T
iTokenly

Maya Protocol hack — August 2026

Verified — 3 sourcesLast checked August 21, 2026

Incident facts

Date of incident
Publicly disclosedAugust 18, 2026
Target typeDecentralised exchange
Loss$1,700,000Published estimates range $1,650,000 to $1,700,000Price at time of incident
MethodContract logic errorSix bugs chained in one 23-instruction transaction; an uncapped slash subsidy inflated the pool's CACAO balance, and a 100 CACAO deposit against the inflated figure claimed 99.93 per cent of the pool
ChainsBitcoin, Ethereum, Other
OutcomeUnresolved

What happened

Maya Protocol, a cross-chain liquidity network, was drained on 18 August 2026 in a single transaction carrying 23 instructions that chained six separate bugs together. An uncapped slash subsidy let the attacker inflate a low-liquidity pool's recorded CACAO balance by about 49.45 million tokens; depositing 100 CACAO against that inflated figure then claimed 99.93 per cent ownership of the pool, and 48.87 million CACAO came back out.

The founder, posting as AaluxxMyth, put it plainly: about 20 BTC worth roughly $1.4 million and another $300,000 in other assets. Roughly $1.36 million of that was moved off to external chains, with about $291,000 left in attacker-controlled positions. CACAO, whose total supply is 100 million, fell about 88 per cent.

MAYAChain was halted. The team asked the attacker to return the funds under a white-hat bounty and said it would contact the arbitrage traders who absorbed pool value on the way down. Recovery depends on whether the offer is taken.

The team has acknowledged that the bugs survived three to four years and prior audits by Halborn and Fable 5. Dates differ slightly across coverage between 18 and 19 August; the founder's own announcement is dated 18 August, which is what this record follows. No attribution has been established.

Sources

  1. DecryptSecondary · retrieved 2026-08-21
  2. crypto.newsSecondary · retrieved 2026-08-21
  3. Crypto AdventureSecondary · retrieved 2026-08-21

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Maya Protocol hack — August 2026", iTokenly, accessed 2026-08-21, https://itokenly.com/hacks/maya-protocol
https://itokenly.com/hacks/maya-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.