Developers of the cross-chain project Maya Protocol have temporarily halted network operations following a security breach. Co-founder Aaluxx confirmed the exploit, which resulted in an attacker stealing approximately $1.7M in cryptocurrency. Blockchain analytics firm PeckShield tracked the hacker’s address, confirming the theft of 20 BTC (~$1.4M) and around $300,000 in other digital assets.
Exploit Mechanics: Fake Pool and Reserve Draining
The breach stemmed from a critical vulnerability in the protocol’s transaction processing logic. The network failed to recognize already executed withdrawals and mistakenly triggered a compensation mechanism.
The attack unfolded in four steps:
- Pool Creation: The attacker created a dummy trading pool, where the system mistakenly minted and credited nearly 50 million unbacked CACAO tokens.
- Dominance Claim: By depositing just 100 real CACAO tokens, the hacker secured a 99.93% share of the pool’s assets.
- Reserve Draining: The attacker immediately withdrew 48.87 million legitimate CACAO tokens directly from the protocol’s reserves.
- Asset Swap: The stolen tokens were swiftly swapped for Bitcoin (BTC), Ethereum (ETH), RUNE, and stablecoins.
This sudden sell-off caused the native CACAO token to plunge 88.7%, dropping from $0.115 to $0.013, before partially recovering to $0.032.
Root Cause and Audit Oversights
The failure originated from trade account code ported from THORChain in mid-2025, which was never integrated with Maya’s internal solvency check mechanism.
What makes the flaw notable is that it slipped past multiple layers of security over an extended period:
- Professional security auditors at Halborn.
- Anthropic’s AI smart contract analysis model (Fable 5).
- Independent community researchers and bug hunters.
Recovery Plan and Security Context
The Maya Protocol team is currently patching the vulnerability and preparing to restart the network. To cover the shortfall, developers hope to raise $1.4M via investments in AZTECChain. Additionally, they offered the hacker a white-hat bug bounty in exchange for returning the stolen funds.
The incident highlights lingering security risks across cross-chain infrastructure. Notably, THORChain—the foundational project from which Maya Protocol was forked—suffered a $10.7M loss in May 2026 due to a compromised validator node.










