Maya Protocol halted its MAYAChain network on August 19, 2026 after an attacker chained together six separate software bugs to inflate a liquidity pool and siphon off Bitcoin and other assets, according to Decrypt and Crypto Briefing. Both outlets reported the mechanics of the attack in close agreement. Neither outlet, nor Maya Protocol’s own public statements, has landed on a single figure for how much was actually taken.
Maya Protocol operates MAYAChain, a decentralized network built to let users swap assets like Bitcoin and Ethereum across blockchains without a centralized exchange, wrapped tokens or bridges. Decrypt described it as a cross-chain liquidity network; Crypto Briefing identified it as a Cosmos SDK-based non-custodial fork of THORChain, describing THORChain as Maya’s architectural predecessor.
The protocol’s pseudonymous co-founder, named by Decrypt as AaluxxMyth (also referred to as “Maya”) and by Crypto Briefing as “Aalux,” confirmed the exploit publicly and said the team halted swaps to contain the damage. In an initial post on X cited by Decrypt, the founder wrote: “No way to sugar coat this,” adding that the team believed it had “likely been exploited by 20 BTC ($1.4M) and other assets ($300k).”
A subsequent post-mortem from the Maya Protocol team, reported by Decrypt, described the mechanism in more technical terms. The attacker used “a single 23-message MsgDeposit transaction to trigger a false ‘theft’ detection, inflate a low-liquidity pool’s CACAO balance via an uncapped slash subsidy, then immediately LP’d into and withdrew from the inflated pool to extract the value,” the team wrote, according to Decrypt.
Per that post-mortem, the attacker inflated the pool by roughly 49.45 million CACAO, gained 99.93% control of it, and withdrew about 48.87 million CACAO. The attacker then converted that position into approximately 20.83 BTC, which Decrypt said the team valued at about $1.34 million, alongside additional assets moved to external chains. Crypto Briefing corroborated the same 20.83 BTC figure and the $1.34 million valuation, while noting a range up to $1.4 million.
As the attacker sold CACAO to acquire Bitcoin and other assets, the token’s price collapsed. Crypto Briefing reported CACAO fell 88.7% in a single day, from approximately $0.115 to as low as $0.013, before a partial recovery. Decrypt separately reported the drop at nearly 89%.
The two outlets align closely on the exploit’s mechanics: six chained bugs, an inflated CACAO pool, roughly 48.87 million CACAO withdrawn, and about 20.83 BTC extracted worth in the neighborhood of $1.34 million to $1.4 million. Both also agree the CACAO token cratered by close to 89% on the day.
Where the accounts split is on the total dollar loss, and the gap is not trivial. Maya’s founder first estimated the damage at $1.4 million in Bitcoin plus $300k in other assets in the initial X post cited by Decrypt. The team’s own post-mortem, also reported by Decrypt, later put total assets taken at roughly $1.65 million, comprising about $1.36 million moved to external blockchains and approximately $291,000 remaining on-chain. Crypto Briefing, meanwhile, described the “direct theft” as roughly $1.7 million — a third figure that does not match either of Maya’s own numbers.
The two outlets diverge further on damage beyond the direct theft. Decrypt reported that the value of MAYAChain’s liquidity pools fell by roughly $10.9 million. Crypto Briefing, in a separate estimate, put total pool-level and market-dislocation damage at an estimated $11 million. Neither figure has been reconciled with the other, and neither has been confirmed against a single authoritative accounting.
Maya Protocol’s pitch — native cross-chain swaps without wrapping or bridging — depends on accurately tracking balances across independent ledgers simultaneously. Crypto Briefing argued that when the accounting layer connecting those ledgers can be manipulated, an inflated number on one side becomes real extracted value on the other. The episode also lands on a protocol whose architectural predecessor, THORChain, suffered its own multiple exploits in 2021, per Crypto Briefing, underscoring a pattern in this category of cross-chain infrastructure.
Decrypt reported that Maya said the six bugs had gone undetected for three to four years despite audits by security firms Halborn and Fable 5 — a detail reported only by Decrypt and not corroborated elsewhere. In a follow-up post cited by Decrypt, the founder wrote the team needs to “get even more adversarial and look for extremely simple code primitives,” adding: “We already knew our job was difficult, but the mission is worth it.”
Crypto Briefing alone reported that security firm PeckShield began monitoring on-chain activity tied to the incident. That detail has not been confirmed by Decrypt or any other source in this record.
The exact total value stolen remains an open question across three different figures now in public circulation: the founder’s original $1.4 million-plus-$300k estimate, the post-mortem’s $1.65 million tally, and Crypto Briefing’s $1.7 million figure. Neither outlet has reconciled these. Decrypt reported that Maya published the suspected attacker’s Bitcoin address, which received 20.83 BTC worth about $1.34 million, and said the team hopes the funds are returned in exchange for a bug bounty. Failing that, Decrypt reported Maya’s stated fallback plan involves recovering the roughly 20 BTC through investments in Aztec Chain and unspecified other means. Decrypt also reported that the team did not say whether it believes AI tooling was used in constructing the attack. When or whether MAYAChain swaps resume has not been announced in either report.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.