Invest1 distinct publisher3 min readUpdated
CertiK puts Maya Protocol's direct loss at $1.7 million. A developer tracking the incident puts total impact near $11 million. The gap is the part audit tooling cannot see.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
Two loss figures are in circulation, and both are defensible, which is the uncomfortable part. The attacker left with 48.87 million CACAO and 98.82 LINK [4]. At the pre-attack price of $0.115, that CACAO was worth about $5.6 million; at the post-attack price of $0.013, about $635,000 [3]. Any single dollar figure for this incident is a decision about which of those two prices counted, taken during an event that moved the price 89% inside 240 blocks [2][7].
The mechanism explains why the accounting is that slippery. According to CertiK, the attacker convinced Maya to award a subsidy that did not exist, misstating internal accounting, then added and removed liquidity repeatedly to pull assets out of shared pools [3]. No step in that sequence requires a broken line of code. Cryptopolitan's read is that ordinary protocol logic behaved differently than expected, and the six bugs spanned accounting, liquidity and outbound transaction handling [1]. DefiLlama filed it under "Protocol Logic" [5], which is the honest label and also an admission that the category has no simple detector.
THORChain, which Maya was forked from [15], already ran this experiment. Its May incident cost $10.7 million, and the post-mortem attributes it to a new node operator exploiting the GG20 threshold-signature scheme, with solvency checks registering the problem only after the attack finished [9]. Aaluxx, a Maya founder, later said on THORChain's community podcast that three older bugs, none dangerous alone, became dangerous chained, and that Maya carried the same latent flaw [10]. Finding it took forensics down to cryptographic configuration parameters and a hunt for small primes that should not have been present [11]. A balance monitor, by contrast, reports the loss after the funds have moved [12].
That is the structural problem for defenders. An audit priced per contract finds broken lines. Nothing in that workflow prices the interaction between two controls that are individually correct. Aaluxx argues AI tooling now lets small teams look at a codebase from many angles at once, which helps defenders and equally gives attackers more paths to novel bugs that existing audit processes miss [13].
His answer was redundancy rather than integration: Maya and THORChain stayed separate, which let Maya keep serving swaps from a verifiably healthy vault while THORChain sat idle for weeks [14]. Worth noting what that independence did not buy. Operational separation held; code lineage did not, since the same latent flaw sat in both stacks [10]. Aaluxx said the team would work to fix and recover in full [8]. A treasury can refund $1.36 million of hard assets [6]. It cannot refund the roughly $9.6 million of damage that came from the repricing [1].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Maya Protocol lost about $1.7 million after a hacker exploited six bugs involving accounting, liquidity and outbound transactions; the vulnerabilities were not the direct result of a broken line of code but of regular protocol logic behaving differently than expected.
CACAO crashed nearly 89%, falling from $0.115 to $0.013 as the attacker moved millions of tokens and other assets.
Blockchain security firm CertiK estimated total direct loss at about $1.7 million, saying the hacker deceived Maya into awarding a nonexistent subsidy and then repeatedly added and removed liquidity to extract assets from shared pools.
CertiK identified the event on August 19 and said the hacker misrepresented Maya's internal accounting through a fake subsidy, then altered liquidity positions to withdraw an estimated 48.87 million CACAO and 98.82 LINK.
The DefiLlama Hacks and Exploits Database classified the August 18 occurrence as "Protocol Logic" and attributed a loss of $1.7 million.
Barbosa said the token fell from $0.115 to $0.013 in less than 240 blocks, a drop of nearly 89%.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named third-party attribution, no primary documents
Two independent trackers (CertiK, DefiLlama) converge on the $1.7M direct loss and the incident is dated, quantified and classified, with a named developer reconstruction and a protocol post-mortem cited for the THORChain parallel. But everything reaches the reader through one general-interest outlet that links none of the primary artifacts, the loss magnitudes ($1.7M / $1.36M / ~$11M) are never reconciled, and supporting industry framing (TRM Labs half-year count, 'research published this month') is uncited.
Incident and price damage observable; aftermath undocumented
The real-world footprint is concrete on the harm side: a dated on-chain exploit with specified asset quantities, a two-tracker loss attribution, an 89% token drawdown, and a prior THORChain incident with the same latent flaw. What is absent is any measured uptake of the prescribed remedies — no evidence that invariant testing, circuit breakers or anomaly detection were deployed at Maya, no post-incident price, liquidity or LP-recovery data, and only a verbal recovery pledge.
Headline impact leans on unrealized price damage
The verified direct loss is $1.7M; the framing that draws attention — near $11M impact and 'tools for defense cannot keep up' — depends on a single developer's mark-to-market of a token that fell 89%, roughly seven times the hard-asset loss. Counting unrealized price collapse as impact, plus a generic uncited remediation checklist and an unlinked record-hacks statistic, overstates the story modestly relative to what is independently evidenced. The underlying cross-protocol latent-bug finding is, if anything, under-emphasized.
Vendor and founder framing both favor 'undetectable and sophisticated'
The loss estimate and mechanism come from a commercial security auditor whose market grows with demand for monitoring and audits, and the interpretive framing comes from a founder of the exploited protocol, for whom 'six chained bugs behaving as written, undetectable until too late' is more favourable than a missed defect, and whose redundancy-over-integration choice is presented as validated. The article's closing prescriptions align with that vendor and founder interest, and no adversarial or independent voice questions the loss scope.
Single publisher, unreconciled magnitudes
Confidence is limited by cluster structure rather than plausibility: one publisher, no primary sources linked, three incompatible loss magnitudes, an approximate date for the THORChain precedent, and the two most consequential interpretive claims sourced to interested parties. The dated tracker attributions and the corroborated shared-latent-bug finding keep it from being lower.
invest
Maya's $1.7M six-bug exploit: the balance monitor rings after the money is gone1 distinct publisher
invest
A Solana DEX halted trading and says the loss stopped at its treasury. Nobody can check1 distinct publisher
invest
Pump.fun's $12m week puts token issuance above every lending market in crypto1 distinct publisher
invest
A 2022 oracle hack starts moving again, three days after Pando shut its books1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 23, 2026