Particle.news

Maya Protocol Halted After $1.7 Million Multi‑Bug Exploit

The breach exposed systemic fragility in cross‑chain accounting, forcing a global halt while developers prepare patches.

Overview

  • Maya Protocol halted its cross‑chain network on Wednesday, August 19, 2026, after an attacker used a single 23‑message transaction that chained six software flaws to manipulate accounting and withdraw assets.
  • The attacker extracted about 48.87 million CACAO from the Asgard vault and removed roughly 20 BTC (about $1.4 million) plus $300,000 in other assets, with preliminary accounting showing $1.36 million moved to external chains and $291,000 left in on‑chain positions.
  • The exploit combined failures in trade‑account logic, outbound transaction processing, and liquidity calculations to trigger a false theft response and inflate a low‑liquidity pool before withdrawal.
  • CACAO’s market price collapsed by roughly 89%, producing an estimated $10.9 million drop in pool value that reflects token devaluation and arbitrage as well as the direct outflows.
  • Maya activated its Mimir halt flags to freeze deposits and withdrawals, investigators including PeckShield are forensically tracing funds, and developers are preparing fixes with no restart timetable given, a development that echoes several 2026 cross‑chain failures and could slow interoperability restores.