Invest1 publisher3 min readPublished
Maya's $1.7M six-bug exploit: the balance monitor rings after the money is gone
Six bugs, none fatal alone, drained Maya Protocol and took CACAO down about 89 percent. THORChain lived through the same chained-logic pattern in May.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Maya Protocol lost about $1.7 million after a hacker exploited six bugs involving accounting, liquidity and outbound transactions.
- CACAO crashed nearly 89%, falling from $0.115 to $0.013, as the attacker moved millions of tokens and other assets.
- Blockchain security firm CertiK estimated the total direct loss at about $1.7 million, saying the hacker deceived Maya into awarding a nonexistent subsidy and then repeatedly added and removed liquidity to extract assets from shared pools.
- According to CertiK, which identified the event on August 19, the hacker misrepresented Maya's internal accounting through a fake subsidy and then altered liquidity positions to withdraw an estimated 48.87 million CACAO and 98.82 LINK.
- DefiLlama's Hacks and Exploits Database classified the August 18 occurrence as "Protocol Logic" and attributed a loss of $1.7 million.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Maya Protocol lost about $1.7 million after an attacker chained six bugs spanning accounting, liquidity and outbound transactions [1]. The direct loss is the smaller number: CACAO fell from $0.115 to $0.013, close to 89 percent, and the developer who dissected the attack puts the total impact near $11 million once the token collapse is counted [2][6].
CertiK, which set the direct loss at roughly $1.7 million, describes a two-stage sequence: the attacker tricked Maya into awarding a subsidy that did not exist, then repeatedly added and removed liquidity to pull assets out of shared pools [3]. CertiK dates its identification of the event to August 19 and puts the withdrawal at an estimated 48.87 million CACAO and 98.82 LINK [4]. DefiLlama's hacks database logs the incident a day earlier, on August 18, files it under "Protocol Logic", and attributes the same $1.7 million [5][19]. Developer Vini Barbosa, who called it a "sophisticated 6-bug exploit", counts just over $1.36 million in hard assets leaving the protocol, about $340,000 below CertiK's figure [6][18], and roughly an eighth of the $11 million he attributes to the price move [16]. The token's fall happened in under 240 blocks [6].
The classification is the story. According to the reporting, no single broken line of code was required; ordinary protocol logic behaved differently than expected, which is why the attack stayed invisible until it was too late to stop [20]. Aaluxx, a Maya founder, acknowledged the damage the same day and said the team would "work to fix and recover in full" [7].
Maya is an offshoot of THORChain, which lost $10.7 million in May [8]. THORChain's post-mortem says a new node operator exploited weaknesses in its GG20 threshold-signature system, and that the network's solvency checks only registered a problem after the theft was complete [9]. That post-mortem also says the root cause was not one dramatic flaw but three older bugs that became exploitable when combined, and states explicitly that the same latent bug existed on Maya without having been exploited [11]. Aaluxx repeated the point on THORChain's community podcast: three bugs, harmless individually, dangerous chained, and present on Maya too [10].
That is the defensive problem in plain terms. Finding the THORChain root cause meant inspecting cryptographic configuration parameters and hunting for insignificant prime numbers that should not have been there in order to identify infected vaults [12]. A balance monitor, by contrast, fires once funds have already moved, which is after the point where the attack could have been interrupted [13]. Aaluxx argues that AI now lets small teams examine a codebase from many angles at once, which helps defenders but also gives attackers more routes to bugs that conventional audits miss [14]. His answer was redundancy rather than a single system: Maya and THORChain stayed independent instead of integrating, which let Maya keep executing swaps from a verifiable healthy vault while THORChain sat inactive for weeks [15]. The wider prescription in the same account is to test how security controls interact, not only whether each one works alone [21].
Watch whether Maya publishes a bug-by-bug post-mortem of the kind THORChain produced [9][11], and what "recover in full" is funded by [7]. The disclosure gap is the live item: THORChain named the shared latent bug before it was used against Maya [11], and any protocol running the same code inherits that clock.