Invest1 distinct publisher3 min readUpdated
Six bugs, none fatal alone, drained Maya Protocol and took CACAO down about 89 percent. THORChain lived through the same chained-logic pattern in May.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Maya Protocol lost about $1.7 million after an attacker chained six bugs spanning accounting, liquidity and outbound transactions [1]. The direct loss is the smaller number: CACAO fell from $0.115 to $0.013, close to 89 percent, and the developer who dissected the attack puts the total impact near $11 million once the token collapse is counted [2][6].
CertiK, which set the direct loss at roughly $1.7 million, describes a two-stage sequence: the attacker tricked Maya into awarding a subsidy that did not exist, then repeatedly added and removed liquidity to pull assets out of shared pools [3]. CertiK dates its identification of the event to August 19 and puts the withdrawal at an estimated 48.87 million CACAO and 98.82 LINK [4]. DefiLlama's hacks database logs the incident a day earlier, on August 18, files it under "Protocol Logic", and attributes the same $1.7 million [5][19]. Developer Vini Barbosa, who called it a "sophisticated 6-bug exploit", counts just over $1.36 million in hard assets leaving the protocol, about $340,000 below CertiK's figure [6][18], and roughly an eighth of the $11 million he attributes to the price move [16]. The token's fall happened in under 240 blocks [6].
The classification is the story. According to the reporting, no single broken line of code was required; ordinary protocol logic behaved differently than expected, which is why the attack stayed invisible until it was too late to stop [20]. Aaluxx, a Maya founder, acknowledged the damage the same day and said the team would "work to fix and recover in full" [7].
Maya is an offshoot of THORChain, which lost $10.7 million in May [8]. THORChain's post-mortem says a new node operator exploited weaknesses in its GG20 threshold-signature system, and that the network's solvency checks only registered a problem after the theft was complete [9]. That post-mortem also says the root cause was not one dramatic flaw but three older bugs that became exploitable when combined, and states explicitly that the same latent bug existed on Maya without having been exploited [11]. Aaluxx repeated the point on THORChain's community podcast: three bugs, harmless individually, dangerous chained, and present on Maya too [10].
That is the defensive problem in plain terms. Finding the THORChain root cause meant inspecting cryptographic configuration parameters and hunting for insignificant prime numbers that should not have been there in order to identify infected vaults [12]. A balance monitor, by contrast, fires once funds have already moved, which is after the point where the attack could have been interrupted [13]. Aaluxx argues that AI now lets small teams examine a codebase from many angles at once, which helps defenders but also gives attackers more routes to bugs that conventional audits miss [14]. His answer was redundancy rather than a single system: Maya and THORChain stayed independent instead of integrating, which let Maya keep executing swaps from a verifiable healthy vault while THORChain sat inactive for weeks [15]. The wider prescription in the same account is to test how security controls interact, not only whether each one works alone [21].
Watch whether Maya publishes a bug-by-bug post-mortem of the kind THORChain produced [9][11], and what "recover in full" is funded by [7]. The disclosure gap is the live item: THORChain named the shared latent bug before it was used against Maya [11], and any protocol running the same code inherits that clock.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Maya Protocol lost about $1.7 million after a hacker exploited six bugs involving accounting, liquidity and outbound transactions.
CACAO crashed nearly 89%, falling from $0.115 to $0.013, as the attacker moved millions of tokens and other assets.
Blockchain security firm CertiK estimated the total direct loss at about $1.7 million, saying the hacker deceived Maya into awarding a nonexistent subsidy and then repeatedly added and removed liquidity to extract assets from shared pools.
DefiLlama's Hacks and Exploits Database classified the August 18 occurrence as "Protocol Logic" and attributed a loss of $1.7 million.
Aaluxx later clarified on THORChain's community podcast that the hack was based on three older bugs that were not dangerous on their own but could prove problematic when combined, and said Maya also had this same latent flaw.
THORChain's post-mortem says its root cause was not one dramatic flaw but three older bugs that became exploitable when chained together, and explicitly notes that the same latent bug existed on Maya but had not previously been exploited.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two trackers agree on the loss, one publisher relays it
The core loss figure is corroborated by two named independent trackers (CertiK and DefiLlama) that converge on about $1.7 million, and the chained-bug root cause is backed by THORChain's own published post-mortem plus on-the-record founder comments. But everything reaches the reader through a single trade publication, no transaction hashes or attacker addresses are provided, the two trackers date the event a day apart, and the headline market-impact figure rests on one developer's unmethodologised estimate.
Concrete incident impact, thin operational follow-through
Real-world impact is quantified rather than hypothetical: specific withdrawn asset amounts, a roughly 89% token collapse in under 240 blocks, immediate liquidity-provider damage, and a documented architectural consequence in which Maya kept swapping while THORChain sat offline for weeks. What is absent is uptake of the remedies the story recommends — no protocol has been shown adopting the circuit breakers, invariant tests or anomaly detection prescribed, and Maya's recovery pledge has no observable execution yet.
Magnitude framing runs ahead of the tracked loss
Mildly overstated. The verified core — $1.7 million, six chained bugs, a detection blind spot mirrored at THORChain — is solid and arguably underreported. The overshoot sits in the framing layer: a near-$11 million impact figure that is 6.5x the tracked loss and 8.1x the hard assets removed is presented without methodology, an unnamed 'research published this month' and a TRM Labs half-year hack count are used to generalise the incident into a trend, and a founder's AI-threat warning is relayed as insight without measurement.
Vendor and founder voices dominate the record
The evidentiary chain runs through parties with interests in how the story lands. A blockchain security vendor supplies the loss estimate and mechanism narrative, which doubles as demonstration of its monitoring capability; the affected protocol's co-founder supplies the root-cause account, the 'recover in full' pledge and the architectural lesson that flatters his own non-integration decision; and the publisher is crypto trade press whose closing sections generalise into an industry security-spending argument. No adversarial or unaffiliated technical reviewer is quoted.
Directionally credible, numerically loose, single-sourced
Confidence is moderate-low. The existence, mechanism class and structural lesson of the exploit are credible and cross-referenced to a public hack database and a published post-mortem, so the story's direction is trustworthy. Precision is not: one publisher, two dates for one event, a $340,000 unreconciled spread, an order-of-magnitude difference between tracked and claimed impact, no on-chain identifiers, and an article body that ends mid-sentence.
invest
Pump.fun's $12m week puts token issuance above every lending market in crypto1 distinct publisher
invest
A 2022 oracle hack starts moving again, three days after Pando shut its books1 distinct publisher
invest
RWA collateral in DeFi nears $4B, and 88% of tokenized assets still do nothing1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026