On the night of August 19, the team behind the cross-chain protocol Maya Protocol made a radical decision—to completely halt network operations. The cause was a hacker attack that resulted in the theft of digital assets worth approximately $1.7 million. The project's co-founder, known under the pseudonym Aaluxx, confirmed the incident and stated an intention to restore funds in full.
Hack Mechanics: Fake Pool and Compensation Error
According to my data, the attack was carried out through a vulnerability in transaction processing. The protocol failed to recognize already executed withdrawals and erroneously activated the compensation mechanism. The hacker exploited this by creating an artificial pool into which the system automatically credited nearly 50 million unbacked CACAO tokens.
The attacker then deposited just 100 real CACAO, which granted them rights to 99.93% of all pool assets. As a result, they instantly withdrew 48.87 million real coins, effectively draining the protocol's reserves. The stolen funds were converted into Bitcoin, Ethereum, RUNE, and stablecoins. Specialists at PeckShield identified the hacker's address, which currently holds 20 BTC (~$1.4 million) and other assets worth $300,000.
CACAO Crash and the Root of the Problem
The consequences were immediate: the price of CACAO plummeted by 88.7%—from $0.115 to $0.013. The coin later partially recovered to $0.032, but investor confidence has been seriously undermined.
The root of the problem, as it turned out, lies in the trading account code migrated from THORChain in mid-2025. This code was not integrated with the solvency verification system. Notably, the vulnerability went unnoticed by Halborn auditors, checks using Anthropic's Fable 5 model, and the community alike—for three to four years.
Recovery Plan and Lessons for the Industry
Currently, developers are actively working to fix the issue and preparing to restart the network. Aaluxx hopes to raise $1.4 million through investments in AZTECChain, and has also offered the hacker a bug bounty reward for returning the stolen funds. I should note that in May 2026, THORChain, of which Maya Protocol is a fork, already lost about $10.7 million due to an attack through a compromised node.
My comment: This incident is yet another reminder that even years of audits do not guarantee security. Cross-chain protocols operate with complex logic, where seemingly simple code primitives can become entry points for attacks. The industry needs to move toward more aggressive testing methods, including formal verification and attack simulation in sandboxes, rather than relying solely on static checks.