Maya Protocol loses $1.7M as six-bug exploit exposes DeFi security gaps

- Maya Protocol lost about $1.7 million after a hacker exploited six bugs involving accounting, liquidity and outbound transactions.
- CACAO crashed nearly 89%, falling from $0.115 to $0.013 as the attacker moved millions of tokens and other assets.
- The attack echoes THORChain’s $10.7 million exploit, showing how multiple small vulnerabilities can become dangerous when combined.
Maya Protocol fell victim to a hacker this week who exploited a flaw that points to a bigger issue, namely, that tools for defense have issues keeping up with sophisticated hacks. Blockchain security firm CertiK has estimated that the total direct loss was about $1.7 million as the hacker deceived Maya into awarding a nonexistent subsidy and then repeatedly added and removed liquidity to extract assets from shared pools.
The aftermath of the attack hit Maya’s liquidity providers and CACAO holders straightaway. What is more important is that the vulnerabilities were not just the direct result of a broken line of code. It took advantage of regular protocol logic behaving differently than what was expected of it, making this type of attack undetectable until it was already too late to stop it.
How the attacker gamed Maya’s accounting
According to CertiK, which identified the event on August 19, the hacker caused a misrepresentation of Maya’s internal accounting through a fake subsidy, only to finally alter liquidity positions to withdraw an estimated 48.87 million CACAO and 98.82 LINK. DefiLlama Hacks and Exploits Database classified the August 18 occurrence as “Protocol Logic,” attributing a loss of $1.7 million.
The greater harm was considerably more significant. Developer Vini Barbosa called it a “sophisticated 6-bug exploit” that took over $1.36 million in hard assets out of the protocol but had an overall impact of close to $11 million given the collapse of the price of CACAO. According to him, the token fell from $0.115 to $0.013 in less than 240 blocks and registered a drop of nearly 89%.
Aaluxx, one of Maya’s founders, recognized the damage on the same day. He added that the team will “work to fix and recover in full.”
A pattern THORChain already lived through
Maya is a friendly offshoot of THORChain, which experienced its own $10.7 million hack in May. In its post-mortem analysis, THORChain said a new node operator took advantage of vulnerabilities in the network’s GG20 threshold-signature system, and the system’s solvency checks only noticed there was an issue after the hack was over.
Aaluxx subsequently clarified in THORChain’s community podcast that the hacking was based on three older bugs that were not dangerous on their own, but when combined could prove problematic. He went on to say that Maya also had this same latent flaw.
In order to determine the cause of the hack, an extremely in-depth forensic investigation was required. The team had to examine cryptographic configuration parameters and search for insignificant prime numbers that should not be present in order to pinpoint the infected vaults. This essentially opens up a general flaw for the defenders: a simple balance monitor can potentially detect losses once the funds have already changed hands, by which point it may already be too late to prevent the attack from continuing.
What upgrading the defense actually looks like
Aaluxx cautioned that AI technology is enabling small teams to investigate codebases from a larger number of perspectives simultaneously. This is useful for defenders, but it also results in more methods for attackers to uncover unique vulnerabilities that existing auditing processes may fail to detect.
His chosen solution was redundancy rather than depending on one system. Maya and THORChain did not go with an integration approach but chose to remain independent instead. In this way, Maya could continue carrying out swaps using a verifiable healthy vault while THORChain was inactive for weeks.
The comparison is particularly interesting because THORChain’s own post-mortem says its root cause was not one dramatic flaw but three older bugs that became exploitable when chained together. THORChain also explicitly notes that the same latent bug existed on Maya but had not previously been exploited.
| Metric | Maya Protocol / MAYAChain | THORChain |
|---|---|---|
| Incident date | Aug. 18, 2026, around 17:30 UTC | May 15, 2026 |
| Loss | About $1.7 million in total attacker value; roughly $1.36 million extracted to external chains | About $10.7 million drained from one vault |
| Assets affected | 20.83 BTC + 48.87 million CACAO, plus other assets | BTC, ETH, BNB and Base-chain assets |
| Root cause | Six chained vulnerabilities involving the Trade Account and outbound-flow logic; the attack exploited interactions between otherwise non-catastrophic bugs | Three older bugs chained together, including a vulnerability involving the GG20 threshold-signature scheme |
| Detection / response | Exploit activity triggered an emergency halt; the attacker executed the exploit before the network was stopped | On-chain investigators, including ZachXBT and PeckShield, flagged suspicious activity; THORChain’s automatic controls then suspended signing/trading |
| Protocol relationship | MAYAChain is a friendly fork of THORChain, sharing much of its architecture/code | Original cross-chain liquidity protocol |
| Security lesson | Multiple individually manageable bugs can become catastrophic when combined with liquidity/accounting and outbound-flow weaknesses | Redundancy, automated detection, and signing controls can limit the blast radius of a vault compromise |
How can DeFi protocols prevent chained exploits?
Protocols need to test interactions between security controls, not just individual vulnerabilities. Maya’s incident shows how false theft detection, faulty outbound-transaction handling, and liquidity-accounting errors could become dangerous when combined. Stronger defenses include invariant testing, adversarial simulation of multi-step attack paths, independent review of accounting logic, real-time anomaly detection, and automatic circuit breakers for abnormal withdrawals or pool balances. Research published this month similarly argues for multi-layer detection and defense rather than relying on a single security mechanism.
| Time / Date | Event | How to cite it |
|---|---|---|
| Aug. 18, 2026 | Exploit occurs. On-chain activity shows the attacker exploiting MAYAChain’s accounting/outbound-flow vulnerabilities and extracting CACAO and BTC. Maya, founder of AaluxxMyth, publicly described the hack on Aug. 18. | Incident date: Aug. 18, 2026 |
| Aug. 18, 2026 | MAYAChain halts trading/transactions to contain the exploit and begins remediation. | Same incident date |
| Aug. 18–19, 2026 | Exploit analysis emerges. Researchers reconstruct the six-bug chain, including the false theft alert, incorrect compensation and accounting failure. | Treat as post-incident analysis, not a second incident |
| Aug. 19, 2026 | Broader reporting and technical write-ups appear. CoinDesk’s report published Aug. 19 describes the Aug. 18 attack and reconstructs the losses. | Reporting date: Aug. 19 |
| Aug. 19, 2026 | Some data providers/security feeds label the event Aug. 19, likely reflecting their UTC/time-zone convention or the date their incident record was created/updated. | Do not use as the primary incident date without qualification |
These block-level figures are reported in the incident reconstruction and provide a particularly useful way to connect exploit mechanics → asset extraction → token-price damage.
| MAYAChain block | Event | Quantitative impact |
|---|---|---|
| 17,977,941 | 23-message exploit transaction executed | Six-bug exploit chain initiated |
| 17,977,971 | Attacker adds/withdraws liquidity from manipulated pool | ~48.87M CACAO extracted |
| 17,977,998–17,978,008 | CACAO rapidly swapped into BTC | 20.83 BTC moved externally |
| 17,978,094 | CACAO reaches post-exploit low | About 88.7% below pre-exploit level |
| 17,978,500+ | Partial recovery begins | CACAO moves back toward approximately $0.03 |
Damage containment
Data from the industry points to the importance of reinforcing defenses. According to TRM Labs, there were 207 hacks in the world of cryptocurrency in the first six months of 2026, the largest number ever recorded in a half-year period, and it states that smart contracts are increasingly being attacked in several different ways rather than just one flaw. The Maya exploit fits that trend perfectly.
The conclusion reached is that it can no longer be possible to secure DeFi without identifying and fixing particular bugs. Protocols must involve multilayer monitoring, use of various review mechanisms independently, installation of the quick halt mechanism in case of an emergency, and the ability to implement the fixes before the questionable transaction becomes irreversible.
Maya not only wants to resolve the issue at hand. Aaluxx indicated that the company intends to accelerate the development of Aztec Chain, an omnichain DeFi project based on what has been learned from their prior projects, Maya, THORChain, and Rujira. If those lessons could help them build better solutions rather than simply restart the cycle of fixing defects, the Maya incident can turn out to be more valuable than the loss of $1.7 million suggests.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What is CACAO?
CACAO is the native token of Maya Protocol's MAYAChain, a decentralized cross-chain liquidity network. It serves as the common asset connecting liquidity pools and helps facilitate native-asset swaps across supported blockchains. Maya Protocol is a friendly fork of THORChain.
When did the Maya Protocol hack happen?
The Maya Protocol exploit occurred on Aug. 18, 2026. The attacker chained six software flaws in a single transaction containing 23 messages, ultimately extracting about $1.7 million in Bitcoin and other crypto assets. Maya then halted the network to contain the attack.
How did the attacker game Maya Protocol's accounting?
The attacker exploited a sequence of bugs that caused MAYAChain to create a false balance in a low-liquidity pool. A faulty compensation mechanism credited roughly 49 million CACAO even though the underlying reserve held only about 168,000 CACAO. Another bug allowed that inflated balance to remain recorded after the attempted transfer failed. The attacker then deposited a small amount, gained more than 99% of the distorted pool and withdrew 48.87 million CACAO, swapping it for real assets including Bitcoin.
How much did the Maya Protocol exploit cost?
CertiK and DefiLlama both put the direct loss at about $1.7 million, while developer Vini Barbosa estimated roughly $11 million in total impact once the CACAO token price collapsed.
Is this exploit connected to the earlier THORChain hack?
Maya runs a friendly fork of THORChain, which lost roughly $10.7 million in May 2026, and co-founder Aaluxx has said the same latent bug existed in Maya's code, tracing both incidents to older flaws that became dangerous only when chained together.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar
Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.
















