Login
Sign Up
Woofun AI reports that the Maya Protocol suffered a $1.7 million loss due to a sophisticated exploit involving six chained vulnerabilities, triggering an 89% collapse in its native CACAO token and exposing critical structural weaknesses shared with THORChain.
Blockchain security firm CertiK identified the incident on August 19, estimating direct losses at approximately $1.7 million. The attackers manipulated the protocol by inducing the distribution of non-existent subsidies, a tactic that distorted internal accounting records. By repeatedly adding and removing liquidity against these fake subsidies, the exploiters extracted assets from the shared pool. This maneuver resulted in the theft of roughly 48.87 million CACAO tokens and 98.82 LINK tokens, demonstrating how liquidity extraction mechanisms can be weaponized when paired with accounting errors.
DefiLlama's hacker database classified the event, which occurred on August 18, as a "protocol logic flaw" with losses totaling $1.7 million.
However, developer Vini Barbosa argued that the actual damage was far more severe, describing it as a "complex chain of six vulnerabilities being exploited in sequence." While tangible assets stolen exceeded $1.36 million, the cascading market impact pushed total losses toward $11 million. CACAO prices plummeted from $0.115 to $0.013 within fewer than 240 blocks, representing a decline of nearly 89% and highlighting the fragility of token valuations during rapid exploit execution.
Aaluxx, one of Maya's founders, acknowledged the losses on the same day, pledging to "work hard to fix things and recover everything lost." The incident casts a long shadow over THORChain, a friendly fork of which Maya is. THORChain itself endured a $10.7 million hack in May, where a new node operator exploited a vulnerability in the GG20 threshold signature system. In that case, solvency checks failed to detect the issue until after the attack had already concluded, revealing a systemic lag in defensive monitoring capabilities across related protocols.
In a THORChain community podcast, Aaluxx clarified that the Maya attack relied on three old vulnerabilities that were not dangerous in isolation but became critical when combined. He explicitly stated that Maya possessed similar underlying flaws to those found in THORChain. This admission underscores a broader industry risk: legacy codebases often harbor dormant weaknesses that only manifest under specific, multi-step attack conditions. The convergence of these historical bugs created a pathway for exploitation that standard audits had previously missed.
To determine the root cause, the team conducted an exhaustive forensic investigation, scrutinizing encryption configuration parameters and searching for small prime numbers that should not have existed in the system. This process was necessary to locate the infected vault responsible for the breach. The investigation revealed a common dilemma faced by defenders: simple balance monitors can only detect losses after funds have changed hands. By the time these monitors trigger alerts, it is often too late to halt the transaction, leaving protocols vulnerable to irreversible asset drains.
Aaluxx warned that AI technology is enabling smaller teams to examine codebases from multiple angles simultaneously, a development that benefits both defenders and attackers. While this enhances detection capabilities, it also allows malicious actors to identify unique vulnerabilities that might evade existing audit processes. To counter this, Aaluxx proposed redundancy rather than reliance on a single system. Maya and THORChain chose to remain independent rather than adopting an integrated approach, ensuring that if THORChain were down for weeks, Maya could continue processing exchanges through a verified healthy vault.
Woofun AI data shows that strong defenses must include integrity tests, adversarial simulation of multi-step attack paths, independent review of accounting logic, real-time anomaly detection, and automatic circuit breakers for unusual withdrawals or pool balances. The Maya incident demonstrated how fake theft detections, incorrect outbound transaction handling, and liquidity accounting errors can combine to create catastrophic risks. Protocols must test the interactions between security controls, not just individual vulnerabilities, to prevent such compounded failures from occurring in live environments.
Regarding the date discrepancy, some data providers marked the incident as August 19 (UTC+8), which corresponds to the evening of August 18 in UTC time. Thus, the August 19 date noted by some providers reflects when the record was created or updated, not the initial block timestamp. TRM Labs reported that there were 207 hacks in the cryptocurrency sector in the first half of 2026, the highest number for a half-year period. This trend indicates that smart contracts are increasingly being attacked via various methods rather than through single vulnerabilities, a pattern the Maya incident exemplifies perfectly.
DeFi security cannot be ensured without identifying and fixing specific vulnerabilities before they are exploited. Maya aims to address current issues by accelerating the development of Aztec Chain, a multichain DeFi project built on lessons from Maya, THORChain, and Rujira. If these lessons help create better solutions instead of simply restarting the cycle of fixing defects, the value of the Maya incident could far exceed the $1.7 million loss. This marks a critical juncture where architectural redundancy may become the standard for resilient DeFi infrastructure.