The decentralized liquidity protocol Maya Protocol has become the latest victim of a hacker attack. The attacker exploited six vulnerabilities in the codebase and siphoned off about $1.7 million, triggering an 88% collapse in the native token CACAO.
The incident was discovered by the project's co-founder under the pseudonym Aaluxx. In my assessment, this is not just a routine theft, but a systemic failure in security logic that exposed fundamental problems in the protocol's architecture.
Attack Mechanics: How the Hacker Deceived the Network
The attack was carried out within a single transaction consisting of 23 separate commands. This structure allowed the malicious operation to pass network verification as legitimate. The protocol attempted to compensate the pool that allegedly suffered losses, but the upper payout limit was not set. As a result, the system credited about 49 million CACAO to a pool where there were virtually no assets.
The critical error was that these credits were not backed by real reserves. Maya's treasury held only 168,000 CACAO, so the transfer did not go through, while the accounting balance remained artificially inflated.
The hacker deposited 100 CACAO into this pool, claimed rights to 99.93%, and withdrew 48.87 million CACAO — nearly half of all 100 million tokens in circulation.
Consequences: Price Collapse and Project Shutdown
The CACAO price crashed from $0.115 to $0.013, then partially recovered to $0.032. The attacker converted the stolen tokens into Bitcoin (BTC), Ethereum (ETH), and other assets across all Maya liquidity pools. In particular, 20.83 BTC (about $1.34 million) were transferred to a single address over ten blocks.
Founder Aaluxx Myth announced a complete halt of the project on Discord and appealed to the hacker to return the funds. The team also contacted arbitrage traders who profited from price differences in the pools, hoping for partial loss recovery.
A Worrying Trend for 2026
This incident marks the 16th major hack in August. According to my data, there have been 219 DeFi protocol hacks totaling $1.26 billion in 2026. For comparison, 146 incidents were recorded for the entire 2025, but losses were higher — $2.71 billion. Notably, Maya was built on THORChain, which lost $10.7 million in May due to a similar exploit.
My analysis: The recurrence of attacks on protocols using similar architecture indicates that the industry is not learning from mistakes quickly enough. Fund recovery now depends entirely on the hacker's goodwill, which in today's reality is an extremely low probability. Investors should reassess their risks when dealing with cross-chain liquidity, where code complexity often becomes the primary attack vector.