Maya Protocol (2026) — Crypto Hack
ActiveCross-chain liquidity protocol Maya Protocol (MAYAChain, THORChain fork) drained after attacker chained 6 bugs to credit a pool with 49M CACAO that was never funded, then withdrew 48.87M CACAO and swapped for BTC/ETH. CACAO crashed 89%.
Summary
Cross-chain liquidity protocol Maya Protocol (MAYAChain, THORChain fork) drained after attacker chained 6 bugs to credit a pool with 49M CACAO that was never funded, then withdrew 48.87M CACAO and swapped for BTC/ETH. CACAO crashed 89%.
How It Was Compromised — Cross-Chain via Logic Bug Chain (6 chained bugs)
Maya Protocol, a cross-chain liquidity protocol and THORChain fork, suffered a complex exploit on August 18, 2026. The attacker chained six separate bugs to credit a liquidity pool with 49 million CACAO tokens that were never actually funded. The attacker then withdrew 48.87 million CACAO and swapped them for Bitcoin and Ethereum. The CACAO token crashed 89% following the exploit, and the total pool value declined by approximately $10.9 million, with approximately $1.7 million in direct theft. The exploit demonstrated the risks of complex cross-chain liquidity protocols where multiple minor bugs can be chained together into a catastrophic attack.
Fund Flow & Laundering Analysis
Stolen CACAO was rapidly swapped for BTC and ETH across the protocol's cross-chain pools, making fund tracing difficult across multiple blockchain networks.