Cross-chain decentralized exchange Maya Protocol lost roughly $1.7 million on August 18 after an attacker chained together six separate software bugs to drain funds from the protocol’s vaults. The exploit hit around 17:30 UTC and marks the first loss-of-funds incident for the THORChain fork since its mainnet launched in April 2023.
Maya operates as a cross-chain DEX. A cross-chain DEX is a decentralized exchange that lets users swap assets like Bitcoin and Ethereum directly between different blockchains, without converting them into wrapped or bridged tokens first. Maya’s validators jointly custody user funds in what the protocol calls Asgard and Yggdrasil vaults, spread across Bitcoin, Ethereum, Dash, Zcash, RUNE and Arbitrum.
Key Takeaways
- An attacker used a single transaction with 23 messages to exploit six chained bugs and withdraw 48.87 million CACAO from Maya’s Asgard vaults.
- Roughly 20.83 BTC (about $1.34 million) was moved to an external Bitcoin address, while the attacker still holds close to $290,000 in CACAO on Maya’s chain.
- CACAO crashed 88.7%, from about $0.115 to $0.013, before recovering to the $0.10–$0.12 range as of publication.
- Maya halted trading network-wide and says it will not pursue a treasury bailout, instead relying on its “halt first, patch, resume” model.
Published: August 19, 2026, 09:00 UTC
How the attacker got in
Blockchain security firm PeckShield flagged the drain through its monitoring alerts, and Maya’s pseudonymous co-founder, known as Aaluxx, confirmed the breach in an on-chain statement shortly after. A preliminary technical writeup Aaluxx shared attributes the exploit to six bugs touching trade accounts, outbound transaction handling and liquidity pool calculations, rather than one clean vulnerability.
The attacker’s batched transaction, carrying 23 internal messages, overwrote tracking records tied to a single transaction ID. That overwrite caused Maya’s outbound-verification logic to lose track of where funds had actually gone, and it mistakenly flagged a legitimate transfer as theft. The false alarm triggered an uncapped slashing calculation that artificially inflated the CACAO balance of a low-liquidity pool. The system saved that inflated balance before it tried to fund it, and when the funding step failed, the error was logged but never rolled back, leaving the fabricated balance in place for the attacker to withdraw against.
What it means for Maya and the wider THORChain ecosystem
The $1.7 million loss equals just over 10% of Maya’s roughly $15 million in total value locked before the incident, according to DefiLlama figures cited in coverage of the exploit. CACAO’s circulating market cap sits near $10 million, and the token remains down more than 92% from its all-time high of $1.43.
This is the second cross-chain incident tied to the THORChain family of protocols this year. THORChain itself lost close to $10.8 million on May 15, a figure the team later revised down to $7.4 million after confirming only one of six Asgard vaults had been compromised. That earlier exploit spanned Bitcoin, Ethereum, BNB Smart Chain and Base, forced a full network halt, and pushed THORChain’s RUNE token down roughly 15% in a day.
Maya’s bug bounty program through Immunefi caps critical-severity payouts at $35,000, a figure security researchers have pointed to as low relative to the funds the protocol custodies. Maya’s Ethereum router contract has also carried a “Draft 3” audit label from security firm Halborn since earlier this year, according to reporting on the incident. Maya inherited its Bifrost bridge architecture from THORChain, the same component exploited for a combined $15 million across two incidents in July 2021.
Response and next steps
Maya’s automated Mimir halt flags froze deposits and withdrawals on affected pools within the hour, using the protocol’s standard 720-block, roughly one-hour, HaltTrading window that node operators can extend. Aaluxx thanked validators for the fast response and said the team has identified the vulnerability chain and is preparing a patch before resuming swaps.
Consistent with how THORChain handled its own breach, Maya is not planning a treasury-funded reimbursement. Losses are expected to be socialized across liquidity providers and bonded node operators under the protocol’s existing economic security model. A full transaction-level post-mortem from the Maya team, covering how the attacker bypassed the solvency checker and node-level circuit breakers, is expected within days.

The incident adds to a difficult year for cross-chain infrastructure. PeckShield’s tracking shows eight major bridge and cross-chain exploits drained a combined $328.6 million through mid-May 2026, with the year’s cumulative DeFi hack losses passing $750 million by mid-April, driven in part by the $292 million Kelp DAO and $285 million Drift Protocol incidents. Readers can follow ongoing coverage of security incidents like this one in Web3 Business News’ News Bites section.
FAQ
What is Maya Protocol?
Maya Protocol is a cross-chain decentralized exchange built as a fork of THORChain. It lets users swap native assets such as Bitcoin and Ethereum across different blockchains without wrapping or bridging them into synthetic versions first.
How much was stolen in the Maya Protocol exploit?
The attacker extracted roughly $1.7 million in total value, including about 20.83 BTC moved to an external address and close to $290,000 in CACAO the attacker still holds on Maya’s chain.
Will Maya Protocol reimburse affected users?
Maya has not announced a treasury bailout. Following the same approach THORChain used after its own 2026 exploit, losses are expected to be spread across liquidity providers and bonded validators rather than covered from a central fund.








