Maya Protocol shut down its cross-chain network on Wednesday after an attacker drained roughly $1.7 million from the cross-chain platform using a chain of six software bugs. Pseudonymous co-founder Aalux shared on X that the attacker walked away with about 20 Bitcoin, worth close to $1.4 million, plus another $300,000 in additional assets. The team activated a global halt within hours to stop the bleeding and has since started building a fix so swaps can resume.
How the Attacker Chained Six Bugs to Drain the Asgard Module
According to a preliminary technical analysis shared by Aalux, the attacker did not rely on one flaw. They chained together six separate bugs touching Maya’s trade accounts, its outbound transaction system, and how it calculates liquidity pool values. All of it happened inside a single transaction packed with 23 messages.
The attacker first tripped Maya’s theft-detection system in a way that let the exploit slip through undetected. From there, they targeted a pool with thin liquidity and artificially inflated its value. That move let them pull 48.87 million CACAO tokens out of Maya’s Asgard module, the part of the protocol that holds assets used to settle cross-chain swaps.
Maya Protocol exists to let users trade native assets across different blockchains without going through a centralized exchange, which makes those vault and accounting systems the backbone of the entire network.
Independent blockchain security researcher Vini Barbosa reviewed the findings and noted the price damage on the token itself. CACAO fell 88.7%, dropping from roughly $0.115 to $0.013 during the attack. Barbosa’s analysis also pointed to a wider $10.9 million drop in pool value, though it noted that figure blends in arbitrage activity and CACAO’s own price collapse rather than reflecting funds the attacker actually took.
What This Means for Maya Protocol Users
If you hold funds on Maya or have an open position through the protocol, swaps are currently paused while the team works through the fix. The preliminary accounting puts about $1.36 million as already moved to external blockchains, meaning it is effectively gone for now, while roughly $291,000 remains tied up in the attacker’s CACAO holdings and trade-account positions on MAYAChain.
Anyone following altcoin projects built around cross-chain liquidity should watch how Maya’s Asgard vault design gets patched, since liquidity-pool accounting bugs are not unique to Maya. In a separate but similar scenario in the past, the Balancer exploit drained that unrelated DeFi protocol through its own rounding-logic flaw and eventually forced it to restructure.
You can check our altcoin news hub for ongoing coverage of how DeFi protocols handle security incidents like this one.
The Fix Maya Protocol Still Needs to Ship
Aalux said the global halt contained the damage and gave developers room to investigate the affected components. No timeline has been given yet for when swaps will resume, and the protocol has not said whether the six chained bugs have all been patched or whether some fixes are still in progress.
What this means for you: If a cross-chain swap or DeFi protocol you use gets exploited, look for an official statement from the team before assuming your funds are affected, since incidents like this one often hit specific pools or modules rather than the entire platform.
This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.

