The emergency halt of the Maya Protocol network on the night of August 19 was the result of a large-scale exploit that cost the project $1.7 million. This is not just a routine theft — the incident exposed a systemic flaw embedded in the codebase during the migration from THORChain and called into question the effectiveness of even the most reputable audit reviews.
Attack mechanics: a fake pool and a hole in logic
The attacker drained 20 BTC (~$1.4 million) and other assets totaling about $300,000. PeckShield specialists quickly identified the hacker's address, but the key point is how exactly he managed to pull off this scheme. The essence is that the protocol, due to a vulnerability in transaction processing, failed to recognize already-executed fund withdrawals and erroneously activated the compensation mechanism.
The attacker exploited this by creating a fake pool, into which the system automatically credited nearly 50 million unbacked CACAO tokens. He then deposited just 100 real CACAO, gaining rights to 99.93% of the pool's assets, and instantly withdrew 48.87 million real coins from the protocol's reserves. All stolen funds were converted into bitcoin, Ethereum, RUNE, and stablecoins.
CACAO collapse and the root of the problem
The market reaction was immediate: the price of CACAO crashed by 88.7% — from $0.115 to $0.013 — before partially recovering to $0.032. However, the main takeaway from the incident is not the numbers, but the cause. The new trading account code, ported from THORChain in mid-2025, turned out to be unintegrated with the solvency verification system. This fatal oversight went unnoticed for years.
Notably, neither Halborn auditors, nor checks using Anthropic's Fable 5 model, nor the community identified this breach. As noted by the project's co-founder under the pseudonym Aaluxx, over 3-4 years of the vulnerability's existence, no one found it. This is an alarming signal for the entire industry: even multi-layered checks do not guarantee protection against simple logical errors in code.
Next steps and context
Developers are currently working on restoring the network. To cover the losses, Aaluxx hopes to attract $1.4 million in investments into AZTECChain, and the hacker has been offered a bug bounty reward in exchange for returning the funds. Notably, in May 2026, THORChain, of which Maya Protocol is a fork, already lost about $10.7 million due to an attack through a compromised node.
My analysis: This case is another reminder that a "fork" does not mean an "improvement." Copying code without a deep review of integration creates hidden risks that surface at the most unexpected moment. Investors should be more cautious about projects that inherit a codebase without fully stress-testing all transaction scenarios. Restoring trust in Maya Protocol will now depend not on the amount of compensation, but on how quickly and transparently the team proves that such a hole is impossible in the future.