WeightChain

Market Prices

Coin Price 24h
BTC Bitcoin
$77,532.5 +6.57%
ETH Ethereum
$2,420.18 +3.37%
SOL Solana
$91.79 +4.75%
BNB BNB Chain
$679.5 +4.14%
XRP XRP Ledger
$1.38 +4.31%
DOGE Dogecoin
$0.0847 +2.29%
ADA Cardano
$0.2184 +8.60%
AVAX Avalanche
$7.68 +5.44%
DOT Polkadot
$0.9019 +7.04%
LINK Chainlink
$11.54 +7.15%

Fear & Greed

72

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$77,532.5
1
Ethereum
ETH
$2,420.18
1
Solana
SOL
$91.79
1
BNB Chain
BNB
$679.5
1
XRP Ledger
XRP
$1.38
1
Dogecoin
DOGE
$0.0847
1
Cardano
ADA
$0.2184
1
Avalanche
AVAX
$7.68
1
Polkadot
DOT
$0.9019
1
Chainlink
LINK
$11.54

🐋 Whale Tracker

🟢
0xc002...a48c
6h ago
In
8,688 BNB
🔴
0xeabc...38e3
12m ago
Out
241.17 BTC
🔵
0x345a...6a1e
12m ago
Stake
4,139.22 BTC

💡 Smart Money

0xe0f9...0115
Top DeFi Miner
+$4.7M
61%
0x2063...fabc
Market Maker
+$1.5M
90%
0xfc2e...9fd8
Market Maker
+$1.3M
64%

🧮 Tools

All →

Maya Protocol Exploit: The Accounting Flaw That Siphoned $1.7M in Shared Liquidity

ChainChain
Security

On-chain data reveals a stark truth: the Maya Protocol exploit was not a typical reentrancy or oracle manipulation. It was a subsidy accounting flaw. The attacker extracted 48.87 million CACAO and 98.82 LINK, worth $1.7 million, by inflating liquidity shares through manipulated subsidy records. The protocol paused global operations, and founder Aaluxx promised full recovery. But the data tells a story of systemic risk hidden in custom logic.

Context

Maya Protocol is a cross-chain liquidity protocol that aggregates shared liquidity pools, similar in design to THORChain. It allows users to deposit assets and earn rewards through a subsidy mechanism. On [date of exploit], an attacker discovered a vulnerability in the subsidy calculation logic. The protocol's global pause function was activated by the team, freezing all operations. CertiK later confirmed the exploit involved "false subsidy overstating accounting." The attacker drained the shared liquidity pool, leaving the protocol on life support.

But the real story is in the mechanics. The protocol's custom subsidy mechanism allowed the attacker to artificially inflate their liquidity position, then withdraw more than they deposited. This is not a simple bug—it's a fundamental failure in accounting logic.

Core Evidence Chain

Let me break down the on-chain evidence. The attacker executed a series of transactions: add liquidity, receive LP tokens, then remove liquidity with a higher share. The subsidy was calculated based on a formula that did not properly validate the source of the subsidy amount. In effect, the attacker could "create" their own subsidy by manipulating input parameters, thereby overstating their share of the pool.

This is a classic accounting flaw, not a cryptographic failure. The protocol's smart contract treated the subsidy as a credit that could be claimed without verifying its legitimacy. The attacker exploited this by adding liquidity, claiming a false subsidy, then removing liquidity that included the inflated share. The net result: a clean extraction of 48.87 million CACAO and 98.82 LINK.

Maya Protocol Exploit: The Accounting Flaw That Siphoned $1.7M in Shared Liquidity

Based on my experience auditing ICO token distribution logic in 2017, I've seen similar patterns. Projects often add custom accounting features without rigorous validation. The subsidy mechanism here was likely added to incentivize liquidity, but it became the attack vector. The protocol's global pause function—a centralized kill switch—stopped the bleed, but it also reveals a centralization risk. The team had the power to freeze all funds, which is both a blessing and a curse.

Contrarian Angle

The conventional narrative is that the exploit is a disaster, and the founder's promise to restore funds is a positive sign. But the contrarian view is more nuanced. The promise to "fully restore" is unusual in DeFi—most protocols would balk. But the source of those funds remains opaque. If the restoration involves minting new CACAO, existing holders face dilution. The protocol's tokenomics already had a subsidy mechanism that likely required inflation. Now, the recovery plan may accelerate that inflation, punishing holders who did not participate in the exploit.

Maya Protocol Exploit: The Accounting Flaw That Siphoned $1.7M in Shared Liquidity

Furthermore, the global pause function is a double-edged sword. It prevented further losses, but it also demonstrates that the protocol is not truly decentralized. The team can unilaterally freeze assets. This is a red flag for institutional investors who require trustless operation. The exploit also highlights a blind spot in security audits: most auditors focus on reentrancy and overflow bugs, but accounting logic flaws are harder to catch. The subsidy mechanism was likely custom, and it slipped through.

Another counter-intuitive insight: the exploit boosts the narrative for THORChain and other cross-chain protocols that have not suffered similar attacks. It creates a comparative advantage for them. But it also increases scrutiny on all custom subsidy mechanisms. Efficiency hides in the edge cases nobody audits.

Takeaway

The next signal to watch is the restoration plan's details. If Aaluxx announces a treasury buyback, CACAO might recover. If it's a token mint, expect dilution and further decline. The broader lesson is clear: custom accounting logic in DeFi is a high-risk surface. Protocols should enforce strict validation of any subsidy or credit mechanism. The Maya Protocol exploit is a case study in how a single untested assumption can drain shared liquidity. The question for the community is not whether the funds will be restored, but whether the protocol will learn from its flawed accounting.

Efficiency hides in the edge cases nobody audits.