Maya Protocol Halts After $1.7M Exploit Drains CACAO
AI SummaryAI
- Maya Protocol suspended operations after an attacker chained six bugs to steal about $1.7 million from its liquidity pools.
- CACAO collapsed 88%, falling from $0.115 to $0.013 before recovering to around $0.032.
- The attacker withdrew 48.87 million CACAO after depositing 100 CACAO and claiming 99.93% ownership of a pool.
- On-chain data shows 20.83 BTC, worth about $1.34 million, was sent to a single Bitcoin address across roughly 10 blocks.
Crypto News
Maya Protocol has suspended operations after an attacker chained six bugs together to steal about $1.7 million from the protocol's liquidity pools, sending its native altcoin CACAO into an 88% collapse. Pseudonymous co-founder Aaluxx Myth disclosed the losses. According to the team, the attacker swapped the stolen CACAO for Bitcoin (BTC), Ethereum (ETH) and other assets, spreading the funds across every Maya liquidity pool. The exploit is the latest in a string of August breaches that have put DeFi security back in the spotlight. The attack was carried out through one transaction carrying 23 bundled instructions, a structure that convinced the network a theft had already taken place. The protocol then moved to make the pool whole, but because the payout logic had no upper bound, roughly 49 million CACAO was credited to a pool that was nearly empty. The credit was never backed by real funds — the reserve contained only 168,000 CACAO — so the transfer failed and the inflated balance stayed on the books. After depositing 100 CACAO and seizing 99.93% ownership of the pool, the attacker withdrew 48.87 million CACAO, close to half of the token's 100 million supply. The 88% collapse erased the token's value in a matter of blocks, underscoring how quickly the accounting flaw cascaded into a market-wide sell-off. CACAO dropped from $0.115 to as low as $0.013 before clawing back to roughly $0.032, leaving the token down more than 70% from its pre-exploit level. On-chain data shows the attacker sent 20.83 BTC — worth about $1.34 million — to one Bitcoin address over roughly 10 blocks. Founder Aaluxx Myth declared a global halt of the project on Discord and appealed to the attacker to give the funds back. The global halt, announced on Discord, freezes activity across Maya's pools while the team investigates the exploit and assesses the damage.
The Maya incident marks the 16th crypto hack logged in August alone, according to DefiLlama data that puts the 2026 total at 219 incidents worth $1.26 billion. That already exceeds the incident count for all of 2025, which recorded 146 hacks, even though last year's dollar losses were higher at $2.71 billion. The breach also carries a lineage angle: Maya forked from THORChain, the cross-chain liquidity protocol that lost $10.7 million to an exploit in May. The August tally underscores how persistent DeFi vulnerabilities have become, with attackers increasingly probing swap protocols and their parameter logic. In Maya's case, the exploit hinged on a compensation mechanism that had no upper bound — the system credited roughly 49 million CACAO to a pool that held almost nothing, and the credit was never funded because the reserve held only 168,000 CACAO. The attacker then claimed the phantom balance, an unfunded credit that resembled a failed airdrop, with a 100 CACAO deposit, taking 99.93% ownership of the pool and withdrawing 48.87 million tokens, nearly half of the total supply. Whether the attacker takes the team's bounty offer will determine how much of the loss is recovered. Aaluxx Myth also said the project will contact arbitrage traders who absorbed pool value during the sell-off, meaning the final loss figure could shift as funds are clawed back. For a protocol that forked from THORChain — itself a May victim — the episode reinforces that inherited codebases require independent audit scrutiny. The 2026 figures, compiled from publicly reported incidents, show that exploit frequency has accelerated even as the average dollar impact has moderated compared with 2025, with attackers spreading their focus across a wider range of targets rather than concentrating on the largest bridges.
The exploit's root cause, laid out in the team's incident disclosure, was a compensation payout with no upper limit: the protocol credited 49 million CACAO to a nearly empty pool, and the unfunded balance was claimed by the attacker. On-chain data confirms the scale — 48.87 million CACAO withdrawn and 20.83 BTC sent to a single address — consistent with the roughly $1.7 million loss disclosed by the team. The remediation, a global halt and a bounty offer, hinges on the attacker's response, which has not yet been disclosed. For an industry already tracking 219 exploits this year, the episode is a reminder that parameter-validation flaws can be as costly as private-key compromises — and that all-time highs in altcoins can evaporate in a single block. The lesson applies across DeFi, from swap protocols to lending markets such as Aave.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.
Comments
More From COINOTAG
Tom Lee Flags Ethereum (ETH) Breakout as ETH/BTC Ratio Hits 0.02994
August 18, 2026 at 05:17 AM UTC
BLACKROCK MOVES $21.8M IN BTC ETH BlackRock withdrew 226.5 $BTC ($14.4M) from its Coinbase Prime wallet and deposited...
August 13, 2026 at 03:15 PM UTC
BitMart Token BMX Faces $10.1M Withdrawal Freeze
August 10, 2026 at 07:31 PM UTC

