Six Chained Bugs Lead to $1.7 Million Maya Protocol Exploit, Network Halted

Attack occurred on Aug 18, 2026 around 17:30 UTC on Maya Protocol’s MAYAChain mainnet. The attacker moved about 20.83 BTC (roughly $1.34 million) to an external address, and on-chain still holds about 8.87 million CACAO worth roughly $288k.
The breach traced to six chained bugs affecting trade-account handling, outbound transaction verification, and liquidity-pool calculations. A batched deposit overwrote internal tracking records, causing the outbound-verification logic to miss where funds went and triggering a false theft alert that inflated the CACAO balance of a low-liquidity pool.
The attacker drained 48.87 million CACAO from Maya’s Asgard module via a single 23-message transaction.
The theft included assets beyond CACAO, notably about 20 BTC and ARB-based tokens among the stolen assets.
CACAO price collapsed about 88.7% during the incident, and the wider pool value declined by about $10.9 million due to arbitrage and devaluation, not solely the attacker’s theft.
Maya Protocol shut down all trading and swaps on August 18, 2026 after an attacker exploited six chained software bugs to steal roughly $1.7 million in Bitcoin and other crypto assets, according to Crypto.news. The attacker drained 48.87 million CACAO tokens from Maya's Asgard module in a single 23-message transaction, then moved about 20.83 BTC — worth around $1.34 million — to an external address.
CACAO, Maya Protocol's native token, collapsed nearly 89% during the incident, according to Head Topics. The wider pool lost an estimated $10.9 million in value, though much of that came from arbitrage and slippage rather than direct theft.
The attack traces to six separate software flaws that worked together, according to CryptoNews.net. A batched deposit overwrote internal tracking records inside the protocol. That confused the system's outbound-verification logic — the code that checks where funds are going. The system then missed where the money went entirely.
The confused tracking triggered a false theft alert, which had an unintended side effect. It inflated the CACAO balance inside a low-liquidity pool. The attacker exploited that inflated balance to drain 48.87 million CACAO from the Asgard module — Maya's central vault — in one coordinated transaction, Yahoo Finance reported.
The stolen assets included roughly 20 BTC and about $300,000 worth of ARB-based tokens and other crypto, according to BeInCrypto. The attacker quickly converted much of the haul into Bitcoin — a common move to make funds harder to trace and freeze.
Not everything was cashed out. On-chain data shows the attacker still holds about 8.87 million CACAO, worth roughly $288,000 to $291,000. Preliminary analysis puts external transfers at about $1.36 million, with the remaining value sitting in CACAO and related positions on MAYAChain, Crypto.news reported.
The total pool value drop looks far worse than the actual theft. The wider pool declined by about $10.9 million during the incident, according to CryptoNews.net. But analysts say most of that loss came from arbitrage trading and CACAO's price collapse — not from the attacker directly taking funds.
CACAO fell nearly 88.7% at the worst point of the attack. When a token drops that fast inside a liquidity pool, other traders can exploit the price gap and pull value out. That kind of slippage-driven loss explains the gap between the $1.7 million stolen and the $10.9 million pool decline, Head Topics noted.
Maya Protocol halted all swaps and trading immediately after the attack to stop further damage. The team has since launched a recovery plan that includes a bug bounty program to find any remaining flaws, BeInCrypto reported. A potential investment in Aztec Chain is also part of the plan.
The protocol aims to resume operations after fixes are in place, though the team has not given a specific timeline. The hack makes Maya Protocol the 16th crypto protocol to be exploited in August 2026 alone, according to Yahoo Finance — a grim sign of how frequently attackers are finding cracks in decentralized finance software.
Publishers
27
Articles
22
Reach
49