The developers of Maya Protocol suspended the network after a hacker attack

8/19/2026, 08:15 AMЕвгения Слив

On the night of August 19, the developers of the cross‑chain project Maya Protocol were forced to suspend the network after a hacker attack, the damage from which amounted to about one million seven hundred thousand dollars. The incident was reported by the project’s co‑founder, who is hiding under the pseudonym Aaluxx. The attacker managed to withdraw twenty bitcoins worth approximately one million four hundred thousand dollars, as well as other digital assets worth about three hundred thousand dollars. This information was confirmed by specialists from PeckShield, who also identified the attacker’s address.

According to the Maya team, the incident occurred due to a vulnerability in the transaction processing mechanism. The protocol failed to recognize funds that had already been withdrawn and mistakenly activated the compensation mechanism. The hacker took advantage of this by creating a фиктивный liquidity pool, into which the system mistakenly credited nearly fifty million unsecured CACAO tokens. The attacker then deposited one hundred real CACAO coins, which gave them the right to ninety‑nine and ninety‑three hundredths percent of all the assets in that pool. After that, they immediately withdrew forty‑eight million eight hundred and seventy thousand real coins, effectively stealing funds from the protocol’s reserves. The hacker exchanged all the stolen assets for Bitcoin, Ether, RUNE, and stablecoins.

As a result of the incident, the value of the CACAO token plummeted by eighty‑eight and seven‑tenths percent, dropping from eleven and a half cents to one and three‑tenths of a cent. Later, the coin partially recovered from the decline, rising to three and two‑tenths of a cent, as reported by the developers. The cause of the serious failure was that the new code for trading accounts, transferred from the THORChain project in mid‑2025, was not correctly integrated with the solvency verification system. The project’s co‑founder noted that over several years, neither auditors from Halborn, nor checks using the Fable 5 model from Anthropic, nor community representatives were able to detect this vulnerability.

Currently, the developers are actively working to resolve the issue and are preparing for the network to resume operations. The project’s co‑founder expressed hope to raise one million four hundred thousand dollars through investments in AZTECChain to cover the losses. In addition, he offered the hacker a reward as part of a vulnerability‑hunting program in exchange for the full return of the stolen funds. It should be recalled that in May 2026, the THORChain protocol — of which Maya Protocol is a fork — lost approximately ten million seven hundred thousand dollars as a result of an attack via a compromised network node.

Popular news