Maya Protocol, a cross-chain liquidity protocol, halted its network on August 19, 2026 after an attacker stole an estimated $1.7 million in Bitcoin and other crypto assets by chaining six separate software flaws.
Pseudonymous co-founder AaluxxMyth confirmed the exploit, stating roughly 20 Bitcoin—worth about $1.4 million—and another $300,000 in assets were taken before a global halt was activated. Preliminary technical analysis traced the attack to vulnerabilities involving trade accounts, outbound transaction processing, and liquidity pool calculations, executed through a single transaction containing 23 messages.
The attacker first triggered the protocol’s theft-detection mechanism incorrectly, then manipulated a low-liquidity pool by inflating its value. This allowed a withdrawal of 48.87 million CACAO tokens from Maya’s Asgard module, which holds assets used to process cross-chain swaps. Approximately $1.36 million was moved to external blockchains, while another $291,000 remained under the attacker’s control in CACAO holdings and trade-account positions.
During the incident, CACAO collapsed 88.7%, falling from about $0.115 to $0.013. The total decline in pool value reached approximately $10.9 million, though researchers said that figure included arbitrage activity and the sharp devaluation of CACAO rather than all being directly stolen.
The Maya Protocol team is working on fixes to restore swaps, has halted trading to prevent further damage, and plans to invest in Aztec Chain as part of recovery. A bug bounty has also been announced offering a reward if the attacker returns funds. The incident follows other cross-chain exploits including THORChain's $10.7 million drain in May and Echo Protocol’s unauthorized eBTC mint, highlighting persistent DeFi security risks.