TLDR
- Maya Protocol was exploited for approximately $1.7 million, its first loss-of-funds incident since launching in 2023
- An attacker used a single 23-message transaction to exploit six chained bugs and drain 48.87 million CACAO tokens
- About 20 Bitcoin worth $1.4 million and $300,000 in other assets were stolen from Asgard and Yggdrasil vaults
- CACAO token dropped nearly 89%, falling from around $0.115 to $0.013 following the breach
- Maya Protocol activated a global network halt and said a patch is being prepared
Cross-chain decentralized exchange Maya Protocol shut down its network on Wednesday after an attacker stole around $1.7 million in crypto assets.
🚨BREAKING: Maya Protocol EXPLOITED for $1.7 MILLION in a sophisticated 6-bug attack.
MAYAChain suffered a chained six-bug exploit that allowed the attacker to manipulate pool accounting, gain 99.93% ownership of an inflated pool and extract roughly $1.36M in hard assets to L1,… pic.twitter.com/564eODmfld
— Coin Bureau (@coinbureau) August 19, 2026
The protocol’s co-founder, known as Aalux, confirmed the breach publicly and said the team applied a global halt to contain further damage.
The attacker took roughly 20 Bitcoin, valued at about $1.4 million, along with around $300,000 in other assets.
How the Attack Happened
A preliminary technical analysis linked the exploit to six chained software bugs involving trade accounts, outbound transaction handling, and liquidity pool calculations.
The attacker used a single transaction made up of 23 messages to trigger a false theft detection, artificially inflate a low-liquidity pool, and then withdraw 48.87 million CACAO tokens from Maya’s Asgard module.
About $1.36 million was moved to external blockchains. The attacker kept roughly $291,000 in CACAO and trade-account positions on the chain.
Blockchain security firm PeckShield flagged the incident and reported that funds were drained from the protocol’s vault infrastructure before automated solvency checks could fully stop the outflow.
The total value locked on Maya Protocol was around $15 million before the attack, according to DeFiLlama. The stolen amount represents just over 10% of that figure.
CACAO’s circulating market cap sits at roughly $10 million. The token was already down more than 92% from its all-time high of $1.43 before the exploit hit.
Independent researcher Vini Barbosa noted the wider pool value decline was estimated at $10.9 million, though that figure includes arbitrage activity and the token’s devaluation, not just stolen funds.
Maya’s Response
Aalux said the team identified the vulnerability and is preparing a fix. He thanked node operators for their fast response.
Maya Protocol operates as a fork of THORChain and uses a “halt first” security model, pausing trading before investigating rather than issuing a bailout.
Maya’s Mimir halt flags were activated, freezing deposits and withdrawals on affected pools while validators and developers investigated.
Context Within the Ecosystem
This exploit follows THORChain being drained of around $10.8 million in May 2026, later revised to $7.4 million, which also forced a full trading halt.
Maya had gone more than three years without a documented loss-of-funds event since its mainnet launch in April 2023.
A full post-mortem detailing how the attacker bypassed Maya’s security systems is expected from the team in the coming days.







