Newsroom

Maya Protocol Halts Network After $1.7 Million Cross-Chain Exploit

19 August, 2026   /   News   /  AI   /   Tags:  cacao, maya, attacker, protocol, pools

Maya Protocol Halts Network After $1.7 Million Cross-Chain Exploit

Attacker chained six software flaws in a single transaction to drain bitcoin and other assets, triggering an 89% drop in CACAO and a sharp decline in pool value

Maya Protocol suspended all activity on its MAYAChain network on Wednesday after an attacker exploited a sequence of six software flaws to extract an estimated $1.7 million in bitcoin and other cryptocurrencies. The cross-chain trading protocol activated a global halt to prevent further losses while developers began preparing fixes.

Pseudonymous co-founder Aalux confirmed that the attacker obtained approximately 20 bitcoin, valued at roughly $1.4 million, along with about $300,000 in additional assets. Preliminary on-chain data indicated that around 20.83 bitcoin, worth approximately $1.34 million, was transferred to an external address controlled by the attacker.

Sad news. Will work to fix and recover in full. We carry on.
Aalux, Maya Protocol co-founder

How the Attack Unfolded

A preliminary technical analysis released by the team showed that the exploit did not rely on a single vulnerability. Instead, the attacker combined six separate bugs affecting trade accounts, outbound transaction processing, and liquidity pool calculations. These weaknesses were executed through one transaction containing 23 messages.

The sequence began when the protocol incorrectly registered an outgoing transaction as missing and activated its theft-compensation mechanism. That mechanism miscalculated the required adjustment and credited a low-liquidity pool with nearly 49 million CACAO tokens, even though the network’s reserve held only about 168,000 CACAO and could not fund the transfer.

Although the actual payment failed, a further accounting error caused the inflated balance to remain recorded on the network. The attacker then deposited a small amount into the distorted pool, gained control of more than 99 percent of it, and immediately withdrew 48.87 million CACAO from Maya’s Asgard module, the system that holds assets used to settle cross-chain swaps.

Those tokens were subsequently swapped for bitcoin, ether, and other assets held in the protocol’s liquidity pools. Approximately $1.36 million in value left the network for external blockchains, while roughly $291,000 remained in attacker-controlled CACAO holdings and trade-account positions on MAYAChain itself. One reconstruction placed the attacker’s total extraction, including retained tokens, near $1.65 million.

Impact on CACAO and Liquidity Pools

The rapid sale of newly obtained CACAO triggered a steep price collapse. The token fell 88.7 percent to 89 percent, dropping from about $0.115 to as low as $0.013 before later recovering to around $0.03. Independent researcher Vini Barbosa confirmed the magnitude of the decline.

The broader effect on the protocol’s pools was larger. Technical estimates put the total decline in pool value at approximately $10.9 million to $11 million. However, that figure includes substantial losses from arbitrage trading that followed the price dislocation and from the sharp devaluation of CACAO itself. Roughly $6.4 million of the decline was attributed to the token’s reduced market value and about $2.9 million to arbitrage activity, rather than direct extraction by the attacker.

Because Maya Protocol enables native-asset swaps across different blockchains without a centralized intermediary, its vault and liquidity accounting systems sit at the center of every transaction. Distortions in those systems therefore affected multiple markets simultaneously.

Response and Recovery Plans

The global halt contained the incident and stopped additional outflows. Developers are now focused on correcting the specific components involved in trade-account behavior, outbound transaction handling, and liquidity calculations so that cross-chain swaps can safely resume. No timetable for the restart has been announced.

The team has indicated it hopes the attacker will return the funds in exchange for a bug bounty. If the assets are not returned, Maya Protocol said it would work to replace the roughly 20 bitcoin through other means, including investments linked to Aztec Chain. Restoring the pools themselves presents an additional challenge, as much of the CACAO created during the exploit was swapped into other markets and is now intermingled with tokens belonging to ordinary liquidity providers.

The incident adds to a series of security events that have affected cross-chain trading infrastructure this year, underscoring the complexity of systems that must coordinate validators, liquidity pools, vault modules, and signature schemes across separate networks.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.