The decentralized liquidity protocol Maya Protocol has fallen victim to a large-scale hacker attack. The attacker, exploiting six vulnerabilities in the code, drained approximately $1.7 million from the system. This incident marks the sixteenth major hack in the cryptocurrency industry in August, highlighting systemic security issues in the DeFi sector.

The loss of funds was first reported by the project's co-founder under the pseudonym Aaluxx. The market reaction was immediate: the price of the native token CACAO plummeted by 88%. The hacker quickly converted the stolen assets into Bitcoin (BTC), Ethereum (ETH), and other cryptocurrencies, distributing them across all of Maya's liquidity pools.

Anatomy of the Attack: One Transaction, 23 Commands

What makes this attack unique is its technical complexity and elegance. The hack was carried out within a single transaction consisting of 23 separate commands. Due to this structure, the network mistakenly treated the malicious operation as legitimate, allowing the attacker to bypass standard security mechanisms.

The protocol attempted to compensate for the losses but encountered a fatal flaw in its own logic. The system tried to credit about 49 million CACAO to a pool that had almost no assets. These credits were not backed by anything — Maya's reserve held only 168,000 CACAO. As a result, the transaction failed, but the balance in the ledger remained artificially inflated.

The hacker deposited just 100 CACAO into this pool, claimed rights to 99.93%, and withdrew 48.87 million CACAO — nearly half of all 100 million tokens in circulation.

As a result, the CACAO price collapsed from $0.115 to $0.013, before partially recovering to $0.032. The attacker transferred 20.83 BTC (about $1.34 million) to a single Bitcoin address over ten blocks. Co-founder Aaluxx Myth announced a complete halt of the project on Discord and appealed to the hacker to return the funds.

Epidemic of Hacks: 2026 Statistics

This incident is just the tip of the iceberg. Based on my calculations from public data, there have already been 219 DeFi protocol hacks totaling $1.26 billion in 2026. For comparison, the entire year of 2025 saw 146 incidents, though losses were higher at $2.71 billion. August alone has already seen 16 cases. Notably, THORChain, the protocol on which Maya is built, lost $10.7 million in May.

Recovery of funds now depends on whether the hacker agrees to return the assets for a reward. Aaluxx Myth also added that the team has reached out to arbitrage traders who profited from price differences in the pools.

My comment: The Maya Protocol hack is not just another incident but a stark demonstration that even protocols built on proven codebases can contain critical vulnerabilities. The increasing frequency of attacks in 2026 indicates that hackers are becoming more sophisticated, while DeFi projects often skimp on security audits. Investors should be extremely cautious with assets in protocols with low liquidity and insufficient audit history. The market needs security standards, not just post-mortem reports on hacks.