On the night of August 19, the team behind the cross-chain protocol Maya Protocol was forced to urgently halt network operations. The cause was a successful hacker attack that resulted in the attacker siphoning off digital assets worth approximately $1.7 million. The project's co-founder, known under the pseudonym Aaluxx, promptly confirmed the incident and stated that the team intends to fully recover the losses.
Mechanics of the hack: a fictitious pool and 50 million phantom tokens
Analysis of the incident shows that the attack was carried out through a vulnerability in transaction processing. The protocol incorrectly interpreted already-executed withdrawals, leading to the erroneous activation of a compensation mechanism. The hacker exploited this glitch by creating a fictitious liquidity pool, into which the system credited nearly 50 million unbacked CACAO tokens.
The attacker then deposited just 100 real CACAO, which automatically granted them rights to 99.93% of all pool assets. As a result, they instantly withdrew 48.87 million real coins, draining the protocol's reserves. According to PeckShield specialists, the bulk of the stolen funds — 20 BTC (~$1.4 million) — was transferred to the address bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646. The remaining funds (~$300,000) were converted into Ethereum, RUNE, and stablecoins.
CACAO collapse and the root of the problem
The market reaction was swift: the price of CACAO plunged by 88.7% — from $0.115 to $0.013. However, the coin later partially recovered to $0.032, suggesting the market is attempting to digest the news.
The key cause of the incident is an architectural flaw. The new trading account code, migrated from THORChain in mid-2025, was not integrated with the solvency verification system. As Aaluxx notes, this vulnerability went unnoticed by Halborn auditors, checks using Anthropic's Fable 5 model, and the project's thousands-strong community for several years. This is a troubling signal for the entire industry: even multi-layered checks do not guarantee the absence of critical errors in smart contract logic.
Next steps
Developers are currently working hard to fix the issue and are preparing to resume network operations. Aaluxx also reported plans to raise $1.4 million in investments into the AZTECChain ecosystem to cover the damages. Additionally, the hacker has been offered a reward under a bug bounty program in exchange for returning the stolen funds — a standard practice in such situations, which, however, rarely leads to success.
It is worth recalling that in May 2026, THORChain, of which Maya Protocol is a fork, already lost about $10.7 million due to an attack via a compromised node. The recurrence of a similar scenario in a subsidiary project underscores a systemic security problem in cross-chain protocols, where code complexity often outpaces the quality of its audit.
My comment: this incident is yet another reminder that even the most "vetted" protocols are vulnerable. Relying on single audits, even from top-tier companies, is an illusion of security. The industry needs more aggressive testing methods, including formal verification and continuous stress tests based on real attack scenarios. As for investors, they should keep in mind that in DeFi, the risk of losing funds due to exploits remains one of the highest.