Maya Protocol has temporarily shut down its cross-chain network after an attacker exploited a series of connected software vulnerabilities and stole an estimated $1.7 million in cryptocurrency.
The attack reportedly involved six separate flaws that were combined into a single sophisticated exploit. Around $1.36 million worth of assets were successfully moved to external blockchains, while another $291,000 remained under the attacker’s control through CACAO holdings and trade-account positions.
The incident also caused significant turbulence for Maya Protocol’s native CACAO token, which reportedly plunged almost 89% during the attack.
Developers have now shifted their attention toward fixing the vulnerabilities and determining when cross-chain swaps can safely resume.
Maya Protocol Halts Network After $1.7 Million Attack
Maya Protocol pseudonymous co-founder Aalux said the attacker managed to take around 20 Bitcoin, valued at roughly $1.4 million at the time, along with approximately $300,000 in additional crypto assets.
Once the scale of the attack became clear, Maya Protocol activated a global network halt.
The emergency action was intended to stop the attacker from extracting additional assets while developers investigated what had happened.
Rather than exploiting one obvious vulnerability, the attacker appears to have taken advantage of several weaknesses across different parts of MAYAChain’s transaction and accounting infrastructure.
That complexity has made the incident particularly significant because it highlights how vulnerabilities that may appear limited individually can become much more dangerous when combined.
Attacker Combined Six Vulnerabilities
According to Maya Protocol’s preliminary technical analysis, the attacker chained together six different software flaws.
The entire sequence was executed through a single transaction containing 23 messages.
The exploit reportedly involved several components of the protocol, including trade accounts, outbound transaction processing, theft detection, and liquidity pool calculations.
The attacker first caused Maya Protocol’s theft-detection mechanism to react incorrectly before targeting a pool with relatively low liquidity.
By manipulating the value of that pool, the attacker was reportedly able to withdraw approximately 48.87 million CACAO tokens from Maya’s Asgard module.
Asgard modules play a critical role in Maya Protocol because they hold assets used to facilitate cross-chain swaps.
Maya allows users to exchange native cryptocurrencies across different blockchain networks without relying on a traditional centralized exchange. As a result, accurate vault accounting and liquidity calculations are essential to keeping the system solvent.
About $1.36 Million Left the Protocol
The total financial impact of the incident is more complicated than simply looking at the value removed from Maya’s liquidity pools.
Preliminary calculations indicate that approximately $1.36 million worth of crypto assets were successfully transferred to external blockchains.
Another roughly $291,000 remained under the attacker’s control through CACAO holdings and positions maintained on MAYAChain.
Together, those figures put the estimated directly controlled or extracted value at around $1.7 million.
The global network halt appears to have prevented the attacker from causing further immediate damage.
Maya Protocol’s developers are now examining each component involved in the exploit before allowing normal network operations to resume.
CACAO Price Crashes Nearly 89%
The attack also triggered a dramatic decline in CACAO.
Blockchain security researcher Vini Barbosa, summarizing the preliminary findings, said CACAO fell approximately 88.7% during the incident.
The token reportedly dropped from around $0.115 to approximately $0.013.
Such a sharp decline complicated efforts to calculate the true economic impact of the exploit.
The total value of Maya’s liquidity pools reportedly fell by around $10.9 million during the incident. However, that does not mean the attacker stole $10.9 million.
Part of the decline resulted from CACAO’s collapsing market price, while arbitrage activity also affected the value remaining in the pools.
The amount directly transferred outside the system was much smaller, at approximately $1.36 million, with another $291,000 remaining in positions controlled by the attacker.
This distinction is important because the headline decline in protocol liquidity can sometimes be significantly larger than the amount an attacker actually manages to steal.
Cross-Chain Protocols Remain Attractive Targets
Maya Protocol is not the only cross-chain platform to face a major security incident in 2026.
Cross-chain infrastructure has repeatedly attracted attackers because these systems need to coordinate assets, transactions, validators, vaults, and smart contracts across multiple blockchain networks.
That complexity can create additional attack surfaces.
In June, Axelar disabled bridge routes connected to Secret Network following an exploit involving approximately $4.7 million in bridged assets.
The affected routes were shut down while investigators examined the incident. Axelar said its core infrastructure had not been compromised and that the vulnerability appeared to be isolated to the smart contract supporting its Secret Network connection.
Other protocols have taken similar emergency measures when vulnerabilities threatened cross-chain assets.
THORChain Also Faced a Major Exploit
One of the more significant examples occurred earlier this year when THORChain was forced to halt trading following a security incident.
The cross-chain decentralized exchange eventually determined that approximately $10.7 million had been drained from one of its vaults.
According to the protocol’s findings, a newly churned node operator exploited a vulnerability involving its GG20 Threshold Signature Scheme and reconstructed a private key.
Automatic solvency checks helped stop cross-chain signing and trading shortly after the problem was detected.
THORChain later approved a recovery plan using protocol-owned liquidity to cover losses without minting additional RUNE or diluting existing holders.
Developers also introduced additional security measures, including mechanisms intended to isolate compromised vaults.
After more than a month offline, THORChain eventually restored network trading on June 23.
The incident demonstrated how a global halt can give developers time to investigate an exploit, verify infrastructure, and introduce safeguards before bringing a cross-chain network back online.
Other Cross-Chain Platforms Have Faced Similar Problems
Maya Protocol’s exploit adds to a growing list of incidents involving interoperability and cross-chain platforms.
Transit Finance reportedly lost approximately $1.88 million in another May exploit.
Echo Protocol also paused cross-chain activity after an attacker created roughly $76.7 million worth of unauthorized eBTC on Monad.
Despite the enormous value of the unauthorized mint, security researchers later estimated that approximately $816,000 in actual value had been stolen.
That incident demonstrates why the amount initially affected by an exploit and the amount ultimately extracted can be very different.
In Maya Protocol’s case, the estimated $10.9 million decline in pool value should therefore not be confused with the roughly $1.7 million directly extracted or controlled by the attacker.
Why Cross-Chain Networks Can Be Difficult to Secure
Cross-chain protocols solve an important blockchain problem: allowing assets and information to move between networks that otherwise operate independently.
But accomplishing that requires multiple systems to work together correctly.
Depending on their design, cross-chain platforms may use liquidity pools, lock-and-mint mechanisms, burn-and-mint systems, validators, multisignature arrangements, threshold signatures, or other cryptographic verification methods.
A weakness in one component can sometimes affect another.
The Maya Protocol attack appears to demonstrate this risk particularly well because the attacker did not rely on a single catastrophic bug.
Instead, several weaknesses were reportedly combined in sequence until they produced a much larger exploit.
That makes fixing the incident more complicated than simply patching one line of vulnerable code. Developers need to understand how the different components interacted and ensure similar combinations cannot be used again.
Maya Protocol Focuses on Restoring Swaps
Maya Protocol’s immediate priority is fixing the vulnerabilities identified during its preliminary investigation.
The attack appears to have depended on interactions between trade-account behavior, outbound transaction processing, theft detection, and liquidity calculations.
By combining those weaknesses through a 23-message transaction, the attacker was able to manipulate a low-liquidity pool before extracting CACAO from the Asgard module.
The network-wide halt prevented further immediate losses, but Maya Protocol has not yet provided a firm timetable for restoring cross-chain swaps.
Before reopening, developers will likely need to ensure that the vulnerabilities have been patched and that the network’s vaults, liquidity calculations, and transaction-processing mechanisms can operate safely.
What Happens Next for Maya Protocol?
The most important question now is when Maya Protocol can safely restart its network.
Restoring swaps too quickly could create additional risk if any part of the exploit remains unresolved. At the same time, a prolonged shutdown could hurt user confidence and liquidity.
The future of CACAO will also be closely watched following its dramatic price collapse.
For Maya Protocol, recovering from the incident will therefore require more than simply restoring technical functionality. The project will also need to demonstrate that the vulnerabilities behind the attack have been fully understood and addressed.
The global halt appears to have limited further losses, but the incident provides another reminder of the security challenges facing cross-chain DeFi infrastructure.
As blockchain networks become increasingly interconnected, the security of the systems linking them together will remain just as important as the security of the individual chains themselves.
Disclaimer: This content is provided for informational and educational purposes only and should not be considered financial or investment advice.


































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































