← Maya Protocol — August 2026 Six-Bug Exploit1 decision on this page
Audit log
Every state-changing event for Maya Protocol — August 2026 Six-Bug Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-01 12:18:20ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
EtZ5cpYXPVB2…ApVdTZdTsha256 → base58
verifying row…canonical bytes (21217 B) ▸
{"actor":"system:backfill","investigation_id":"6454cdea-d014-42eb-80b9-6f5c255570fc","kind":"publish","page_slug":"maya-protocol-august-2026-six-bug-exploit","published_at":"2026-09-01T12:18:20.437Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Maya Protocol — August 2026 Six-Bug Exploit","sections":[{"content":"Maya Protocol is a decentralized cross-chain liquidity network whose underlying blockchain, MAYAChain, is a friendly fork of THORChain. The protocol launched its blockchain genesis in March 2023 and opened trading in April 2023, offering native cross-chain swaps between Bitcoin, Ethereum, USDC, USDT, and other assets using the native token CACAO (analogous to THORChain's RUNE) as the settlement layer. Security audits of the codebase were conducted by Halborn prior to launch, covering the ETH Router, Layer 1 and Liquidity Nodes, Liquidity Auction, Dynamic Inflation, Liquidity Auction Tiers, and Bifrost implementations for both Thorchain and Dash integrations. No prior publicly documented exploits of MAYAChain were identified before the August 2026 incident, though at least one post-incident analysis noted that bugs in a related part of the codebase had existed and were flagged in prior audit cycles without having been triggered.","heading":"Background: Maya Protocol and MAYAChain","severity":"medium","sources":[{"credibility":2,"name":"What Is Maya Protocol? — The Defiant","type":"news_article","url":"https://thedefiant.io/education/defi/what-is-maya-protocol"},{"credibility":1,"name":"Maya Protocol Audits — Official Documentation","type":"official","url":"https://docs.mayaprotocol.com/deep-dive/audits"},{"credibility":2,"name":"Maya Protocol Chain Integrations — THORChain Community","type":"other","url":"https://thorchain-community.medium.com/maya-protocol-chain-integrations-532d304520f3"}]},{"content":"At approximately 17:30 UTC on August 18, 2026, an attacker submitted a single MsgDeposit transaction at block 17977941 containing 23 individual messages targeting the low-liquidity Arbitrum Chainlink (ARB.LINK) pool. The transaction exploited a sequence of six distinct software bugs in MAYAChain's trade-account handling, outbound transaction processing, and liquidity-pool mathematics. Bug 1 (Voter Clobbering): Each successive message in the batched MsgDeposit transaction overwrote the previous ObservedTxVoter using the same transaction ID, causing a trailing DONATE message to reset OutboundHeight to zero. Bug 2 (Stride-Based Matching Flaw): The outbound matcher traversed blocks in signingTransPeriod strides rather than checking each block individually, causing it to miss the block at height 17977942 where the LINK outbound transaction had legitimately settled. This caused the system to incorrectly conclude the LINK transfer had been stolen. Bug 3 (Uncapped Subsidy Calculation): The slash compensation mechanism lacked bounds relative to pool depth. Converting the notionally stolen LINK through a pool holding only 0.11 LINK generated a calculated subsidy of 49.45 million CACAO—far exceeding the protocol's reserves of approximately 168,000 CACAO. Bug 4 (Pre-Commitment State Write): The pool balance was updated to reflect the 49.45 million CACAO subsidy before the Reserve transfer funding it was confirmed, allowing the state change to persist. Bug 5 (Failed Transfer Without Rollback): When the Reserve transfer subsequently failed due to insufficient funds, the error was logged but no rollback occurred, leaving the inflated 49.45 million CACAO balance permanently in state. Bug 6 (Pool Seeding Miscalculation): When the attacker deposited a minimal amount into the now-inflated but near-empty pool, the system triggered new-pool logic that issued the attacker approximately 99.93% of pool ownership from roughly 1 trillion units. This allowed the attacker to immediately withdraw 48.87 million CACAO plus real cross-chain assets from the pool. From block 17977971 onward, the attacker began collecting extracted value.","heading":"The Exploit: Attack Mechanism","severity":"critical","sources":[{"credibility":2,"name":"Maya Protocol Six-Bug Trade Account Exploit — DeFiMon","type":"research","url":"https://defimon.xyz/blog/maya-protocol-hack-august-2026"},{"credibility":2,"name":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Decrypt","type":"news_article","url":"https://decrypt.co/375976/maya-protocol-halts-network-bitcoin-exploit"},{"credibility":1,"name":"Maya Protocol Exploit Drains Bitcoin and Other Assets as Pool Value Drops $11 Million — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/19/maya-protocol-exploit-drains-bitcoin-and-other-assets-as-pool-value-drops-usd11-million"}]},{"content":"The direct attacker-controlled gain was approximately $1.65–1.7 million, composed of three parts. First, confirmed hard-asset extraction: 20.8273 BTC (approximately $1.34–1.36 million at the time of the attack) was moved to an external Bitcoin address identified and published by the Maya Protocol team (bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646). As of August 21, 2026, that address had recorded zero outgoing transactions. Second, on-chain held value: approximately $291,000 remained in attacker-controlled positions on MAYAChain. Third, ARB assets: 98.82 LINK and additional Arbitrum-based assets were also extracted. The total network pool value fell by approximately $10.9–11 million, a figure that encompasses three distinct components: (1) CACAO token repricing of approximately $6.4 million, as the CACAO price collapsed from approximately $0.115 to $0.013—an 88.7% decline—across all Maya pools; (2) arbitrage activity of approximately $2.9 million, as traders exploited the price dislocation by purchasing discounted CACAO and swapping it against BTC, ETH, and stablecoins faster than internal pool math could reprice them; and (3) the confirmed hard-asset extraction of approximately $1.36 million. The $11 million figure reported in several headlines reflects the total network pool value decline including CACAO repricing and arbitrage losses, not the direct theft amount. Protocol TVL immediately before the exploit was approximately $10 million.","heading":"Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"Maya Protocol Exploit: $11M Headline vs $1.7M Actual Loss — SpotedCrypto","type":"research","url":"https://www.spotedcrypto.com/maya-protocol-exploit-real-loss-2026/"},{"credibility":2,"name":"Maya Protocol Exploit Drains $1.7M as CACAO Falls 89% in a Day — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/maya-protocol-exploit-drains-17m-cacao-falls/"},{"credibility":2,"name":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/six-bug-exploit-halts-maya-182035824.html"},{"credibility":2,"name":"Maya Protocol exploited for $1.7M as attacker drains 48.87M CACAO tokens — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/maya-protocol-exploit-cacao-drained/"}]},{"content":"Following detection of the exploit, Maya Protocol enacted an emergency network-wide halt of MAYAChain, suspending all swaps and transactions to prevent further losses. Founder AaluxxMyth publicly confirmed the incident and stated the team would work to fix and recover in full. The team published the suspected attacker's Bitcoin address and extended a white-hat bounty offer, inviting voluntary fund return in exchange for a bug bounty and public vulnerability disclosure. As of the most recent reporting available (late August 2026), the attacker had not responded and the Bitcoin wallet remained unspent. The team committed to completing a comprehensive security audit by a reputable firm before restarting swap operations. As of the reporting cutoff, no patch timeline, no swap-restart date, and no LP compensation framework had been publicly announced.","heading":"Protocol Response and Network Halt","severity":"high","sources":[{"credibility":2,"name":"Maya Protocol Halts Operations After Multi-Bug Exploit — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/299219-maya-protocol-halts-operations-after-multi-bug-exploit-drains-cacao-tokens-and-cross-chain-assets/"},{"credibility":2,"name":"Maya Protocol suffers $1.7 million exploit, halts network — Crypto.news","type":"news_article","url":"https://crypto.news/maya-protocol-suffers-1-7-million-exploit-halts-network/"},{"credibility":2,"name":"Maya Protocol Exploit: MAYAChain Is Halted — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/maya-protocol-exploit-network-halt/"}]},{"content":"Rather than pursuing recovery of the stolen 20.83 BTC directly, co-founder Aaluxx announced that proceeds from the Aztec Chain project—described as a next-generation omnichain DeFi platform whose launch was said to be accelerated by the incident—and other means would be used to backfill the affected liquidity pool. The stated plan was that donating 20 BTC back to the pool through those means would restore CACAO to its pre-exploit price of approximately $0.115 and make liquidity providers whole. No timeline for that process was given. Analysis published after the incident noted that this approach mirrors the precedent set by THORChain in response to a series of exploits in 2021 (in which the community donated funds to affected pools rather than recovering stolen assets) and a May 2026 vault breach. Critics noted that the recovery plan depends entirely on assets and funding mechanisms outside the protocol itself, and that no final ledger dividing losses between hard-asset extraction, CACAO repricing, and dislocation trading had been published. At least one post-incident analysis also noted that founder Aaluxx hedged his own post-mortem disclosure, acknowledging uncertainty as to whether the incident was intentional exploitation or an accidental bug trigger—a characterization that some observers found inconsistent with standard incident communication practice.","heading":"Recovery Plan and Criticism","severity":"high","sources":[{"credibility":2,"name":"Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain's Old Playbook — Cryip","type":"research","url":"https://cryip.co/maya-protocol-hack-recovery-plan-thorchain-playbook/"},{"credibility":2,"name":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Decrypt","type":"news_article","url":"https://decrypt.co/375976/maya-protocol-halts-network-bitcoin-exploit"},{"credibility":2,"name":"Maya Protocol Becomes the 16th Crypto Hack Logged in August Alone — BeInCrypto","type":"news_article","url":"https://beincrypto.com/maya-protocol-exploit-halts-btc-swaps/"}]},{"content":"Prior to the August 2026 exploit, Maya Protocol had undergone security reviews by Halborn covering the ETH Router, Layer 1 and Liquidity Nodes, Liquidity Auction, Dynamic Inflation, Liquidity Auction Tiers, and Bifrost implementations. The six bugs exploited in August 2026 resided in the trade-account and outbound-flow logic—areas that multiple post-incident analyses characterized as insufficiently covered by prior reviews. At least one source noted that THORChain had identified a related latent flaw in Maya's codebase prior to August 2026 but that the vulnerability had not been previously triggered in production. Post-incident commentary from founder Aaluxx acknowledged that AI technology is enabling small teams to investigate codebases from larger perspectives simultaneously, framing this as both a defensive opportunity and a risk vector. The codebase's origins as a fork of THORChain—itself the subject of multiple exploits in 2021—have led some analysts to characterize the incident as evidence of systemic vulnerability patterns persisting across iterations of the same codebase rather than an isolated failure.","heading":"Security Audit History and Codebase Risk","severity":"high","sources":[{"credibility":1,"name":"Maya Protocol Audits — Official Documentation","type":"official","url":"https://docs.mayaprotocol.com/deep-dive/audits"},{"credibility":2,"name":"Maya Protocol loses $1.7M in sophisticated six-bug exploit — CryptoPolitan","type":"news_article","url":"https://www.cryptopolitan.com/maya-protocol-loses-1-7m-bug-exploit/"},{"credibility":2,"name":"Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain's Old Playbook — Cryip","type":"research","url":"https://cryip.co/maya-protocol-hack-recovery-plan-thorchain-playbook/"}]},{"content":"The Maya Protocol incident was reported as the 16th separate crypto hack recorded in August 2026 alone. The same week saw exploits affecting BounceBit, The Sandbox, and Term Labs, with combined losses across those four incidents estimated at approximately $15 million. This broader pattern indicates an elevated threat environment for DeFi protocols during the period, though each incident involved distinct attack vectors and is not directly linked to the Maya exploit.","heading":"Broader Context: August 2026 Exploit Wave","severity":"medium","sources":[{"credibility":2,"name":"Maya Protocol Becomes the 16th Crypto Hack Logged in August Alone — BeInCrypto","type":"news_article","url":"https://beincrypto.com/maya-protocol-exploit-halts-btc-swaps/"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week as Maya, BounceBit, Sandbox and Term Labs Fall — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"}]}],"sources_used":[{"credibility":1,"name":"Maya Protocol Exploit Drains Bitcoin and Other Assets as Pool Value Drops $11 Million — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/19/maya-protocol-exploit-drains-bitcoin-and-other-assets-as-pool-value-drops-usd11-million"},{"credibility":2,"name":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Decrypt","type":"news_article","url":"https://decrypt.co/375976/maya-protocol-halts-network-bitcoin-exploit"},{"credibility":2,"name":"Maya Protocol Six-Bug Trade Account Exploit — DeFiMon","type":"research","url":"https://defimon.xyz/blog/maya-protocol-hack-august-2026"},{"credibility":2,"name":"Maya Protocol exploited for $1.7M as attacker drains 48.87M CACAO tokens — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/maya-protocol-exploit-cacao-drained/"},{"credibility":2,"name":"Maya Protocol loses $1.7M in sophisticated six-bug exploit — CryptoPolitan","type":"news_article","url":"https://www.cryptopolitan.com/maya-protocol-loses-1-7m-bug-exploit/"},{"credibility":2,"name":"Maya Protocol Exploit Drains $1.7M as CACAO Falls 89% in a Day — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/maya-protocol-exploit-drains-17m-cacao-falls/"},{"credibility":2,"name":"Maya Protocol Exploit: $11M Headline vs $1.7M Actual Loss — SpotedCrypto","type":"research","url":"https://www.spotedcrypto.com/maya-protocol-exploit-real-loss-2026/"},{"credibility":2,"name":"Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain's Old Playbook — Cryip","type":"research","url":"https://cryip.co/maya-protocol-hack-recovery-plan-thorchain-playbook/"},{"credibility":2,"name":"Maya Protocol Halts Operations After Multi-Bug Exploit — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/299219-maya-protocol-halts-operations-after-multi-bug-exploit-drains-cacao-tokens-and-cross-chain-assets/"},{"credibility":2,"name":"Maya Protocol suffers $1.7 million exploit, halts network — Crypto.news","type":"news_article","url":"https://crypto.news/maya-protocol-suffers-1-7-million-exploit-halts-network/"},{"credibility":2,"name":"Maya Protocol Becomes the 16th Crypto Hack Logged in August Alone — BeInCrypto","type":"news_article","url":"https://beincrypto.com/maya-protocol-exploit-halts-btc-swaps/"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week as Maya, BounceBit, Sandbox and Term Labs Fall — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"},{"credibility":2,"name":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/six-bug-exploit-halts-maya-182035824.html"},{"credibility":2,"name":"Maya Protocol halts MAYAChain after bugs trigger $11 million loss — CryptoWisser","type":"news_article","url":"https://www.cryptowisser.com/news/six-software-bugs-let-hacker-drain-11m-from-maya-protocol/"},{"credibility":1,"name":"Maya Protocol Audits — Official Documentation","type":"official","url":"https://docs.mayaprotocol.com/deep-dive/audits"},{"credibility":2,"name":"What Is Maya Protocol? — The Defiant","type":"news_article","url":"https://thedefiant.io/education/defi/what-is-maya-protocol"}],"summary":"On August 18, 2026, an attacker exploited MAYAChain—the decentralized cross-chain liquidity network operated by Maya Protocol—by chaining six distinct software bugs in a single 23-message transaction. The exploit allowed the attacker to inflate a liquidity pool by approximately 49.45 million CACAO tokens, gain near-total control of that pool, and extract roughly $1.65–1.7 million in Bitcoin and other assets. CACAO's price fell approximately 89% and total network pool value dropped by an estimated $11 million, prompting an emergency network halt. As of late August 2026, the attacker's Bitcoin wallet remained unspent and no patch timeline or LP compensation framework had been publicly confirmed.","timeline":[{"date":"2023-03-01","event":"MAYAChain blockchain genesis. Maya Protocol launches as a friendly fork of THORChain with CACAO as its native settlement token.","source":"The Defiant — What Is Maya Protocol?","source_url":"https://thedefiant.io/education/defi/what-is-maya-protocol"},{"date":"2023-04-01","event":"MAYAChain trading opens with BTC, ETH, USDC, USDT, and RUNE paired against CACAO in liquidity pools.","source":"Maya Protocol Post Launch — Medium","source_url":"https://medium.com/@saltycashew03/maya-protocol-post-launch-c27433cf07cc"},{"date":"2023-07-01","event":"Dash blockchain integrated as Maya Protocol's first unique chain integration not present on THORChain.","source":"THORChain Community — Maya Protocol Chain Integrations","source_url":"https://thorchain-community.medium.com/maya-protocol-chain-integrations-532d304520f3"},{"date":"2026-08-18","event":"At approximately 17:30 UTC, an attacker submits a single 23-message MsgDeposit transaction at block 17977941, triggering a chain of six software bugs in MAYAChain's trade-account and outbound logic. The Arbitrum Chainlink (ARB.LINK) pool is inflated by 49.45 million CACAO via an uncapped slash subsidy with no rollback on failed reserve transfer. The attacker gains 99.93% ownership of the inflated pool and withdraws 48.87 million CACAO and 98.82 LINK. CACAO price collapses from approximately $0.115 to $0.013 (88.7% decline). Maya Protocol enacts a network-wide halt of MAYAChain.","source":"Maya Protocol Six-Bug Trade Account Exploit — DeFiMon","source_url":"https://defimon.xyz/blog/maya-protocol-hack-august-2026"},{"date":"2026-08-18","event":"The attacker moves 20.8273 BTC (approximately $1.34–1.36 million) to external Bitcoin address bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646.","source":"Maya Protocol Exploit Drains Bitcoin and Other Assets as Pool Value Drops $11 Million — CoinDesk","source_url":"https://www.coindesk.com/markets/2026/08/19/maya-protocol-exploit-drains-bitcoin-and-other-assets-as-pool-value-drops-usd11-million"},{"date":"2026-08-19","event":"Maya Protocol founder AaluxxMyth publicly confirms the exploit. The team publishes the attacker's Bitcoin address and extends a white-hat bounty offer in exchange for fund return and vulnerability disclosure. Recovery plan involving Aztec Chain investment proceeds is announced.","source":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Decrypt","source_url":"https://decrypt.co/375976/maya-protocol-halts-network-bitcoin-exploit"},{"date":"2026-08-21","event":"The attacker's Bitcoin address holds 20.8273 BTC with zero outgoing transactions as of this date. No response from the attacker to the white-hat bounty offer reported.","source":"Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen — Yahoo Finance","source_url":"https://finance.yahoo.com/markets/crypto/articles/six-bug-exploit-halts-maya-182035824.html"},{"date":"2026-08-24","event":"The Maya Protocol incident is reported as the 16th crypto hack of August 2026. Combined losses across Maya, BounceBit, The Sandbox, and Term Labs that week are estimated at approximately $15 million. Network remains halted with no announced patch or restart timeline.","source":"Crypto Hacks Drain $15M in a Week — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 1c48db84-4b5b-4693-9d29-5ca4e9ed6a87
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.