Cross-chain liquidity protocol Maya Protocol was suspended after the attack. According to the project party, the attackers used multiple software deficiencies to transfer approximately $1.7 million in assets, and the team is repairing the loophole and will continue to stop the conversion until it is restored.

Six defects trigger the attack.

In its ex post facto report, the projecter indicated that the attackers had used an MsgDeposit transaction containing 23 messages to trigger the wrong “theft” detection logic and used an unceiling penalty subsidy mechanism to add to the CACAO balance in the low liquidity pool.

The attackers then injected liquidity into the pool and quickly withdrew funds, thereby gaining near-total control of the pool. According to the report, the operation at one point raised the CACAO balance in the pool by about 49.45 million, eventually removing about 48.8 million.

About $165,000 has been transferred out

The actual loss was estimated by the project participants to be approximately $1.65 million. Of this amount, approximately $1.36 million has been transferred to the external block chain, while some $291 million remains in the chain. The founder, Aalux Myth, previously stated that stolen assets included about 20 bitcoin and about $300,000 in other currencies.

The team also released a bitcoin address for suspected attackers. The address received 20.83 BTCs valued at approximately $13.43 million. The projector indicated that it would like the other party to return the funds in the form of a gap reward; if not, the team plans to replenish the damaged mobile pool by, inter alia, investing in Aztec Chain.

CACAO dropped by 89%.

As the attackers exchanged their coins for bitcoin and other assets, the CACAO prices fell rapidly and the final withdrawals were reduced. As a result of the events, CACAO experienced a downfall of 89 per cent and the total value of the MayaChain mobile pool decreased by approximately $10.9 million.

The projecters state that these deficiencies have not been detected in the last 3 to 4 years, although the codes were audited by Halborn and Fable 5. The team indicated that the code would be reviewed in a more rigorous manner, focusing on simple gaps in the underlying logic.

Additional information:This incident was preceded by a series of attacks in the DeFi area in recent months. In July, the Arbitrum Eco-Renewal Contract Exchange Ostium was damaged by the destruction of about $18 million for the premonition machine signature key; the same month, AFX Trade also lost about $24 million for the USDC cross-chain bridge gap.