities even in audited protocols. While Bitcoin remains at $64,168 with little immediate market reaction, the exploit could accelerate capital flight from smaller DEXs toward established platforms. User funds remain inaccessible during the halt, and the protocol's native token has experienced significant selling pressure.
Maya Protocol said it is working with security researchers to investigate the vulnerabilities and assess damage. The incident underscores why continuous security audits and robust bug bounty programs remain essential for DeFi protocols operating at scale.