TL;DR
-
Maya Protocol halted trading on MAYAChain after six interacting software bugs produced a false liquidity-pool balance.
-
An attacker directly extracted nearly $1.7 million in Bitcoin and other assets.
-
The exploit created approximately 49 million unfunded CACAO tokens in the network’s records.
Cross-chain liquidity provider Maya Protocol has halted its MAYAChain network after a series of software failures allowed an attacker to drain nearly $1.7 million in Bitcoin and other digital assets.
The resulting collapse of the protocol’s CACAO token triggered further losses across its liquidity pools, bringing the total financial impact to approximately $11 million.
Maya Protocol founder AaluxxMyth said the attacker extracted 20 BTC, worth roughly $1.4 million, alongside approximately $300,000 in other assets. The protocol suspended all trading to contain the damage and said swaps would remain unavailable while developers worked on a fix.
“Sad news,” AaluxxMyth said on X. “Will work to fix and recover in full. We carry on.”
Sad news 😕
— Aaluxx⚡️🍫🛡️ (@AaluxxMyth) August 18, 2026
Will work to fix and recover in full. We carry on. @Maya_Protocol pic.twitter.com/EYK9BeWWLI
Six Bugs Combined to Create the Exploit
MAYAChain allows users to exchange assets such as Bitcoin and Ether without first transferring them through a centralized cryptocurrency exchange.
Trades are completed through pools of digital assets supplied to the network, while CACAO serves as the common token connecting those markets.
A technical reconstruction reportedly identified six software bugs that had to interact for the attack to succeed.
The incident began when MAYAChain incorrectly determined that an outgoing transaction had gone missing. This activated a safety mechanism designed to compensate a liquidity pool when assets are lost or stolen.
However, the system miscalculated the required compensation and attempted to add approximately 49 million CACAO to a relatively small pool.
MAYAChain’s reserve contained only around 168,000 CACAO, meaning it could not fund the payment.
The compensation transfer ultimately failed because the protocol did not have enough CACAO in reserve. However, another software bug meant the pool’s inflated balance had already been recorded.
MAYAChain failed to reverse the accounting change after the transaction was rejected. The network therefore continued operating as if the liquidity pool genuinely held the additional 49 million CACAO.
This false balance created an opportunity for the attacker.
By depositing a relatively small amount into the affected pool, the attacker acquired more than 99% of its ownership. They then withdrew approximately 48.87 million CACAO and started exchanging the tokens for Bitcoin, Ether, and other assets held across MAYAChain’s liquidity pools.
The incident shows how a failed transaction can still cause major losses if a blockchain updates its internal accounting before confirming that the underlying transfer succeeded.
Attacker Moved Bitcoin to an External Address
On-chain records indicate that 20.83 BTC, worth approximately $1.34 million at the time, was transferred to the attacker’s Bitcoin address.
The technical analysis confirmed that around $1.36 million in assets moved from MAYAChain onto external blockchains. A further 8.87 million CACAO remained in the attacker’s wallet on the network.
Maya Protocol estimated that the attacker directly extracted close to $1.7 million across Bitcoin and other assets.
However, the wider financial damage was significantly larger because the exploit undermined CACAO’s price and distorted the value of assets held in the protocol’s other pools.
CACAO Plunges Nearly 89%
CACAO traded at approximately $0.115 before the exploit but fell as low as $0.013 as the attacker sold the newly acquired tokens.
That represented a decline of nearly 89%. CACAO subsequently recovered to around $0.03 but remained substantially below its pre-attack price.
The collapse enabled arbitrage traders to purchase heavily discounted CACAO and exchange it for Bitcoin, Ether, stablecoins and other assets held by MAYAChain.
Although those trades may have followed the protocol’s ordinary rules, they drained additional value from liquidity providers because the internal pools could not adjust quickly enough to CACAO’s sudden depreciation.
The secondary outflows reportedly raised the overall loss to approximately $11 million, far exceeding the amount taken directly by the original attacker.
Maya Protocol has not provided a timeline for restoring swaps. Before restarting the network, developers will need to correct the accounting and compensation flaws, assess the remaining liquidity, and determine how affected users will be reimbursed.
Hassan Maishera