Maya Protocol was hit by an exploit that drained roughly $1.7 million in crypto assets, according to blockchain security firm CertiK. The attacker inflated the protocol's accounting with a false subsidy, then added and removed liquidity to extract about 48.87 million CACAO and 98.82 LINK from shared liquidity pools. The incident was reported this week, and the protocol has not yet issued a public statement.
How the attacker pulled it off
CertiK's analysis points to a single false subsidy as the root cause. By injecting a fake subsidy into the accounting system, the attacker made the protocol believe it had more funds than it actually did. That opened the door to a series of liquidity moves — adding and then removing assets — that let the attacker walk away with a meaningful chunk of the shared pools.
The assets taken were CACAO, Maya's native token, and LINK, the Chainlink token. Both came from shared liquidity, meaning the losses hit multiple users who had provided funds to those pools. The exact mechanics are still being pieced together, but the core flaw appears to be a failure to verify the subsidy before it was counted.
What CertiK found
CertiK flagged the exploit in a public alert, noting the false subsidy as the entry point. The firm didn't name a specific vulnerability in the code, but the pattern — inflate accounting, then trade against the inflated balance — is a familiar one in DeFi. The total loss is small compared to some of the bigger hacks this year, but it's a reminder that even mid-sized protocols aren't immune.
Maya Protocol hasn't confirmed a timeline for recovery or said whether it plans to reimburse affected users. The protocol's social channels have been quiet since the news broke, which isn't unusual in the immediate aftermath of an exploit.
Shared liquidity is the weak spot
The fact that the stolen assets came from shared liquidity is worth pausing on. When a protocol pools funds from many users, a single accounting error can drain everyone at once. That's what happened here. The attacker didn't need to break into a wallet or guess a private key — they just found a way to make the books lie.
For users who had assets in those pools, the loss is real. Whether Maya Protocol can claw back any of the funds depends on how quickly it can trace the transactions and whether the attacker tries to move the assets through mixers or exchanges. CertiK's report doesn't include any recovery efforts so far.
What happens next
The immediate question is whether Maya Protocol will publish a post-mortem. Most protocols that get exploited do, eventually, but the timing varies. Some come out within hours; others take weeks. The community will also be watching to see if the protocol offers any compensation plan, though that's far from guaranteed.
For now, the exploit stands as a case study in how a single false input can unravel a shared liquidity system. The attacker got away with $1.7 million, and the protocol is left to explain how it happened.




