Maya Protocol halted its cross-chain network on August 19, 2026, after an attacker exploited a sequence of six separate software flaws to drain approximately $1.7 million in assets. The exploit involved vulnerabilities affecting trade accounts, outbound transaction handling, and liquidity pool calculations that, when combined, allowed the attacker to bypass standard security checks.
According to a technical breakdown provided by security researcher Vini Barbosa, the attacker used a single transaction containing 23 messages to execute the exploit. The process reportedly involved triggering the protocol’s theft-detection mechanism under unintended conditions and manipulating a low-liquidity pool to inflate asset values. These combined edge-case bugs enabled the extraction of roughly 48.87 million CACAO tokens from Maya’s Asgard module.
sad day for @Maya_Protocol (i love the project) 🙁
MAYAChain just suffered a sophisticated 6-bug exploit that extracted ~$1.36M in hard assets to L1 and left the protocol with roughly $11M in total impact$CACAO went from $0.115 → $0.013 (−88.7%) in under 240 blocks
this was… https://t.co/X4hth17BTB
— Vini B 「thecoding.dev」 (@vinibarbosabr) August 18, 2026
Maya Protocol co-founder Aaluxx confirmed the breach, stating that the attacker moved approximately 20.83 BTC, valued at roughly $1.4 million at the time, to external chains, while another $300,000 in various assets remained in positions controlled by the attacker.
Sad news 😕
Will work to fix and recover in full. We carry on. @Maya_Protocol pic.twitter.com/EYK9BeWWLI— Aaluxx⚡️🍫🛡️ (@AaluxxMyth) August 18, 2026
Network Response and Technical Impact
Immediately following the detection of the exploit, the team activated a global halt of the network to prevent further fund depletion. The halt froze cross-chain activity, including deposits and withdrawals. Technical findings indicate that while Maya Protocol is a fork of THORChain, the specific exploit vector used in this incident does not affect the THORChain network.
The incident also coincided with a sharp decline in the value of the protocol’s native token, CACAO, which reportedly fell more than 80% during the event. The attack follows similar automated exploits in the DeFi sector, such as the Hinkal Protocol drain earlier this year, which also involved rapid withdrawals and the bridging of funds.
Maya Protocol’s development team is currently working on fixes to restore swapping functionality. The team has expressed its intent to pursue full recovery of the funds, although specific details regarding a reimbursement plan or the status of the stolen Bitcoin have not been finalized. The attacker’s primary address has been identified as maya1dl3yrfpedyr5jfr0r86s2apjltnjqgszmwsv8x.
