
Maya Protocol has halted its cross-chain network after an attacker exploited six linked software flaws to steal an estimated $1.7 million in Bitcoin and other crypto assets.
Summary
- Maya Protocol halted its network after an attacker stole an estimated $1.7 million in crypto.
- The exploit chained six software flaws and used a single transaction containing 23 messages.
- About $1.36 million was moved to external blockchains, while another $291,000 remained in attacker controlled positions.
- CACAO plunged 88.7% during the incident as Maya Protocol began working on fixes to restore swaps.
Maya Protocol pseudonymous co-founder Aalux said on Wednesday that the attacker took about 20 Bitcoin, worth roughly $1.4 million, alongside another $300,000 in assets before the protocol activated a global halt to stop further losses.
The team has since started working on fixes needed to restore swaps, while a preliminary technical analysis shared by Aalux traced the attack to a chain of bugs involving trade accounts, outbound transaction processing, and liquidity pool calculations.
Maya Protocol exploit used six chained bugs
According to the preliminary analysis, the attacker combined six separate flaws instead of relying on a single vulnerability, allowing several parts of MAYAChain’s transaction and accounting system to be manipulated within the same attack.
A single transaction containing 23 messages was used to execute the sequence. The analysis said the attacker first triggered the protocol’s theft-detection mechanism incorrectly before manipulating a pool with limited liquidity.
By inflating the value of the low-liquidity pool, the attacker was able to withdraw 48.87 million CACAO tokens from Maya’s Asgard module, according to the technical findings.
Asgard modules hold assets used by the protocol to process cross-chain swaps. Maya Protocol allows users to exchange native assets across different blockchains without relying on a traditional centralised exchange, making the network’s vault and liquidity accounting systems central to settling transactions.
The preliminary accounting estimated that approximately $1.36 million in assets ultimately moved to external blockchains. Another $291,000 remained under the attacker’s control through CACAO holdings and trade-account positions on MAYAChain.
Aalux said the global halt contained the incident and prevented additional damage while developers investigated the affected components and prepared a fix.
The response resembles emergency measures used by other cross-chain protocols when vulnerabilities threaten assets held across several networks. In June, Axelar disabled bridge routes connected to Secret Network after approximately $4.7 million in bridged assets were taken through an exploit linked to a Secret-side ICS-20 smart contract.
Axelar’s emergency committee shut the affected connections while the investigation continued. The interoperability protocol said at the time that its core infrastructure had not been compromised and that the problem appeared isolated to the smart contract supporting the connection with Secret Network.
CACAO price collapsed during the attack
Independent blockchain security researcher Vini Barbosa, summarising the preliminary findings, said CACAO dropped 88.7% during the incident, falling from about $0.115 to $0.013.
The decline in CACAO also complicated estimates of the total economic damage because the attack affected both assets directly extracted from the protocol and the market value of liquidity remaining in its pools.
According to the technical analysis, the total decline in pool value reached approximately $10.9 million. However, the report did not classify the entire amount as stolen funds because the calculation also included arbitrage activity and the sharp devaluation of CACAO during the incident.
The estimated amount directly moved out of the system was considerably lower, with about $1.36 million transferred to other blockchains and roughly $291,000 remaining in positions controlled by the attacker.
Cross-chain systems have faced several attacks this year in which the value initially affected by a vulnerability differed from the amount ultimately extracted. Echo Protocol, for example, paused cross-chain transactions in May after an attacker minted about $76.7 million worth of unauthorised eBTC on Monad. Security researchers later estimated that roughly $816,000 in actual value had been stolen despite the much larger unauthorised mint.
Echo’s incident was linked by security researchers to a compromised administrative private key. Monad co-founder Keone Hon said at the time that the underlying Monad network continued operating normally, while Curvance paused the affected Echo eBTC market as a precaution.
Cross-chain DEX exploits have forced similar network halts
Maya Protocol’s decision to stop network activity also follows a series of security incidents involving cross-chain trading infrastructure in 2026.
In May, crypto.news reported a THORChain exploit that forced the cross-chain DEX to pause trading and activate a global emergency halt after blockchain investigator ZachXBT estimated losses of at least $10 million across several networks.
THORChain later determined that approximately $10.7 million had been drained from one of its five vaults. The protocol said a newly churned node operator exploited a vulnerability in its GG20 Threshold Signature Scheme and reconstructed a private key, while automatic solvency checks stopped cross-chain signing and trading within minutes.
Node operators subsequently approved the ADR028 recovery plan, which used protocol-owned liquidity to absorb losses without minting new RUNE, selling RUNE or diluting existing holders. Developers also prepared version 3.19.0 with additional security measures, including a mechanism designed to quarantine compromised vaults.
After more than a month offline, THORChain resumed network trading on June 23. Swaps, signing, churning, secured assets, trade assets and liquidity provider functions were restored after the protocol said vaults and keyshares had been checked as part of the restart process.
Another cross-chain protocol, Transit Finance, lost about $1.88 million in May after an exploit flagged by blockchain security firm PeckShield. At the time of the initial report, Transit Finance had not released a detailed technical post-mortem or recovery plan.
Maya Protocol works on restoring swaps
For Maya Protocol, the immediate work is focused on fixing the vulnerabilities identified in the preliminary review before cross-chain swaps can resume.
The technical findings indicate that the attack depended on several components interacting in sequence, including trade-account behaviour, outbound transaction processing and liquidity calculations. The 23-message transaction allowed the attacker to combine those weaknesses, trigger an incorrect theft response and manipulate the low-liquidity pool before extracting CACAO from Asgard.
Maya’s incident comes as security concerns around cross-chain infrastructure remain focused on the number of components required to move assets between otherwise separate blockchain networks. A July crypto.news review of cross-chain bridges noted that such systems can use lock-and-mint, burn-and-mint or liquidity-based designs, while transaction verification can depend on validators, multisignature arrangements or cryptographic mechanisms.
Maya Protocol has not provided a timetable for fully restoring swaps in the information available so far. Aalux said the global halt had contained further damage and that the protocol was working on the fixes required to bring network operations back online.







