The flaws let the pool credit nearly 50 million tokens to addresses without receiving matching deposits, creating phantom liquidity that had no backing on-chain.
This was not a single bug. Six separate weaknesses had to line up for the attack to work, which is why routine audits can miss this class of exploit entirely.
Individually, the attacker's transactions passed validation. Only the full sequence broke the protocol's accounting, a pattern that defeats per-call security checks.
Bitcoin still rose to $64,877 and Ethereum to $1,936 on August 19, as the SEC's new crypto regulation proposal dominated sentiment over the exploit news.
Maya Protocol's recovery response, whether through a DAO vote, insurance payout, or upgrade, will decide how much liquidity returns to the pool.
Read More →