Wednesday, August 19, 2026

Maya Protocol Exploited for ~$1.7M via Chained Six-Bug Attack

Neon-lit multi-bridge breach with six failing locks and cascading tokens, blue-cyan-purple glow.

Maya Protocol halted its cross-chain network on August 19, 2026, after an attacker exploited a sequence of six separate software flaws to drain approximately $1.7 million in assets. The exploit involved vulnerabilities affecting trade accounts, outbound transaction handling, and liquidity pool calculations that, when combined, allowed the attacker to bypass standard security checks.

According to a technical breakdown provided by security researcher Vini Barbosa, the attacker used a single transaction containing 23 messages to execute the exploit. The process reportedly involved triggering the protocol’s theft-detection mechanism under unintended conditions and manipulating a low-liquidity pool to inflate asset values. These combined edge-case bugs enabled the extraction of roughly 48.87 million CACAO tokens from Maya’s Asgard module.

Maya Protocol co-founder Aaluxx confirmed the breach, stating that the attacker moved approximately 20.83 BTC, valued at roughly $1.4 million at the time, to external chains, while another $300,000 in various assets remained in positions controlled by the attacker.

Network Response and Technical Impact

Immediately following the detection of the exploit, the team activated a global halt of the network to prevent further fund depletion. The halt froze cross-chain activity, including deposits and withdrawals. Technical findings indicate that while Maya Protocol is a fork of THORChain, the specific exploit vector used in this incident does not affect the THORChain network.

The incident also coincided with a sharp decline in the value of the protocol’s native token, CACAO, which reportedly fell more than 80% during the event. The attack follows similar automated exploits in the DeFi sector, such as the Hinkal Protocol drain earlier this year, which also involved rapid withdrawals and the bridging of funds.

Maya Protocol’s development team is currently working on fixes to restore swapping functionality. The team has expressed its intent to pursue full recovery of the funds, although specific details regarding a reimbursement plan or the status of the stolen Bitcoin have not been finalized. The attacker’s primary address has been identified as maya1dl3yrfpedyr5jfr0r86s2apjltnjqgszmwsv8x.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.