BTC $79,798.35 +3.38%
ETH $2,482.37 +0.96%
BNB $702.57 +0.76%
XRP $1.49 +1.45%
SOL $100.08 +6.18%
TRX $0.3432 -0.03%
DOGE $0.0907 -0.29%
ADA $0.2211 +0.46%
BCH $269.32 +0.37%
LINK $11.57 +0.35%
HYPE $80.84 +3.65%
AAVE $129.94 -7.00%
SUI $0.8031 -1.53%
XLM $0.1930 -0.43%
ZEC $842.02 +1.75%
BTC $79,798.35 +3.38%
ETH $2,482.37 +0.96%
BNB $702.57 +0.76%
XRP $1.49 +1.45%
SOL $100.08 +6.18%
TRX $0.3432 -0.03%
DOGE $0.0907 -0.29%
ADA $0.2211 +0.46%
BCH $269.32 +0.37%
LINK $11.57 +0.35%
HYPE $80.84 +3.65%
AAVE $129.94 -7.00%
SUI $0.8031 -1.53%
XLM $0.1930 -0.43%
ZEC $842.02 +1.75%

stolen

All
Article
Flash

Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million

The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.

153 stolen addresses contain 132.95 BTC, and researchers are still unable to reproduce the Coldcard attacker's seed

According to monitoring by Bitcoin News, new research published by @PraveenPerera shows that Coldcard attackers seem to first identify addresses with vulnerabilities, then sort them by the amount of Bitcoin held, starting to transfer in batches from the addresses with the highest holdings. The transfer software used was relatively crude.One address had 225 spendable UTXOs, and the attackers extracted exactly the latest 200, leaving the earliest 25, which included a UTXO worth 0.16 BTC. This aligns perfectly with the limitation of a blockchain API investigated by researchers, which defaults to returning 200 records, indicating that the attackers may have failed to load the next page of data. The software even spent a UTXO of 294 satoshis, reportedly increasing the transaction fee by about 2040 satoshis, with the spent amount significantly higher than the value of the UTXO itself.The authors of the study believe that the builders of this tool may have a better understanding of the account balance system than of the Bitcoin UTXO model. Although the attackers seem to have obtained the complete seed of the victims, at least 75 BTC still remain in other addresses derived from the same seed. The biggest suspicion currently is that among the 153 stolen addresses, there are still 132.95 BTC, and researchers have been unable to reproduce the seed behind these addresses, so it cannot be ruled out that the attackers obtained undisclosed private device data or candidate data.
app_icon
ChainCatcher Building the Web3 world with innovations.