On the night of August 19, the cross-chain protocol Maya Protocol faced a serious security incident. The project team was forced to urgently halt network operations after an attacker withdrew digital assets worth approximately $1.7 million. The project's co-founder, known under the pseudonym Aaluxx, promptly confirmed the attack and stated the intention to fully recover the losses.

Mechanics of the Hack

Analysis of the incident shows that the hacker exploited a critical error in the transaction processing logic. The protocol failed to recognize already executed withdrawals and mistakenly activated the compensation mechanism. The attacker created a fictitious liquidity pool, into which the system credited nearly 50 million unbacked CACAO tokens. By contributing only 100 real coins, he gained rights to 99.93% of the pool's assets and immediately withdrew 48.87 million real CACAO at the expense of the protocol's reserves. The stolen funds were converted into bitcoin, Ethereum, RUNE, and stablecoins. Specialists at PeckShield confirmed that the bulk of the damage—20 BTC (~$1.4 million)—was transferred to the address bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646.

Impact on the Ecosystem

The immediate result of the attack was a sharp collapse in the price of CACAO by 88.7%—from $0.115 to $0.013. Subsequently, the coin partially recovered to $0.032, but trust in the protocol was severely undermined.

The root of the problem lies in the trading account code ported from THORChain in mid-2025. This module was not integrated with the solvency verification system. Notably, the vulnerability was not detected by Halborn auditors, during checks using Anthropic's Fable 5 model, or by the community over several years.

Recovery Plan

Developers are already working to fix the issue and are preparing to resume network operations. Aaluxx is considering raising $1.4 million through investments in AZTECChain. Additionally, the hacker has been offered a reward under the bug bounty program in exchange for returning the stolen funds.

It is worth noting that this is not the first such case in the THORChain ecosystem: in May 2026, THORChain itself lost about $10.7 million due to an attack through a compromised node.

My comment: This incident once again highlights the critical importance of integrating all modules when forking a codebase. Even the most thorough audits do not guarantee security if architectural changes do not undergo comprehensive verification. The industry needs more aggressive testing methods, including the search for "simple" logic errors that can go unnoticed for years. Restoring trust in Maya Protocol will be a challenging task, but the team's transparent approach is the first step in the right direction.