The decentralized liquidity protocol Maya Protocol has suffered a large-scale attack. The attacker, exploiting six vulnerabilities, drained approximately $1.7 million. This incident marks the 16th major hack in the crypto industry in August, highlighting systemic risks in the DeFi sector.
The loss of funds was first reported by the project's co-founder under the pseudonym Aaluxx. The market reaction was immediate: the price of the native token CACAO collapsed by 88%. The hacker did not limit themselves to a single asset — they converted the stolen tokens into Bitcoin (BTC), Ethereum (ETH), and other digital assets, dispersing them across all of Maya's liquidity pools.
Attack Mechanics: One Transaction, 23 Commands
The exploit was carried out in just one transaction consisting of 23 separate commands. This structure allowed the network to accept the operation as legitimate. The protocol attempted to compensate for the losses, but the system credited approximately 49 million CACAO to a pool where there were actually no assets.
These credits turned out to be completely unbacked. Maya's reserve held only 168,000 CACAO, so the transfer did not go through, leaving the accounting balance artificially inflated. The hacker deposited just 100 CACAO into the pool, claimed rights to 99.93%, and withdrew 48.87 million CACAO — nearly half of all 100 million tokens in circulation.
The CACAO price fell from $0.115 to $0.013, then partially recovered to $0.032. The attacker transferred 20.83 BTC (approximately $1.34 million) to a single Bitcoin address over ten blocks. Founder Aaluxx Myth announced a complete halt of the project on Discord and appealed to the hacker to return the funds.
Scale of the Threat: 2026 Statistics
The attack on Maya Protocol is just the tip of the iceberg. According to my calculations, there were 219 DeFi protocol hacks totaling $1.26 billion in 2026. For comparison, 146 incidents were recorded for all of 2025, but losses were higher — $2.71 billion. In August alone, there have already been 16 major cases.
Notably, the THORChain protocol, on which Maya is built, lost $10.7 million in May. This points to systemic vulnerabilities in the architecture of such cross-chain solutions.
Recovery of funds now depends on the hacker's willingness to return the assets for a reward. Aaluxx Myth also appealed to arbitrage traders who profited from price differences across the pools.
My analysis: This incident demonstrates that even protocols copying proven architectures are not immune to attacks. The key issue is the lack of limits on operations and insufficient smart contract auditing. Until the DeFi sector implements mandatory insurance mechanisms and multi-level transaction verification, we will continue to see similar hacks with alarming regularity.