
A Bitcoin address tied to the Maya Protocol exploit still holds ~20.8 BTC, while analysis shows total pool impacts far exceed initial estimates.
AI-generated summary
Maya Protocol suffered an exploit on Aug. 18 involving accounting flaws, impacting cross-chain pools and CACAO token value.
The suspected Bitcoin address at the center of Maya Protocol’s Aug. 18 exploit still held about 20.8273 BTC with no outgoing spend on Aug. 21, while no published recovery plan accounted for the much larger estimated impact across the cross-chain liquidity protocol’s pools.
Public Bitcoin data showed 20.82731228 BTC funded, zero spent, 11 confirmed transactions and none waiting in the mempool. Ten initial deposits totaling 20.82730682 BTC arrived at 17:32:18 UTC on Aug. 18, while a later 546-satoshi transaction raised the total slightly. At today's Bitcoin price, the balance was worth about $1.59 million.
Maya Protocol founder Aaluxx initially said the network had likely lost about 20 BTC, worth roughly $1.4 million at the time, plus about $300,000 in other assets. He said he would work to fix the incident and recover in full.
Why replacing 20 BTC would not make pools whole
A technical reconstruction by SigIntZero attributed the exploit to six accounting and state-handling flaws chained inside one 23-message transaction. It said overwritten outbound state produced a false missing-transfer signal, activating a compensation path that credited about 49.45 million CACAO to a thin ARB.LINK pool even though Maya’s reserve held only about 168,000 CACAO.
The reserve transfer failed, but the inflated balance persisted. After adding negligible liquidity, the attacker received about 99.93% of the pool’s ownership units and withdrew roughly 48.87 million CACAO before swapping into assets held by other MAYAChain pools.
SigIntZero estimated that about $1.36 million in assets moved to external chains and roughly $291,000 remained on MAYAChain, putting total attacker-controlled value near $1.65 million to $1.7 million.
Separately, the pool was impacted by $10.9 million. CryptoSlate analysis attributed about $6.4 million to CACAO repricing and about $2.9 million to arbitrage after the token fell from roughly $0.115 to $0.013, an 88.7% decline.
Maya reportedly hopes for a bug-bounty return and, failing that, could seek to replace roughly 20 BTC through Aztec Chain investments and other means. Even if that Bitcoin is returned or replaced, it would cover only one part of the damage. As of press time, Maya had not publicly defined which remaining losses it would restore or who would absorb the gap created by CACAO’s repricing and trades during the dislocation.
AI outlook — possibilities, not facts
Maya Protocol may seek to replace ~20 BTC through Aztec Chain investments.
Possible · Within weeks

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.

Ethereum's better.codes contest tracks a 52.14-bit cryptographic proof gap for the koalaIRS12 parameter profile, measuring distance between certified safety and unsafe bounds via soundness and attack tracks.

Coldcard maker Coinkite released a security overhaul for Bitcoin hardware wallets following a firmware flaw that led to over $130 million in stolen Bitcoin.

Solana has upgraded its network for the first time since genesis, reducing base slot timing from 400ms to 350ms to speed up transaction confirmations. The change is part of a phased plan to reach 200ms, aiming to improve latency and censorship resistance.

Binance has launched 'Binance Agent OS,' a platform enabling AI agents like ChatGPT and Claude to connect to its exchange for market data and trading. The system uses isolated sub-accounts and restricts withdrawals to mitigate security risks for users.