Technology

Maya Protocol Exploit Halts Cross-Chain Network After $1.7 Million Drain

Maya Protocol MAYAChain cross-chain exploit August 2026
A six-bug exploit on MAYAChain drained Bitcoin and other assets even as majors rallied, underlining that protocol risk does not take a holiday in a squeeze. AXT News

Maya Protocol halted MAYAChain on 18 August after an attacker chained six software flaws to drain about $1.7 million in Bitcoin and other assets from the THORChain-style cross-chain swap network. Co-founder Aalux said the theft included roughly 20 BTC (about $1.4 million) plus some $300,000 in other tokens. The native CACAO token collapsed nearly 89%, from about $0.115 to $0.013. Independent reconstructions put the drop in pool value near $10.9 million — most of it token devaluation and arbitrage, not coins the attacker pocketed.

The incident landed in the same 48-hour window as Bitcoin's bounce toward $70,000. That contrast is the point. A risk-on tape in majors does not reduce smart-contract or cross-chain accounting risk. Liquidity protocols that settle Bitcoin, ether, and Arbitrum assets in the same pools remain a concentrated failure surface.

How the Attack Worked

Researchers say a single MsgDeposit transaction carrying 23 messages overwrote the protocol's observed-transaction voter. MAYAChain then treated a legitimate LINK transfer as stolen and paid an uncapped slash subsidy of about 49.45 million CACAO into a tiny ARB.LINK pool that held roughly 0.11 LINK. The reserve could not fund that credit. Thirty blocks later the attacker deposited a trivial amount, received about 99.93% of the distorted pool, and withdrew 48.87 million CACAO from the Asgard module.

About $1.36 million left for external chains; roughly $291,000 stayed in attacker-controlled on-chain positions. Maya published a suspected Bitcoin address that received 20.83 BTC (about $1.34 million) and said it hoped for a return-for-bounty. If not, the team said it planned to try recovering the Bitcoin through other means, including investments tied to Aztec Chain, and to restore the affected pool.

What the Loss Number Means

Do not treat the $11 million pool-value drop as $11 million stolen. Analyses split the hit roughly as $1.65–$1.7 million extracted, about $6.4 million from CACAO's own crash, and about $2.9 million from arbitrageurs buying cheap CACAO and swapping it for Bitcoin, ether, and stablecoins still in the pools. That is still a severe event for LPs. It is also a reminder that "safety" mechanisms — theft compensation, slash subsidies, pool-unit math — can become the exploit if they are uncapped against pool depth.

Cross-chain bridges and swap networks have been among the largest DeFi loss categories for years. For how investigators follow funds after an exploit, see how blockchain forensics works. For the market that is growing around that work, see the forensics-market expansion. If you held assets in a halted protocol, treat recovery claims with the same caution as any other incident: verify team channels, ignore unsolicited "recovery" DMs, and wait for an official post-mortem before moving funds.