Maya Protocol, a decentralized liquidity protocol, has become the latest victim of a hacker attack. The attacker, exploiting six vulnerabilities, drained approximately $1.7 million from liquidity pools, causing the native token CACAO to plummet by 88%. This incident adds to August's grim statistics, marking the 16th major hack in the crypto industry this month.
The attack was carried out within a single transaction consisting of 23 separate commands. This structure allowed the network to perceive the operation as legitimate, highlighting the complexity and sophistication of the hacker's actions. The attacker converted the stolen tokens into Bitcoin (BTC), Ethereum (ETH), and other assets, emptying all of Maya's liquidity pools.
Mechanics of the Hack and CACAO's Collapse
A key detail of the attack was the manipulation of a pool that was supposedly affected. The protocol attempted to compensate for losses, but no one set an upper limit on the payout. As a result, the system credited approximately 49 million CACAO to a pool where there were virtually no assets. These credits were not backed by anything: Maya's reserve held only 168,000 CACAO, so the transfer did not go through, leaving the balance artificially inflated.
The hacker deposited just 100 CACAO into this pool, claimed 99.93% of it, and withdrew 48.87 million CACAO—nearly half of all 100 million tokens in circulation. This caused an immediate price collapse from $0.115 to $0.013, after which the price partially recovered to $0.032. The attacker transferred 20.83 BTC (approximately $1.34 million) to a single Bitcoin address over ten blocks.
Context: A Wave of Attacks on DeFi
This hack is just the tip of the iceberg. In 2026, there have already been 219 DeFi protocol hacks totaling $1.26 billion. For comparison, throughout 2025, 146 incidents were recorded, but losses were higher—$2.71 billion. In August alone, there have already been 16 cases. Notably, the THORChain protocol, on which Maya is based, lost $10.7 million in May due to a similar exploit.
The Maya team has announced a complete halt of the project and has appealed to the hacker to return the funds for a reward. Negotiations are also underway with arbitrage traders who may have profited from price differences across pools during the chaos.
My analysis: This incident once again demonstrates that even protocols built on proven codebases are not immune to errors in liquidity management logic. The lack of payout limits and weak smart contract auditing is a systemic DeFi problem that requires an immediate overhaul of security standards. Until the industry implements robust transaction validation mechanisms, such attacks will continue to occur with alarming regularity.