Skip to content
Est. MMXXVIVol. VI · № 329RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 321Other

Maya Protocol Six-Bug Accounting Exploit

An attacker chained six bugs in MAYAChain's trade-account and outbound logic to fabricate a CACAO subsidy and drain about $1.7 million in Bitcoin and other assets from Maya Protocol.

Date
Status
Funds Stolen

On August 18, 2026, cross-chain liquidity network Maya Protocol was exploited when an attacker chained six distinct bugs in MAYAChain's trade-account and outbound-transaction logic, draining roughly $1.7 million in Bitcoin and other assets. The protocol halted its MAYAChain network the same day; its native CACAO token collapsed nearly 89%, from about $0.115 to as low as $0.013, and total pool value fell by around $11 million.

What happened

The exploit was not a single broken contract but a sequence of accounting failures triggered by one intricate transaction that packaged 23 messages. First, MAYAChain wrongly concluded that an outgoing transaction had gone missing, which fired the compensation code meant to reimburse users after a theft. That routine then miscalculated the payout, crediting roughly 49 million CACAO — an uncapped subsidy — into a small, nearly empty pool whose reserve held only about 168,000 CACAO. Because the network could not actually fund the payment, a further bug persisted the inflated balance despite the failed transfer, and the system kept operating as though the pool truly held the fraudulent tokens. The attacker, who had seeded the distorted pool with a minimal deposit, thereby gained more than 99% ownership, withdrew 48.87 million CACAO, and swapped it for real assets — about 20.83 BTC (~$1.34 million) plus roughly $300,000 in other tokens.

Aftermath

Maya Protocol paused MAYAChain to stop further outflows and began tracing the stolen funds. Co-founder Aaluxx said the team would "work to fix and recover in full," offered the attacker a bug-bounty arrangement for returning the funds, and floated a plan to replace the roughly 20 BTC through the protocol's Aztec Chain investments if the assets were not returned. As of late September 2026 the drained assets had not been recovered, so the status here remains stolen.

Why it matters

Maya Protocol is a fork of THORChain, and this incident echoes a recurring theme in app-specific chains: the most dangerous bugs live not in a single lending contract but in the network's own accounting and settlement logic, where one false assumption can cascade. A theft-compensation feature — code designed to protect users — became the attack surface, minting an uncapped subsidy that the reserve could never back. The episode underscores that outbound-handling, reserve-solvency checks, and per-pool subsidy caps are as security-critical as any swap or bridge function, and that chaining several individually minor flaws can produce a loss far larger than any one of them.

Sources & on-chain evidence

  1. [01]coindesk.comhttps://www.coindesk.com/markets/2026/08/19/maya-protocol-exploit-drains-bitcoin-and-other-assets-as-pool-value-drops-usd11-million
  2. [02]crypto.newshttps://crypto.news/maya-protocol-suffers-1-7-million-exploit-halts-network/
  3. [03]cryptobriefing.comhttps://cryptobriefing.com/maya-protocol-exploit-cacao-drained/
  4. [04]crowdfundinsider.comhttps://www.crowdfundinsider.com/2026/08/299219-maya-protocol-halts-operations-after-multi-bug-exploit-drains-cacao-tokens-and-cross-chain-assets/
  5. [05]defimon.xyzhttps://defimon.xyz/blog/maya-protocol-hack-august-2026

Related filings