Cointelegraph
DOGE$0.07001 0.20%
TRX$0.3330 0.01%
LINK$9.75 3.22%
ZEC$507.36 0.31%
ADA$0.1737 0.41%
XRP$1.00 0.79%
ETH$1,917.86 1.12%
BTC$64,354.51 0.33%
XMR$414.48 0.42%
BNB$602.64 0.19%
XLM$0.1560 1.51%
SOL$77.22 1.69%
HYPE$58.30 2.04%
Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor

MAYAChain halts network after estimated $1.7M exploit

Latest NewsPublishedAug 19, 2026

A preliminary analysis says six chained bugs let a 23-message transaction drain 48.87 million CACAO, sending the token down nearly 89%.

[Update, 09:25 UTC, Aug. 19: Adds details on the exploit mechanics and its impact on MAYAChain’s liquidity pools.]

Cross-chain decentralized exchange (DEX) Maya Protocol halted its network after an attacker exploited a series of software flaws to obtain an estimated $1.7 million in crypto.

On Wednesday, Maya Protocol’s pseudonymous co-founder Aalux said the attacker stole about 20 Bitcoin worth $1.4 million and another $300,000 in assets. They said the halt prevented further damage and the team had started working on a fix to resume swaps.

A preliminary technical analysis shared by Aalux attributed the incident to six chained bugs involving trade accounts, outbound transaction handling and liquidity pool calculations. 

While the analysis put the attacker’s haul at about $1.7 million, it estimated that MAYAChain’s pools lost about $10.9 million in value, including losses from arbitrage and CACAO’s collapse.

Cointelegraph reached out to Aalux and the Maya team for more information but did not receive a response. 

How the MAYAChain exploit unfolded

Maya Protocol is a cross-chain network built from THORChain’s open-source code and designed to complement it. CACAO is MAYAChain’s gas and settlement token and is paired with supported assets in its liquidity pools. 

According to the analysis, the transaction overwrote records tracking outbound transfers, causing transfers to be classified as missing. This activated a theft-protection mechanism, which miscalculated compensation for Maya’s low-liquidity Arbitrum Chainlink (ARB.LINK) pool and incorrectly credited it with 49.45 million CACAO.

Related: BitBox patches ‘severe’ wallet flaws that could put funds at risk

The transfer intended to fund that credit failed because Maya’s reserve held insufficient CACAO, but the inflated pool balance remained. The attacker then added negligible liquidity, acquired 99.93% of the pool and withdrew 48.87 million CACAO from Asgard, which holds protocol assets.  

Independent blockchain security researcher Vini Barbosa summarized the findings and noted that CACAO fell by 88.7%, from approximately $0.115 to $0.013 during the incident. 

Aalux said the team would seek the return of the stolen funds through a bug bounty and work to restore liquidity. 

Magazine: ‘Fabricated rumors’ about BitMart founder, Binance bStocks dominate: Asia Express


1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject