Cross-chain liquidity protocol Maya Protocol was exploited for an estimated $1.7 million on August 18, in what marks the THORChain fork's first significant loss-of-funds incident since its mainnet launched in April 2023. The attack struck around 17:30 UTC, and a preliminary technical analysis attributed it to six chained bugs spanning trade-account handling, outbound transaction processing and liquidity pool accounting.

The attacker used a single transaction packed with 23 messages to trigger a false theft-detection flag, artificially inflate a low-liquidity pool, and withdraw roughly 48.87 million CACAO tokens from Maya's Asgard module. Confirmed extraction to external chains totaled about $1.36 million in Bitcoin, ARB-based tokens and native CACAO, with total attacker-controlled value approaching $1.7 million once on-chain remainders are included. CACAO's price collapsed roughly 88%, from about $0.115 to near $0.013, as the exploited funds were swapped into other assets, before partially recovering into the $0.03 range.

Maya Protocol Exploited for $1.7M in Chained Six-Bug Attack
Image via @coinbureau on X

Team Halts the Chain and Offers a Bounty

Validators froze deposits and withdrawals on the affected pools within the immediate aftermath by activating Maya's chain-halt flags, buying time for the development team to investigate. Founder AaluxxMyth acknowledged the incident directly on X, thanked node operators for their rapid response, and said the team had identified the vulnerability and was preparing a patch while pledging to make affected users whole. The team also extended a white-hat offer to the attacker: return the stolen funds and publicly disclose the vulnerability in exchange for a bounty, rather than face pursuit.

Related: Falcon Finance Launches Regulated GPU Tokenization in El Salvador

An Echo of THORChain's Own May Exploit

The incident lands just three months after THORChain itself, the protocol Maya forked from, suffered a roughly $10.8 million exploit in May 2026 that froze cross-chain activity for 13 hours and prompted a dedicated recovery portal for more than 12,000 affected wallets. White-hat negotiations, in which an attacker is offered a percentage of the stolen funds to return the rest, have become a recurring playbook across the THORChain ecosystem rather than a one-off response, though THORChain has separately faced criticism from security researchers over how its own bug bounty program was managed following that exploit.

What It Signals for THORChain-Derived Protocols

Maya's six-bug chain, hitting the same category of cross-chain liquidity logic that has already burned its parent protocol once this year, suggests the underlying architecture shared across THORChain forks carries risk that individual forks haven't fully isolated. Whether the white-hat offer succeeds will likely shape how quickly confidence in CACAO and Maya's liquidity pools recovers, but the repeat pattern across two related protocols in a single year is likely to draw closer scrutiny to how THORChain-based codebases handle outbound transaction and pool-accounting edge cases.