Maya Protocol Exploit Drains $1.7M, Sending CACAO Crashing 88.7%

2 hours ago 21
Maya Protocol exploit

A cross-chain exploit has forced Maya Protocol to shut down its entire network, after an attacker drained roughly $1.7 million in Bitcoin and other digital assets by chaining together six separate software flaws. The Maya Protocol exploit triggered a global halt on Wednesday and sent the project’s native CACAO token into a steep, almost instant collapse, raising fresh questions about how secure cross-chain infrastructure really is.

Key takeaways

  • Maya Protocol halted its cross-chain network after an attacker stole an estimated $1.7 million in crypto assets.
  • The attacker chained six separate software flaws together in a single transaction containing 23 messages.
  • About $1.36 million moved to external blockchains, while roughly $291,000 remained in attacker-controlled positions on MAYAChain.
  • The attacker took around 20 Bitcoin, worth about $1.4 million, plus another $300,000 in other assets.
  • CACAO’s price crashed 88.7%, falling from about $0.115 to $0.013 during the incident.

How the Maya Protocol exploit unfolded

The attack was not the result of a single bug but a carefully sequenced combination of weaknesses across the protocol’s transaction and accounting layers. Maya Protocol’s pseudonymous co-founder, known as Aalux, confirmed on Wednesday that the attacker made off with about 20 Bitcoin, worth roughly $1.4 million, along with an additional $300,000 in other assets, before the team activated a network-wide halt to stop further losses.

A preliminary technical analysis shared by Aalux traced the breach to a chain of six linked flaws touching trade accounts, outbound transaction processing, and liquidity pool calculations. Rather than exploiting one weak point, the attacker stitched these vulnerabilities into a single transaction containing 23 messages, letting several parts of MAYAChain’s system get manipulated almost simultaneously.

Manipulating a thin liquidity pool

According to the findings, the attacker first tricked the protocol’s own theft-detection mechanism into responding incorrectly. With that safeguard neutralized, they then inflated the value of a pool with limited liquidity, using that distortion to withdraw 48.87 million CACAO tokens from Maya’s Asgard module — the vault system that holds assets used to settle cross-chain swaps.

Because Maya Protocol lets users swap native assets across different blockchains without going through a centralized exchange, its vault and liquidity accounting systems sit at the center of every transaction. That centrality is exactly what made the exploit so damaging: a flaw in accounting logic didn’t just affect one trading pair, it rippled across the entire settlement process.

Quantifying the damage and the CACAO token crash

Independent blockchain security researcher Vini Barbosa, who reviewed the preliminary data, said CACAO plunged 88.7% during the incident, tumbling from around $0.115 to just $0.013. That kind of drop complicates any clean tally of losses, since the exploit hit both directly stolen funds and the market value of liquidity still sitting in Maya’s pools.

The technical analysis estimated total pool value fell by around $10.9 million, but researchers were careful not to label that entire figure as stolen funds — a meaningful chunk reflected arbitrage trading and CACAO’s own devaluation rather than assets the attacker actually pocketed. The more precise breakdown showed about $1.36 million moved out to external blockchains, while roughly $291,000 remained parked in attacker-controlled CACAO holdings and trade-account positions on MAYAChain itself.

This gap between headline exposure and actual extracted value matters for anyone trying to gauge the real severity of a cross-chain network hack. It’s a pattern that’s shown up repeatedly this year, where the number initially reported as “at risk” ends up far larger than what attackers ultimately walk away with.

Not an isolated incident in cross-chain DeFi

Maya’s shutdown fits into a broader, uncomfortable trend across interoperability protocols in 2026. In June, Axelar disabled bridge routes connected to Secret Network after roughly $4.7 million in bridged assets were taken through a flaw tied to a Secret-side smart contract, even as Axelar insisted its core infrastructure remained untouched.

Echo Protocol offers another instructive comparison. In May, an attacker minted about $76.7 million worth of unauthorized eBTC on Monad, yet security researchers later concluded the actual stolen value was closer to $816,000 — a massive gap between the headline mint and the real economic damage, similar in spirit to what’s now being untangled at Maya. That incident was linked to a compromised administrative private key, and Monad co-founder Keone Hon noted the underlying network kept operating normally throughout.

THORChain’s experience is perhaps the closest parallel. Blockchain investigator ZachXBT flagged losses of at least $10 million in May, and the protocol later confirmed approximately $10.7 million had been drained from one of its five vaults after a newly churned node operator exploited a flaw in its GG20 Threshold Signature Scheme to reconstruct a private key. Automatic solvency checks halted cross-chain signing within minutes. THORChain node operators then approved a recovery plan using protocol-owned liquidity — without minting new RUNE, selling RUNE, or diluting holders — and the network resumed trading after more than a month offline, on June 23.

Transit Finance also suffered a smaller-scale hit, losing about $1.88 million in May in an exploit flagged by security firm PeckShield, though it has yet to publish a detailed technical post-mortem.

Why cross-chain protocols keep getting hit

Each of these cases points to the same underlying vulnerability: cross-chain systems, by design, require multiple moving parts — validators, liquidity pools, vault modules, signature schemes — to talk to each other across separate blockchains. That complexity multiplies the attack surface. A July crypto.news review of cross-chain bridges noted that such systems can rely on lock-and-mint, burn-and-mint, or liquidity-based designs, with verification depending on validators, multisignature setups, or cryptographic proofs. Every additional layer is a potential point of failure, and Maya’s exploit shows how six modest flaws can be combined into one damaging sequence when no single check catches the full pattern.

For users and liquidity providers, this matters because a blockchain security breach of this kind doesn’t just cost the protocol — it erodes confidence in the entire cross-chain swap model, at a moment when interoperability is often pitched as DeFi’s next big unlock.

What comes next for Maya Protocol

Maya Protocol has not given a timetable for fully restoring swaps. Aalux said the global halt had contained further damage and that engineers were working on the fixes needed to bring cross-chain trading back online, focusing specifically on the trade-account behavior, outbound transaction handling, and liquidity calculations that allowed the 23-message transaction to succeed.

Whether Maya can rebuild trust quickly may depend on how transparently it documents the fix — and whether the broader CACAO token crash proves to be a temporary shock or a lasting dent in the protocol’s liquidity base once trading resumes.

FAQ

What was the cause of the Maya Protocol exploit?

The attack involved an exploitation of six linked software flaws within a single transaction containing 23 messages, manipulating trade accounts, outbound transaction processing, and liquidity pool calculations.

How did Maya Protocol respond to the $1.7 million exploit?

Maya Protocol activated a global halt to stop further losses and started working on fixes needed to restore cross-chain swaps.

What was the impact of the exploit on the CACAO token price?

CACAO’s token price dropped 88.7%, falling from about $0.115 to $0.013 during the incident.

How much cryptocurrency was stolen in the attack?

Approximately 20 Bitcoin worth about $1.4 million and $300,000 in other assets were stolen, with $1.36 million moved externally and $291,000 remaining in attacker-controlled positions.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article