NewsCryptoMaya Protocol Exploited for $1.7M as Attacker Drains 48.87M CACAO Tokens

Maya Protocol Exploited for $1.7M as Attacker Drains 48.87M CACAO Tokens

Author: CryptoBriefing·

Key Takeaways

  • An attacker chained six separate logic flaws into a single 23-message transaction to drain approximately 48.87 million CACAO tokens, 98.82 LINK, and 20.83 BTC, totaling roughly $1.7 million in direct losses.
  • CACAO's price plummeted nearly 89%, from about $0.115 to roughly $0.013, and even after recovering to around $0.03 remained approximately 74% below pre-exploit levels.
  • Maya Protocol's total pool value fell by an estimated $10.9 million, exceeding its roughly $10 million pre-exploit total value locked and effectively wiping out the protocol's capital base.
  • The team halted the network and is pursuing a white-hat bounty offer to the attacker as well as possible compensation for liquidity providers through its Aztec Chain.
  • The exploit adds to a pattern of cross-chain protocol breaches, following major losses at Ronin Bridge, Wormhole, Nomad, and the Bybit exchange's roughly $1.5 billion theft in February 2025.
Maya Protocol Exploited for $1.7M as Attacker Drains 48.87M CACAO Tokens

Maya Protocol, a cross-chain liquidity platform built as a fork of THORChain, suffered a sophisticated exploit on August 18, 2025 that drained approximately 48.87 million CACAO tokens and 98.82 LINK from its shared liquidity pools. The direct theft amounted to roughly $1.7 million, but the collateral damage extended considerably further: CACAO's price fell nearly 89%, and the protocol's total pool value declined by an estimated $10.9 million. CACAO is the network's native asset — Maya's counterpart to THORChain's RUNE — and serves as the settlement token for its cross-chain swaps.

Protocol founder AaluxxMyth publicly confirmed the exploit, while blockchain security firm CertiK flagged the stolen assets. The network has since halted operations to contain further losses, and the team is exploring recovery options, including a white-hat bounty offer to the attacker.

How the Exploit Worked

The attack was not a simple smash-and-grab. The attacker chained together six distinct bugs in Maya Protocol's logic, executing a single transaction containing 23 messages that manipulated the protocol's internal accounting systems. The approach has been compared to finding six separate unlocked doors in a building and walking through all of them in exactly the right sequence to reach the vault. The precision required suggests the attacker spent considerable time studying Maya's codebase before striking.

The attack targeted Maya's shared liquidity infrastructure, which is designed to facilitate swaps across multiple blockchains. Cross-chain protocols such as Maya are inherently complex because they must track balances and verify transactions across different networks simultaneously. That complexity creates additional attack surface, and in this case six different flaws were available to be exploited in concert.

In total, the attacker moved 20.83 BTC during the exploit, alongside the CACAO and LINK tokens.

Market Fallout

CACAO's price collapsed in the hours following the exploit. The token had been trading at around $0.115 before the attack and plummeted to approximately $0.013, a decline of nearly 89%. It has since recovered to the $0.03 range, which still represents a roughly 74% decline from pre-exploit levels.

In Maya's THORChain-style design, CACAO sits on one side of every liquidity pool, which ties the token's price directly to the protocol's overall pool depth. For liquidity providers who had capital deployed in Maya's pools, the damage extends well beyond the $1.7 million the attacker actually stole. The total pool value decline of approximately $10.9 million reflects how liquidity evaporated as panic set in and the protocol halted.

Maya Protocol's total value locked (TVL) before the exploit stood at approximately $10 million, meaning the pool value decline effectively wiped out the protocol's entire TVL and more once the cascading price effects on CACAO-denominated positions are factored in.

Recovery Plans and the Road Ahead

Maya's team is pursuing a multi-pronged recovery strategy. The most immediate step was halting the network to prevent additional drainage. Beyond that, the protocol is exploring asset replenishment through its Aztec Chain, which could potentially be used to compensate affected liquidity providers.

The team has also extended a white-hat offer to the attacker. This is a common playbook in DeFi exploits: return the funds, keep a percentage as a bug bounty, and avoid legal consequences. The approach has succeeded before — Euler Finance recovered $197 million through a similar arrangement in 2023, and Wormhole's $320 million exploit was eventually resolved. Plenty of attackers, however, simply ignore the offer and move on with the stolen funds.

Even if the attacker returns the assets, Maya Protocol faces a significant rebuilding challenge. Cross-chain protocols already sit in a higher risk tier in most investors' mental models, and a six-bug exploit does little to inspire confidence in the codebase. The protocol will almost certainly need a comprehensive audit from a reputable security firm before it can expect meaningful capital to flow back in.

Broader Context

For the wider DeFi ecosystem, the incident is another data point in a long-running pattern. Cross-chain bridges and multi-chain liquidity protocols have been among the most frequently exploited categories in crypto. The Ronin Bridge lost $625 million in 2022, Wormhole lost $320 million, and Nomad lost $190 million. Maya's lineage underscores the point: the protocol descends from THORChain, which was itself exploited twice in mid-2021 for a combined total of roughly $13 million. And 2025 has already produced the largest single theft in crypto history — the February breach of the Bybit exchange, which resulted in roughly $1.5 billion in stolen assets. Maya's $1.7 million in direct losses is small by comparison, but the proportional impact on its ecosystem — effectively destroying its entire TVL — was equally devastating for its users.

The incident will likely push more capital toward protocols with longer track records and multiple completed audits. For newer cross-chain projects, the bar for earning trust has been raised. Investors who were already cautious about deploying capital into interoperability protocols now have another case study supporting that caution.

Whether Maya Protocol can rebuild depends entirely on what happens next: whether the white-hat offer succeeds, how quickly the team can patch all six vulnerabilities, and whether a credible third-party audit can validate the fixes. The crypto market has a short memory for protocols that recover well, but an even shorter tolerance for those that stumble twice.