Maya Protocol Halts Network After $1.7 Million Exploit, CACAO Plunges 88%

2 hour ago 3 sources negative

Key takeaways:

  • Cross-chain swap protocols face systemic exploit risk, threatening confidence in RUNE and CACAO.
  • CACAO's 88.7% collapse amplifies liquidity provider losses beyond the $1.7 million theft.
  • Watch for prolonged outflows from cross-chain protocols until security audits and swaps resume.

Maya Protocol, a cross-chain liquidity protocol, halted its network on August 19, 2026 after an attacker stole an estimated $1.7 million in Bitcoin and other crypto assets by chaining six separate software flaws.

Pseudonymous co-founder AaluxxMyth confirmed the exploit, stating roughly 20 Bitcoin—worth about $1.4 million—and another $300,000 in assets were taken before a global halt was activated. Preliminary technical analysis traced the attack to vulnerabilities involving trade accounts, outbound transaction processing, and liquidity pool calculations, executed through a single transaction containing 23 messages.

The attacker first triggered the protocol’s theft-detection mechanism incorrectly, then manipulated a low-liquidity pool by inflating its value. This allowed a withdrawal of 48.87 million CACAO tokens from Maya’s Asgard module, which holds assets used to process cross-chain swaps. Approximately $1.36 million was moved to external blockchains, while another $291,000 remained under the attacker’s control in CACAO holdings and trade-account positions.

During the incident, CACAO collapsed 88.7%, falling from about $0.115 to $0.013. The total decline in pool value reached approximately $10.9 million, though researchers said that figure included arbitrage activity and the sharp devaluation of CACAO rather than all being directly stolen.

The Maya Protocol team is working on fixes to restore swaps, has halted trading to prevent further damage, and plans to invest in Aztec Chain as part of recovery. A bug bounty has also been announced offering a reward if the attacker returns funds. The incident follows other cross-chain exploits including THORChain's $10.7 million drain in May and Echo Protocol’s unauthorized eBTC mint, highlighting persistent DeFi security risks.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.