Maya Protocol shut its network down after an attacker chained six software bugs together, withdrew nearly 49 million CACAO tokens, and drained bitcoin and other assets from the cross-chain DEX’s liquidity pools.
The pseudonymous co-founder Aalux said the attacker took about 20 bitcoin, worth roughly $1.4 million, plus another $300,000 in other assets. That puts the direct theft at an estimated $1.7 million, Cointelegraph reported. A preliminary analysis pinned the wider pool-value drop at about $10.9 million, driven by arbitrage activity and the collapse in CACAO’s price rather than the stolen assets alone. The $10.9 million figure is the pool-decline number behind the $11 million headline. The direct theft is pegged at $1.7 million.
Two numbers. Two different things. One measures what left the protocol. The other measures what the pools bled.
CACAO, Maya Protocol’s native token, fell from approximately $0.115 to $0.013 as the exploit played out. That is an 88.7% drop. Independent blockchain security researcher Vini Barbosa summarized the findings. The token was trading near $0.013 at the time of the report.
What makes this exploit notable is the technical breakdown. Aalux said the attacker packed 23 messages into a single transaction. Those messages triggered a false theft detection, artificially inflated a low-liquidity pool, and withdrew 48.87 million CACAO from Maya’s Asgard module. Six chained bugs, spanning trade accounts, outbound transaction handling, and liquidity pool calculations, let each step compound the last. One flaw opened the door. The next walked through it.
Of the withdrawn funds, about $1.36 million was moved to external blockchains, per the analysis. The attacker retained roughly $291,000 in CACAO and trade-account positions on MAYAChain.
Aalux said the protocol imposed a global halt to contain further damage and began working on a fix to resume swaps. No timeline for resuming operations was given.
What remains unknown: whether any of the moved funds can be recovered, whether the attacker has been identified, and whether a bounty or freeze arrangement is in play. The CoinDesk article referenced in initial reporting of this story was not accessible at press time. The figures here are single-sourced through Cointelegraph’s reporting of Aalux’s statements and the preliminary analysis.
For a protocol built on cross-chain swaps, the failure lives in the plumbing. The Asgard module, which the analysis says held the credited CACAO, is central to Maya’s liquidity management. Six bugs. Each one survivable on its own. Chained into a single 23-message transaction, they inflated a pool and drained it. That is the kind of compounding failure bridge and pool designers watch for. Whether Maya’s fix addresses the chain as a whole, or only the last link, is a question for when the network restarts.
Holders, as ever, are divided.


