Maya Protocol Halts MAYAChain After Six Bugs Trigger $1.7M Attack
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- An attacker used six software bugs to steal about $1.7 million from Maya Protocol.
- Maya Protocol stopped the network to prevent further losses while developers worked on fixes.
- CACAO dropped nearly 89% during the attack, pushing the wider pool decline to about $10.9 million.
Maya Protocol, a cross-chain liquidity protocol, halted MAYAChain today after an attacker exploited six software flaws to steal about $1.7 million. Pseudonymous co-founder Aalux said the attacker took about 20 Bitcoin worth roughly $1.4 million. The attacker also obtained about $300,000 in other crypto assets. Maya stopped network activity to prevent further losses and began preparing software fixes.
BREAKING: Maya Protocol halts network after attacker exploits bugs to drain $1.7M from DEX.
— MSB Intel (@MSBIntel) August 19, 2026
A preliminary review found that the attacker combined six bugs within one transaction containing 23 messages. The attacker triggered a bug that made MAYAChain incorrectly classify an outbound transaction as missing. The false alert activated MAYAChain’s theft-response system, which compensates liquidity pools when outbound assets disappear.
However, another calculation bug credited roughly 49 million CACAO to a low-liquidity pool during the false compensation process. Maya’s reserve held about 168,000 CACAO, so the system lacked enough tokens to complete the transfer. Another bug saved the 49 million CACAO balance in MAYAChain’s records even though the actual transfer failed.
MAYAChain continued calculating ownership against the false balance because the network failed to reverse the accounting change. The attacker then deposited a small amount into the distorted pool. The false balance caused MAYAChain to calculate that the attacker controlled more than 99% of the pool. The attacker used that position to withdraw 48.87 million CACAO from Maya’s Asgard module.
Maya Protocol Faces Wider Losses
The attacker exchanged the withdrawn CACAO for Bitcoin, Ethereum, and other crypto held across MAYAChain liquidity pools. On-chain records showed the attacker transferred 20.83 BTC from MAYAChain to an external Bitcoin address during the exploit. The transferred Bitcoin carried an estimated value of about $1.34 million. The preliminary review traced about $1.36 million in extracted assets from MAYAChain to external blockchains.
The attacker retained another 8.87 million CACAO in a MAYAChain wallet after exchanging part of the withdrawn tokens. The attacker also controlled trade-account positions that remained inside MAYAChain after developers halted the network. The analysis valued the remaining CACAO holdings and trade-account positions at approximately $291,000. It estimated about $1.65 million in direct attacker gains after including external transfers and remaining assets.
Meanwhile, CACAO’s value fell sharply while the attacker exchanged millions of withdrawn tokens through MAYAChain pools. The rapid decline created price differences that allowed arbitrage traders to profit from distorted pool prices.
Arbitrage traders bought discounted CACAO and exchanged it for Bitcoin, Ether, stablecoins, and other assets in MAYAChain pools. Those trades reduced pool assets beyond the funds that the original attacker directly extracted. The technical reconstruction estimated that CACAO’s collapse, arbitrage, and direct extraction reduced MAYAChain pool value by about $10.9 million.
Developers Work to Restore Swaps
Maya developers are fixing trade-account, outbound-processing, and liquidity-calculation flaws before they restart cross-chain swaps. Maya has not announced when MAYAChain will resume swaps because developers must complete and review the required fixes.
Sad news 😕
Will work to fix and recover in full. We carry on. @Maya_Protocol pic.twitter.com/EYK9BeWWLI— Aaluxx⚡️🍫🛡️ (@AaluxxMyth) August 18, 2026
Maya’s team offered the attacker a bug bounty in hopes of recovering crypto removed during Wednesday’s exploit. The team will seek ways to replace roughly 20 BTC if the attacker refuses to return the funds.
Meanwhile, THORChain also halted trading in May after a node operator exploited a vulnerability and drained about $10.7 million from one vault. Its automatic solvency checks stopped cross-chain signing and trading within minutes of the attack. Node operators later approved ADR028, which used protocol-owned liquidity to absorb losses without minting or selling additional RUNE. THORChain restored network trading on June 23 after developers checked its vaults and key shares.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







