Maya Protocol Halts Network After $1.7M Exploit Drains 20 BTC
Maya Protocol has halted its cross-chain trading network after an attacker exploited a chain of software flaws and extracted about $1.7 million in crypto, with roughly 20 BTC accounting for most of the confirmed loss.
Maya co-founder Aaluxx said the team would fix the vulnerabilities and recover liquidity in full after operations were globally paused. Blockchain security firm PeckShield separately tracked approximately 20 BTC worth $1.34 million to an attacker-controlled Bitcoin address, with Maya estimating another roughly $300,000 in affected assets.
Six Bugs Combined In 23-Message Transaction
Preliminary technical analysis traced the attack to six interacting weaknesses across trade accounts, outbound transaction processing, solvency checks and liquidity-pool calculations.
Security researcher Vini Barbosa traced most of the exploit to a single transaction containing 23 messages. The sequence manipulated Maya’s theft-detection and penalty-subsidy logic, allowing the attacker to inflate a low-liquidity pool before adding and withdrawing liquidity.
Approximately 48.87 million CACAO were pulled from Maya’s Asgard module during the sequence, while the attacker also moved assets including LINK before converting part of the position into BTC, ETH, RUNE and stablecoins. About 20.83 BTC ultimately reached an external Bitcoin address, while an estimated 8.87 million CACAO remained under attacker control during the initial response.
The structure differs from the May attack on fellow native cross-chain liquidity network THORChain, where a compromised vault path produced a $10.7 million drain and forced emergency network controls.
CACAO Crashes 88.7% During Attack
CACAO fell from roughly $0.115 to $0.013 during the exploit, an intraday collapse of about 88.7%, as pool balances and the protocol’s native settlement asset were distorted. The token subsequently recovered part of the move as arbitrage activity repriced affected pools.
The sudden CACAO dislocation follows another supply-driven crypto shock this month, when Harmony’s ONE plunged nearly 40% after roughly 4 billion tokens were created without authorization. Harmony later moved toward exchange freezes and a network rollback as developers attempted to contain the damage.
Broader DeFi and cross-chain infrastructure had already accumulated $816.9 million in major exploit losses during 2026 before the Maya attack.
Maya Accelerates Aztec Chain Recovery Plan
Maya is working on patches required to restore swaps and has pledged to make liquidity providers whole. Aaluxx also signaled that the exploit will accelerate the launch of Aztec Chain, with investment proceeds from the planned ecosystem expansion intended to flow back into Maya liquidity pools.
The team is also pursuing recovery from the attacker through a bug-bounty arrangement. Aaluxx said returning the roughly 20 BTC to Maya’s pools would restore a large part of the lost liquidity.
MAYAChain remained under a global operational pause while developers patched the affected transaction paths and prepared the network for trading to resume.




Post Comment
You must be logged in to post a comment.