On August 19, the developers of the cross-chain project Maya Protocol decided to suspend network operations after a hacking incident that resulted in losses estimated at approximately $1.7 million. This announcement was made by co-founder Aaluxx.
Sad news 😕
— Aaluxx⚡️🍫🛡️ (@AaluxxMyth) August 18, 2026
Will work to fix and recover in full. We carry on. @Maya_Protocol pic.twitter.com/EYK9BeWWLI
The hacker managed to steal 20 BTC, valued at about $1.4 million, along with other digital assets totaling around $300,000. This information was corroborated by specialists at PeckShield, who identified the hacker's address.
#PeckShieldAlert @Maya_Protocol has reported that they were exploited for ~$1.7M worth of crypto, with the majority - 20 $BTC ($1.34M) - sitting in bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646https://t.co/v4AUjEUEcK pic.twitter.com/4dUt9dXZi0
— PeckShieldAlert (@PeckShieldAlert) August 19, 2026
Details of the Attack
According to information from the Maya team, the breach occurred due to a vulnerability in transaction processing. The protocol failed to detect already executed withdrawals and mistakenly activated a compensation mechanism. The hacker exploited this by creating a fake pool into which the system erroneously credited nearly 50 million unsupported CACAO tokens.
Subsequently, the hacker contributed 100 legitimate CACAO tokens, which granted them access to 99.93% of the pool's assets, allowing them to withdraw 48.87 million real tokens, effectively depleting the protocol's reserves. The stolen assets were then exchanged for Bitcoin, Ethereum, RUNE, and stablecoins.
This incident caused the price of CACAO to plummet by 88.7%, dropping from $0.115 to $0.013. However, developers later reported that the token had partially recovered to $0.032.
The root of the issue was linked to new trading account code transferred from THORChain in mid-2025, which was not integrated with the solvency verification system. Aaluxx mentioned that this vulnerability went unnoticed for several years by auditors from Halborn, as well as by checks using the Fable 5 model from Anthropic, and the broader community.
And as a side note, the bugs exploited were not caught by Halborn audit, nor Fable 5 audit, nor all humanity for 3-4 years. We have to get even more adversarial and look for extremely simple code primitives. We already knew our job was difficult, but the mission is worth it. https://t.co/nFbnhhsXyg
— Aaluxx⚡️🍫🛡️ (@AaluxxMyth) August 19, 2026
Currently, developers are working to resolve the issue and are preparing to restart the network. The co-founder is optimistic about raising $1.4 million through investments in AZTECChain and has also proposed a bounty for the hacker in exchange for the return of the stolen funds.
It is worth noting that in May 2026, THORChain, the fork from which Maya Protocol is derived, lost approximately $10.7 million due to an attack involving a compromised network node.