Maya Protocol Halts After $1.7M Exploit Drains CACAO
Maya Protocol halted after a $1.7M exploit drained its liquidity pools; CACAO collapsed 88% as the attacker converted funds to BTC and ETH.
AI SummaryAI
- Maya Protocol suspended operations after an attacker chained six bugs to steal about $1.7 million from its liquidity pools.
- CACAO collapsed 88%, falling from $0.115 to $0.013 before recovering to around $0.032.
- The attacker withdrew 48.87 million CACAO after depositing 100 CACAO and claiming 99.93% ownership of a pool.
- On-chain data shows 20.83 BTC, worth about $1.34 million, was sent to a single Bitcoin address across roughly 10 blocks.
Maya Protocol has suspended operations after an attacker chained six bugs together to steal about $1.7 million from the protocol's liquidity pools, sending its native altcoin CACAO into an 88% collapse. Pseudonymous co-founder Aaluxx Myth disclosed the losses. According to the team, the attacker swapped the stolen CACAO for Bitcoin (BTC), Ethereum (ETH) and other assets, spreading the funds across every Maya liquidity pool. The exploit is the latest in a string of August breaches that have put DeFi security back in the spotlight. The attack was carried out through one transaction carrying 23 bundled instructions, a structure that convinced the network a theft had already taken place. The protocol then moved to make the pool whole, but because the payout logic had no upper bound, roughly 49 million CACAO was credited to a pool that was nearly empty. The credit was never backed by real funds — the reserve contained only 168,000 CACAO — so the transfer failed and the inflated balance stayed on the books. After depositing 100 CACAO and seizing 99.93% ownership of the pool, the attacker withdrew 48.87 million CACAO, close to half of the token's 100 million supply. The 88% collapse erased the token's value in a matter of blocks, underscoring how quickly the accounting flaw cascaded into a market-wide sell-off. CACAO dropped from $0.115 to as low as $0.013 before clawing back to roughly $0.032, leaving the token down more than 70% from its pre-exploit level. On-chain data shows the attacker sent 20.83 BTC — worth about $1.34 million — to one Bitcoin address over roughly 10 blocks. Founder Aaluxx Myth declared a global halt of the project on Discord and appealed to the attacker to give the funds back. The global halt, announced on Discord, freezes activity across Maya's pools while the team investigates the exploit and assesses the damage.
The Maya incident marks the 16th crypto hack logged in August alone, according to DefiLlama data that puts the 2026 total at 219 incidents worth $1.26 billion. That already exceeds the incident count for all of 2025, which recorded 146 hacks, even though last year's dollar losses were higher at $2.71 billion. The breach also carries a lineage angle: Maya forked from THORChain, the cross-chain liquidity protocol that lost $10.7 million to an exploit in May. The August tally underscores how persistent DeFi vulnerabilities have become, with attackers increasingly probing swap protocols and their parameter logic. In Maya's case, the exploit hinged on a compensation mechanism that had no upper bound — the system credited roughly 49 million CACAO to a pool that held almost nothing, and the credit was never funded because the reserve held only 168,000 CACAO. The attacker then claimed the phantom balance, an unfunded credit that resembled a failed airdrop, with a 100 CACAO deposit, taking 99.93% ownership of the pool and withdrawing 48.87 million tokens, nearly half of the total supply. Whether the attacker takes the team's bounty offer will determine how much of the loss is recovered. Aaluxx Myth also said the project will contact arbitrage traders who absorbed pool value during the sell-off, meaning the final loss figure could shift as funds are clawed back. For a protocol that forked from THORChain — itself a May victim — the episode reinforces that inherited codebases require independent audit scrutiny. The 2026 figures, compiled from publicly reported incidents, show that exploit frequency has accelerated even as the average dollar impact has moderated compared with 2025, with attackers spreading their focus across a wider range of targets rather than concentrating on the largest bridges.
In a published post-mortem, the Maya team disclosed that the six vulnerabilities had gone undetected for three to four years despite security audits by Halborn and Fable 5, prompting a pledge to adopt a more adversarial code-review process. The team updated its loss estimate to roughly $1.65 million, with about $1.36 million moved to external blockchains and $291,000 still on-chain. If the attacker does not accept the bug bounty, Maya said it intends to recover approximately 20 BTC through investments in Aztec Chain and other means, returning the funds to the affected pool. The recovery plan underscores the team's effort to restore losses while emphasizing the longevity of the undetected flaws.
(as of 21:09 UTC) The exploit's root cause, laid out in the team's incident disclosure, was a compensation payout with no upper limit: the protocol credited 49 million CACAO to a nearly empty pool, and the unfunded balance was claimed by the attacker. On-chain data confirms the scale — 48.87 million CACAO withdrawn and 20.83 BTC sent to a single address — consistent with the roughly $1.7 million loss disclosed by the team. The remediation, a global halt and a bounty offer, hinges on the attacker's response, which has not yet been disclosed. For an industry already tracking 219 exploits this year, the episode is a reminder that parameter-validation flaws can be as costly as private-key compromises — and that all-time highs in altcoins can evaporate in a single block. The lesson applies across DeFi, from swap protocols to lending markets such as Aave.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


