The decentralized liquidity protocol Maya Protocol has halted operations after an attacker exploited six vulnerabilities in its codebase and siphoned off approximately $1.7 million. The incident marks the 16th major hack in the crypto industry in August, highlighting a troubling trend in DeFi security.
The loss of funds was first reported by the project's co-founder under the pseudonym Aaluxx. The market reaction was swift: the native token CACAO plunged 88% — from $0.115 to $0.013 — before partially recovering to $0.032. The hacker quickly converted the stolen assets into Bitcoin (BTC), Ethereum (ETH), and other coins, distributing them across all of Maya's liquidity pools.
Attack Mechanics: One Transaction, 23 Commands
The exploit was carried out within a single transaction consisting of 23 separate commands. This structure is what allowed the network to be deceived: validators perceived the operation as legitimate. The protocol attempted to compensate the pool that was supposedly affected, but due to the absence of an upper payout limit, the system credited approximately 49 million CACAO to a pool where there were actually no assets.
In reality, these credits were completely unbacked. Maya's reserve held only 168,000 CACAO, so the transfer did not go through, while the accounting balance remained artificially inflated. The attacker deposited just 100 CACAO into the pool, claimed rights to 99.93%, and withdrew 48.87 million CACAO — nearly half of all 100 million tokens in circulation.
The stolen funds were converted into 20.83 BTC (approximately $1.34 million) and sent to a single Bitcoin address over ten blocks. Aaluxx Myth announced a full halt of the project on Discord and appealed to the hacker to return the funds.
August 2026: A Rising Wave of Hacks
According to my own analysis, based on open data from monitoring platforms, there were 219 DeFi protocol hacks in 2026 totaling $1.26 billion. For comparison, 146 incidents were recorded for the entire year of 2025, though losses were higher — $2.71 billion. August alone has already seen 16 major cases.
Notably, Maya Protocol was built on THORChain, which lost $10.7 million in May as a result of a similar exploit. This points to systemic issues in cross-chain liquidity architecture.
Fund recovery now depends on the hacker's willingness to strike a deal. The team has also reached out to arbitrage traders who managed to profit from price discrepancies in the drained pools.
My expert commentary: This incident is yet another piece of evidence that even "battle-tested" architectural solutions do not guarantee security. The absence of payout limits and insufficient smart contract auditing constitute critical negligence that ultimately cost the project its life. Investors should be extremely cautious with protocols that have not undergone multiple independent code reviews.