Key Takeaways
- The decentralized exchange Maya Protocol suffered a $1.7 million security breach, marking its first significant fund loss since its 2023 debut
- A sophisticated attack leveraged six interconnected vulnerabilities through one complex transaction containing 23 messages, extracting 48.87 million CACAO tokens
- The breach resulted in the theft of approximately 20 Bitcoin valued at $1.4 million, plus an additional $300,000 in various digital assets from protocol vaults
- The native CACAO token experienced a devastating price collapse of nearly 89%, plummeting from approximately $0.115 to $0.013
- Protocol administrators implemented an emergency network-wide shutdown while developers work on security patches
The cross-chain decentralized trading platform Maya Protocol executed an emergency shutdown on Wednesday following a sophisticated theft that resulted in approximately $1.7 million in stolen cryptocurrency.
Maya’s co-founder, operating under the pseudonym Aalux, publicly acknowledged the security incident and revealed that the development team initiated a comprehensive network freeze to prevent additional losses.
The stolen assets included approximately 20 Bitcoin with a current market value near $1.4 million, supplemented by roughly $300,000 worth of additional cryptocurrencies.
Technical Breakdown of the Exploit
Early forensic investigation revealed the breach stemmed from six interconnected software vulnerabilities affecting trade account mechanics, outbound transaction processing, and liquidity pool mathematical operations.
The perpetrator orchestrated a sophisticated assault using one comprehensive transaction composed of 23 individual messages designed to activate fraudulent theft alerts, manipulate a thinly-traded liquidity pool, and ultimately extract 48.87 million CACAO tokens from Maya’s Asgard security module.
Approximately $1.36 million worth of assets were successfully transferred to external blockchain networks. The attacker retained around $291,000 in CACAO tokens and trade-account balances within the native chain.
Cybersecurity intelligence firm PeckShield detected the compromise and confirmed that assets were siphoned from the protocol’s vault systems before automated financial integrity mechanisms could successfully intervene.
Maya Protocol maintained approximately $15 million in total value locked prior to the incident, based on data from DeFiLlama. The compromised funds constitute slightly more than 10% of that total.
CACAO’s active market capitalization currently stands at approximately $10 million. The token had already depreciated over 92% from its peak value of $1.43 before this latest security incident.
Independent blockchain analyst Vini Barbosa calculated the broader liquidity pool depreciation at $10.9 million, though this assessment encompasses arbitrage trading operations and token devaluation effects beyond the directly stolen assets.
Official Protocol Response
Aalux confirmed the team has pinpointed the security weakness and is currently developing remediation measures. He expressed appreciation for the rapid coordination from node operators.
As a derivative project of THORChain, Maya Protocol follows a “halt first” security framework, prioritizing immediate trading suspension over financial rescue packages when incidents occur.
Maya’s Mimir emergency halt mechanisms were deployed, effectively suspending deposit and withdrawal functionality across compromised liquidity pools while validators and technical teams conducted their investigation.
Historical Ecosystem Perspective
This security breach occurs in the wake of THORChain’s own exploitation in May 2026, where attackers initially extracted approximately $10.8 millionālater reassessed to $7.4 millionāwhich similarly necessitated a complete operational suspension.
Maya had successfully maintained over three years of operation without any confirmed fund-loss incidents since launching its production network in April 2023.
The development team has committed to releasing a comprehensive incident analysis detailing precisely how the attacker circumvented Maya’s security infrastructure in the forthcoming days.





