Maya Protocol Halts Network After $1.7M Exploit Crashes CACAO 89%

By Giuseppe Ciccomascolo // August 19, 2026 @ 12:51 PM Make AlphaWire Logo preferred on Google News

Share

659 Stripe Merchant API Keys Leak Alongside 688,000 Customer Records, but Stripe Wasn’t Hacked

Share

Points of Focus

  • Maya Protocol halted its cross-chain network after an estimated $1.7-million exploit.
  • The attacker chained six vulnerabilities through one transaction.
  • Around $1.4 million was transferred to external blockchains.

 

Maya Protocol has suspended its cross-chain network after an attacker exploited six interconnected software flaws and extracted an estimated $1.7 million in Bitcoin (BTC) and other digital assets.

The protocol activated a global halt to prevent further losses while developers investigated the incident and prepared fixes. Maya Protocol has not announced when cross-chain swaps will resume.

Pseudonymous co-founder Aalux said the attacker obtained about 20 BTC, valued at $1.4 million, alongside another $300,000 in crypto assets.

 

Attacker chained six vulnerabilities

Preliminary technical findings indicate that the attacker combined six bugs affecting trade accounts, outbound transaction processing and liquidity pool calculations.

Rather than exploiting a single weakness, the attacker executed the entire sequence through one transaction containing 23 messages. The transaction allegedly triggered Maya Protocol’s theft-detection mechanism incorrectly before manipulating a pool with limited liquidity.

 

 

By artificially inflating the value of that pool, the attacker reportedly withdrew 48.87 million CACAO tokens from Maya’s Asgard module. Asgard modules hold assets used to process swaps between blockchains, making their accounting and security critical to Maya Protocol’s operations.

Initial estimates show that about $1.36 million was transferred to external blockchains.

Another $291,000 remained under the attacker’s control through CACAO holdings and trade-account positions on MAYAChain.

 

CACAO collapses as liquidity drains

CACAO, the protocol’s native token, fell by 89% during the incident, dropping from $0.115 to $0.013, according to blockchain security researcher Vini Barbosa.

The crash complicated estimates of the total damage. Preliminary analysis placed the decline in pool value at about $10.9 million.

 

 

However, that figure includes arbitrage activity and the sharp depreciation of CACAO rather than only assets stolen by the attacker.

The amount extracted or retained in attacker-controlled positions remains closer to $1.7 million.

 

Cross-chain security risks grow

Maya Protocol joins several cross-chain platforms forced to suspend operations following security incidents in 2026. THORChain halted trading after approximately $10.7 million was drained from one of its vaults, while Axelar disabled routes linked to Secret Network following a $4.7-million exploit.

Such incidents highlight the risks created by cross-chain systems, which rely on multiple vaults, validators, liquidity pools and transaction-verification components to move assets between separate networks.

 

 

Developers are now working to address the vulnerabilities before restoring swaps. Aalux said the global halt successfully contained the incident and prevented additional losses.

However, recovery will likely require comprehensive testing of the affected accounting, outbound-processing, and theft-detection systems. 

Until Maya Protocol releases a technical post-mortem and restart plan, the timeline for resuming full network operations remains unclear.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles