Skip to main content

Maya Protocol Halts Network After $1.7 Million Exploit via Six Chained Bugs

Maya Protocol paused MAYAChain after an attacker exploited six software flaws to drain about $1.7 million in bitcoin and other assets, sending CACAO down nearly 89%.

By CryptoPress
August 19, 2026
  • Maya Protocol halted its MAYAChain network after an attacker drained roughly $1.7 million using six chained software bugs.
  • The attacker withdrew 48.87 million CACAO and moved about 20.83 BTC worth approximately $1.34 million off-chain.
  • CACAO fell nearly 89% from around $0.115 to a low of $0.013 before partial recovery.
  • Founder AaluxxMyth confirmed the incident and said the team is working to fix the issues and recover fully.
  • Liquidity pool values declined an estimated $10.9 million including arbitrage and token devaluation.

Cross-chain liquidity protocol Maya Protocol halted its MAYAChain network after an attacker exploited a series of software flaws to drain nearly $1.7 million in bitcoin and other assets.

According to a statement from founder AaluxxMyth, the attacker took about 20 bitcoin valued at roughly $1.4 million plus approximately $300,000 in additional assets. The protocol implemented a global halt to contain further damage and is working on a fix before swaps resume.

A preliminary technical analysis attributed the incident to six chained bugs involving trade accounts, outbound transaction handling and liquidity pool calculations. The attacker executed a single transaction containing 23 messages that triggered a false theft detection, artificially inflated a low-liquidity pool, and allowed the withdrawal of 48.87 million CACAO from Maya’s Asgard module, as detailed in reporting by Cointelegraph.

On-chain data showed about $1.36 million moved to external blockchains, while the attacker retained positions worth around $291,000 on MAYAChain. CertiK Alert confirmed the roughly $1.7 million figure and noted the inflation of ARB.LINK accounting followed by liquidity add/remove actions that extracted the CACAO and other tokens.

CACAO, the protocol’s native token, plunged from approximately $0.115 to as low as $0.013 — a drop of nearly 89% — before recovering toward $0.03. The broader impact included an estimated $10.9 million decline in pool values, driven by the exploit itself, subsequent arbitrage, and the token’s devaluation rather than solely the assets taken by the attacker, according to analysis cited across coverage.

Maya Protocol, a THORChain fork that enables native cross-chain swaps without wrapped assets, marked its first major loss-of-funds incident of this scale since launching in 2023. The team has indicated it will pursue recovery options, including outreach to the attacker regarding a potential bug bounty.

Related

© Cryptopress. All rights reserved.