Key Highlights
- Maya Protocol suffered a devastating $1.7 million security breach, marking its first major security incident since its 2023 mainnet deployment
- The hacker executed a sophisticated attack leveraging six interconnected vulnerabilities through a single 23-message transaction, extracting 48.87 million CACAO tokens
- Approximately 20 Bitcoin valued at $1.4 million plus an additional $300,000 in various digital assets were siphoned from the protocol’s Asgard and Yggdrasil vault systems
- The native CACAO token experienced a catastrophic price collapse of nearly 89%, plummeting from approximately $0.115 to $0.013 in the aftermath
- The development team implemented an emergency protocol-wide freeze and confirmed remediation efforts are underway
Maya Protocol, a cross-chain decentralized exchange platform, executed an emergency network shutdown on Wednesday following a security compromise that resulted in approximately $1.7 million in stolen cryptocurrency.
Aalux, one of the protocol’s co-founders, publicly acknowledged the security incident and explained that the development team implemented a comprehensive network freeze to prevent additional losses.
The malicious actor successfully extracted approximately 20 Bitcoin, representing roughly $1.4 million in value, alongside an estimated $300,000 worth of additional cryptocurrency assets.
Technical Breakdown of the Exploit
Initial technical investigation revealed the breach stemmed from six interconnected software vulnerabilities spanning trade account mechanisms, outbound transaction processing logic, and liquidity pool mathematical computations.
The perpetrator crafted a sophisticated single transaction containing 23 individual messages designed to activate a fraudulent theft detection alert, manipulate a low-liquidity pool’s valuation upward, and subsequently extract 48.87 million CACAO tokens from Maya’s Asgard module infrastructure.
Approximately $1.36 million worth of assets were successfully bridged to external blockchain networks. The attacker retained control of roughly $291,000 in CACAO tokens and trade-account holdings within the native chain.
Blockchain security research company PeckShield identified the incident and confirmed that digital assets were extracted from the protocol’s vault architecture before the platform’s automated solvency verification systems could fully intervene and halt the drainage.
According to DeFiLlama data, Maya Protocol held approximately $15 million in total value locked prior to the security breach. The stolen amount constitutes slightly over 10% of that total.
CACAO maintains a circulating market capitalization of approximately $10 million. The token had already experienced a decline exceeding 92% from its peak valuation of $1.43 prior to this latest security incident.
Independent blockchain researcher Vini Barbosa calculated the broader pool value deterioration at approximately $10.9 million, though this figure encompasses arbitrage trading activity and token devaluation effects beyond purely stolen funds.
Official Protocol Response
Aalux confirmed the development team successfully identified the security weakness and is actively developing corrective measures. He expressed appreciation to node operators for their rapid coordinated response.
As a THORChain fork, Maya Protocol implements a “halt first” security framework, prioritizing immediate trading suspension during investigations over post-incident compensation mechanisms.
The protocol’s Mimir emergency halt mechanisms were triggered, effectively freezing all deposit and withdrawal operations across compromised liquidity pools while validators and core developers conducted forensic analysis.
Broader Industry Implications
This security breach occurs in the shadow of THORChain’s May 2026 incident, where approximately $10.8 million was initially reported stolen (later adjusted to $7.4 million), which similarly necessitated a complete platform trading suspension.
Maya Protocol had maintained an unblemished security record spanning over three years without any documented fund-loss incidents following its April 2023 mainnet activation.
The development team has committed to releasing a comprehensive technical post-mortem analysis explaining how the attacker successfully circumvented Maya’s multi-layered security infrastructure in the forthcoming days.


