Cryptelio

Hacks & Exploits

Maya Protocol Suffers $1.7M Exploit, Halts Operations Amid Liquidity Crisis

Cryptelio Editorial Published 19 Aug 2026 · 19:00 UTC

Maya Protocol, a cross-chain liquidity platform, was compromised on August 18, resulting in the theft of approximately 48.87 million CACAO tokens and 98.82 LINK from its liquidity pools, totaling around $1.7 million. The exploit caused CACAO's price to plummet nearly 89%, and the protocol's total pool value dropped by an estimated $10.9 million.

The exploit was executed through a complex manipulation of the protocol's accounting systems, where the attacker exploited six distinct software vulnerabilities. This allowed them to inflate the recorded balance of a liquidity pool, leading to an artificial payout of CACAO tokens in a low-liquidity environment. The attacker subsequently withdrew the tokens and converted them into approximately 20.83 BTC.

In response to the incident, Maya Protocol's team halted all operations to prevent further losses and is exploring recovery options, including a potential white-hat bounty offer to the attacker. The fallout from the exploit has raised concerns about the security of cross-chain protocols, which have been frequent targets for similar attacks.

The incident has left liquidity providers facing significant losses, as the total value locked in the protocol has effectively been wiped out. The protocol's future will depend on its ability to address the vulnerabilities, regain user trust, and potentially recover the stolen assets.

FAQ

What happened to Maya Protocol on August 18?

Maya Protocol suffered an exploit that resulted in the theft of approximately 48.87 million CACAO tokens and 98.82 LINK, totaling around $1.7 million.

How did the exploit affect the price of CACAO tokens?

The exploit caused the price of CACAO tokens to plummet nearly 89%.

What actions did Maya Protocol take in response to the exploit?

Maya Protocol halted all operations to prevent further losses and is exploring recovery options, including a potential white-hat bounty offer to the attacker.

What vulnerabilities were exploited in the attack?

The attacker exploited six distinct software vulnerabilities to manipulate the protocol's accounting systems, inflating the recorded balance of a liquidity pool.

What are the implications of this incident for cross-chain protocols?

The incident has raised concerns about the security of cross-chain protocols, which have been frequent targets for similar attacks, and highlights the need for improved security measures.

Read story →