Overview
- Maya Protocol halted its cross‑chain network on Wednesday, August 19, 2026, after an attacker used a single 23‑message transaction that chained six software flaws to manipulate accounting and withdraw assets.
- The attacker extracted about 48.87 million CACAO from the Asgard vault and removed roughly 20 BTC (about $1.4 million) plus $300,000 in other assets, with preliminary accounting showing $1.36 million moved to external chains and $291,000 left in on‑chain positions.
- The exploit combined failures in trade‑account logic, outbound transaction processing, and liquidity calculations to trigger a false theft response and inflate a low‑liquidity pool before withdrawal.
- CACAO’s market price collapsed by roughly 89%, producing an estimated $10.9 million drop in pool value that reflects token devaluation and arbitrage as well as the direct outflows.
- Maya activated its Mimir halt flags to freeze deposits and withdrawals, investigators including PeckShield are forensically tracing funds, and developers are preparing fixes with no restart timetable given, a development that echoes several 2026 cross‑chain failures and could slow interoperability restores.