Cross-chain protocol Maya Protocol halted all operations on August 18, 2026 after an attacker chained six software flaws to siphon roughly $1.7 million in bitcoin and other assets. The incident wiped out nearly 89% of the native CACAO token and erased more than $10 million from its liquidity pools.
🔑 Key takeaways
- Maya Protocol suspended all swaps and operations on August 18, 2026.
- ~$1.7M was drained, including 20.83 BTC, ether, stablecoins and ~8.87M CACAO.
- The CACAO token plunged ~89%, from $0.115 to $0.013.
- A chain of six software bugs enabled the attack, starting with a routing error.
- Pools lost ~$10.9M in total, of which only ~$1.65M was directly stolen.
Timeline of a six-step exploit
On August 18, 2026, Maya Protocol — a cross-chain exchange built on top of THORChain — froze every trading function after spotting an unauthorized outflow of funds. The exploit pushed 20.83 BTC, worth roughly $1.34 million, into the attacker’s bitcoin address (bc1q…l646), alongside additional assets looted from other pools on the protocol.
On-chain data shows around $1.36 million of assets were bridged out to external blockchains, while roughly 8.87 million CACAO tokens stayed parked in the attacker’s MAYAChain wallet. The attacker’s total direct gains are estimated at $1.65 million, including tokens still held on-chain.
The protocol’s founder, known on X as @AaluxxMyth, publicly confirmed the theft of about 20 BTC (~$1.4M) and roughly $300,000 in other assets, and announced a full halt of trading to contain the damage.

Six bugs in cascade: technical anatomy of the attack
The breach did not stem from a single flaw but from a chain of six software bugs whose combined effects compounded inside the MAYAChain network. The trigger was a routing error: the network incorrectly assumed an outgoing transaction had been lost and activated a refund mechanism targeting a liquidity pool.
The refund calculation was wildly disproportionate. The mechanism credited roughly 49 million CACAO to a pool that actually held only about 168,000 CACAO in reserves. The compensation transfer failed because reserves were nowhere near sufficient — but another bug had already written the inflated balance into the network’s ledger.
Instead of rolling back when the payment failed, MAYAChain kept operating as if the pool genuinely held those extra tokens. The attacker only had to deposit a tiny amount into the distorted pool to become the owner of more than 99% of it. They immediately withdrew 48.87 million CACAO and began swapping those tokens for bitcoin, ether and other assets sitting in the protocol’s pools.
CACAO drops 89% as $10.9M vanishes from the pools
Collateral damage far exceeded the strict amount stolen. CACAO collapsed as the attacker dumped tokens onto the network. Trading at roughly $0.115 before the exploit, the token plunged to $0.013 — a drop of nearly 89% — before a tentative bounce near $0.03.
That slide mechanically drained value out of every pool. Arbitrage traders scooped up the suddenly cheap CACAO and swapped it for bitcoin, ether, stablecoins and other assets. The post-mortem reconstruction pegs the pools’ total loss at about $10.9 million, broken down as follows:
| Component | Amount |
|---|---|
| CACAO depreciation | ~$6.4M |
| Third-party arbitrage gains | ~$2.9M |
| Assets directly stolen | ~$1.65M |
| Total pool value lost | ~$10.9M |
The distinction matters: the amount actually stolen by the attacker (~$1.65M) is only a fraction of what pools appear to have lost. The rest came from price slippage and opportunistic arbitrageurs profiting from the temporary imbalance.
« Sad news 😕 Will work to fix and recover in full. We carry on. »
@AaluxxMyth, Maya Protocol founder, on X
Bug bounty, Aztec and the path to recovery
The Maya Protocol team published the attacker’s bitcoin address (bc1q…l646) and said it hoped the funds would be returned in exchange for a bug bounty. If the hacker does not return the ~20 BTC, the team plans to recapitalize the pool using investments in Aztec Chain and other treasury levers.
According to the protocol, if the 20 BTC is returned to the pool, CACAO could revisit its pre-exploit price of $0.115. Yet a software patch alone will not fully restore the pools: most of the CACAO minted by the exploit has been swapped on other MAYAChain markets and is now mixed with tokens belonging to ordinary liquidity providers.
The team also stressed that the bulk of the loss came from extreme price slippage, abusive arbitrage trades and pool fees extracted by third parties during the instability window. Restarting swaps is conditional on a complete patch and an external audit of the affected modules.
Conclusion: a textbook case for cross-chain DeFi
The Maya Protocol affair highlights the structural fragility of cross-chain DeFi protocols, where the interconnection of pools mechanically amplifies the impact of a single routing error. An isolated bug — misclassifying a « lost » transaction — was enough to trigger a chain reaction that erased about $10.9 million in pool value.
Two scenarios now lie ahead: a fund return through the bug bounty, which could bring CACAO back to $0.115, or a recapitalization through Aztec Chain and the protocol’s treasury, combined with an overhaul of the refund modules. Either way, this episode will stand as a stark reminder of the importance of audits, invariant checks and circuit breakers in decentralized liquidity pools.
Sources
- CoinDesk – Maya Protocol exploit drains bitcoin and other assets as pool value drops $11 million (Aug 19, 2026)
- Binance Square – Post on the Maya Protocol incident (Aug 2026)
This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

