The attacker behind the MAYAChain exploit moved about $1.36 million in hard assets to external chains, including roughly 20.83 BTC, while the estimated impact across the network's liquidity pools approached $11 million. MAYAChain, operated by Maya Protocol, is a cross-chain liquidity network in which users trade against pooled assets linked by CACAO. Independent researcher Vini Barbosa traced most of the activity to a single MsgDeposit transaction containing 23 messages. He said its final DONATE message overwrote ObservedTxVoter state, including the outbound height used to match transactions, causing legitimate transfers to be classified as missing. That activated theft-detection logic, which generated an excessive subsidy for a nearly empty ARB pool. About 49.45 million CACAO was recorded against reserves holding only about 168,000 CACAO; although the module transfer failed, the inflated state remained committed. The attacker then added negligible liquidity, received about 99.93% of the pool's ownership units and withdrew roughly 48.87 million CACAO. CACAO fell from about $0.115 to $0.013, an 88.7% decline, further reducing the dollar value of liquidity remaining in the pools. Founder Aaluxx said on Aug. 18 that the team would fix the incident and “recover in full.” As of the Aug. 20 reporting cutoff, Maya had not confirmed a swap restart, a mainnet patch, recovered-asset total, final loss allocation or comprehensive compensation terms for liquidity providers. Maya's recovery promise therefore remains undefined across three areas: replacing hard assets, repairing pool balances, and determining how remaining losses are allocated. Public documentation also did not show that THORChain carries the same complete exploit path, despite shared development lineage around Trade Accounts.