Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
0
1

The cross-chain protocol Maya Protocol halted its MAYAChain blockchain on August 18, 2026, after an attacker had, on the team's account, drained some $1.65 million. Swaps have stood still since then, and the protocol token CACAO lost almost 89 percent of its value. Anyone who swapped through MAYAChain or provided liquidity there now faces a very practical question: where exactly are their coins, and what can still be done with them?
The answer up front. A network halt freezes the state of a blockchain: no new blocks are produced, so no deposits or withdrawals are processed either. Coins sitting in MAYAChain's liquidity pools stay there until the developers restart the chain. Coins you hold yourself in your own wallet on Bitcoin or another chain are untouched by the halt. That distinction determines whether you can act right now or have to wait.
What happened in the Maya Protocol exploit on August 18, 2026
The attack hit the MAYAChain mainnet on August 18, 2026, in the late afternoon European time. Shortly afterwards the team halted the chain globally. The founder, who goes by the name AaluxxMyth, wrote a single sentence about it on the platform X, quoted by the trade publication Decrypt in its report of August 19, 2026: „No way to sugar coat this.“ In the same message he gave a first estimate of 20 bitcoin, worth around $1.4 million at the time, plus further assets worth roughly $300,000.
The later figures from the team's own review sit slightly below and slightly above that, depending on what is counted. According to the post-mortem, which Decrypt and the trade publication crypto.news report consistently, the attacker made off with assets worth about $1.65 million. Of that, roughly $1.36 million moved out to external blockchains, while about $291,000 initially remained on MAYAChain under the attacker's control. The bitcoin address that received 20.83 BTC was published by the project itself.
A post-mortem is the report a development team publishes after an incident, describing the sequence, the cause and the consequences. It is the view of the project concerned and not an independent audit. Read the figures exactly that way: as a statement by the team, corroborated so far by the observations of analytics firms and trade media, not by an authority or an auditor.
Cross-chain swap explained: why there is no account behind MAYAChain
A cross-chain swap is an exchange between two different blockchains in which you trade, say, real bitcoin for the native coin of another chain, without the detour through a centralised exchange. MAYAChain is built for that. The protocol describes itself in its own documentation as non-custodial, permissionless infrastructure for native swaps. Non-custodial means there is no customer account, no provider holding your coins for you, and no support line that could release a withdrawal.
The price of that is the flip side of the same property. On a regulated trading venue there is an operator with an authorisation, a complaints route and duties towards client money. With a protocol such as MAYAChain there is code, validators and a community. Anyone using both side by side should know which part of their holdings sits under which regime. For the part held at a supervised provider, a look at our comparison of regulated crypto exchanges helps, listing each provider's licence and registered seat.
The second building block is liquidity pools. A liquidity pool is a pot of two or more assets from which those swapping draw, and which other users, the liquidity providers, have filled beforehand. Those liquidity providers carry the risk of the pot: if it is emptied, their share is gone. In the Maya Protocol exploit it was precisely this layer that was hit.
Six faults in one transaction: how the attack on the liquidity pools unfolded
According to the team's post-mortem, quoted verbatim by Decrypt, the attacker needed a single transaction carrying 23 deposit messages strung together. That combination triggered a false theft detection in the software. The protective function, meant to compensate a pool after a genuine theft, calculated the compensation incorrectly and without any upper limit. By this route a pool with little liquidity grew, on paper, by 49.45 million CACAO.
The attacker then supplied liquidity to that artificially inflated pool, briefly held 99.93 percent of it and withdrew 48.87 million CACAO again. Those tokens were swapped into bitcoin and further assets. The team counts six separate faults that had to mesh for this to work; none of them would have sufficed alone. According to the founder, as reported by Decrypt, those faults had gone undetected for three to four years, even though the code had been externally audited.
One detail that limited the damage is worth noting: because the attacker had to sell the captured CACAO immediately, he pushed down the price of his own haul. What looked larger on paper shrank in the selling. The value of MAYAChain's liquidity pools fell in the process by roughly $10.9 million on the team's calculation, several times what reached the attacker.

CACAO price crash of 89 percent: what the drop reveals about pool depth
The CACAO price fell by 88.7 percent on crypto.news's account, from about $0.115 to roughly $0.013. Decrypt puts it at just under 89 percent. Both figures describe the same event and differ only in the moment of measurement.
For you as a reader, the percentage matters less than what it says about market breadth. A token that a single sale worth a few hundred thousand dollars moves that far has little depth. This property is the rule rather than the exception among small protocol tokens, and it works in both directions: the price collapses quickly under selling pressure, and it recovers just as quickly on modest buying. Anyone holding such tokens should price in that sensitivity before an incident makes it visible.
Network halt at MAYAChain: what a global stop means for your balance
A global halt is an intended emergency mechanism on Cosmos-based chains such as MAYAChain. The validators stop producing blocks so that an attack in progress cannot continue. For you this has three practical consequences, and they are unpleasant to differing degrees.
First, a swap that had not yet completed remains in limbo. The deposited side is with the protocol, the paid-out side is not yet with you. Second, as a liquidity provider you cannot reach your position, neither to withdraw nor to add. Third, CACAO you hold on an external trading venue is technically unaffected by the halt, yet in practice often restricted anyway, because venues suspend deposits and withdrawals for halted chains.
What is technically possible after a halt, and where the limits lie, we set out at greater length in our article on a blockchain rollback after an exploit. In short: the state before the attack can be restored technically, but socially it is the hardest decision a network can take.
Am I affected? How to check swaps and liquidity positions step by step
The check takes a few minutes and answers the only question that counts: is any of your money stuck in the halted system?
Five checks for the next few days
- Look in your wallet to see whether you initiated a swap through MAYAChain, or an interface built on it, on August 18, 2026. What counts is the transaction on the source chain, that is, the entry in the explorer of the chain you sent from.
- Check whether the other side of the swap has reached you. If it is missing, the operation is open and you cannot currently speed it up.
- Check whether you hold liquidity in one of the protocol's pools. That position can neither be withdrawn nor altered until the restart.
- Check whether you hold CACAO at a trading venue, and read its status notice on deposits and withdrawals.
- Note the date, time, amount and transaction ID for each point. You will need that list later, whether the question turns out to be compensation or your tax return.
Non-custodial and custodial: the one-sentence definition
Non-custodial means that you alone hold the private key to your coins; custodial means that a provider keeps it for you and shows you an account in return. Whoever holds the key is independent of any provider failure, but carries full responsibility for backup and safekeeping. Which devices are suitable is shown in our hardware wallet comparison.
After the hack comes the fraud: why you should not click rescue links now
Every larger incident draws a second wave behind it. In the replies beneath the official posts, accounts appear within hours offering help, compensation or a supposed recovery. Anyone who signs an approval there or enters a seed phrase loses the remainder too, the part the incident never touched.
The rule against it is unspectacular and effective: sign no transaction you did not initiate yourself, commission no recovery services, enter no seed phrase, not even into a supposed checking tool. Official notices come through the project's known channels, and they never ask for a key.
Liquidity providers at MAYAChain: what the developers' pledge is worth
The team has announced that it will close the gaps, restore liquidity in full and then release swaps again. On the reports available, no timetable for this has been set. Such a pledge is a statement of intent by a development team, not a claim you can enforce against anyone. With a decentralised protocol there is neither deposit insurance nor a provider liable for the loss.
That warrants no panic, but a sober expectation. Earlier cases show both outcomes: full reimbursement from project funds, and equally years of waiting for partial amounts. Until the chain restarts, your position is an open claim against a project rather than an available balance.

Recovery through a bug bounty: what may become of the 20.83 bitcoin
A bug bounty is a reward offered for reporting a security flaw or returning captured funds. Maya Protocol has offered the attacker exactly that, according to Decrypt, and hopes for the haul to be returned against such a premium. Should nothing come back, the team has said it will replace the roughly 20 bitcoin from its own funds and by other routes, and feed them into the affected pool.
Whether that succeeds is open. Negotiations of this kind run in practice through messages in the blockchain itself and take weeks. If you are affected, it is worth checking the published address in an explorer from time to time: if the balance moves to a mixing service, the likelihood of a return falls markedly.
Exploit series 2026: how the case sits alongside KelpDAO, Ostium and AFX Trade
Measured against other incidents this year, the damage is small. Decrypt sets three cases alongside it in its report: in April, some $292 million flowed out of a KelpDAO cross-chain bridge; in July the perpetuals venue Ostium lost about $18 million through a compromised oracle key; and a few weeks later AFX Trade was hit for roughly $24 million. We covered the last of these in AFX Trade hack: perp DEX on Arbitrum loses 24 million USDC.
The difference lies in the cause. At KelpDAO and Ostium, keys and access were the way in; here it was the logic of the protocol itself. For you as a user that means an external code audit is a mark of quality, not a guarantee. It describes a state at a point in time and does not cover every combination of edge cases.
Tax and documentation: why to record the price history now
A price loss on its own is nothing for tax purposes. In Germany a loss from private disposal transactions arises only when you actually sell or swap. That is precisely why documentation matters now: anyone keeping clean records of holdings, dates and acquisition costs can later evidence what they owned and when. A portfolio tracker takes that work off your hands, and an overview is in our comparison of crypto tax tools and portfolio trackers. Whether and how a loss is to be treated for tax belongs in the hands of a tax adviser; this article does not replace one.
In practice that means: export the transaction data of the wallets involved while the data is fresh, and save screenshots of the status notices. Should the protocol pay compensation later, you will need both in any case.
Maya Protocol exploit: what to take away
- Check first whether any of your money is stuck in the halted system. Open swaps and pool shares are blocked until the restart; everything in your own wallet is not. For the part you hold at supervised providers, the comparison of regulated crypto exchanges helps you place it.
- Secure the rest rather than banking on a quick rescue. Anyone handing over keys or approvals after an incident loses twice over. Which devices keep your keys offline is shown in the hardware wallet comparison.
- Document now, not later. Holdings, dates and acquisition costs belong in a record that still holds up a year from now. Tools for that are in the comparison of crypto tax tools and portfolio trackers.
The case shows what a cross-chain protocol can do and where its limit lies. Swapping native coins without a central counterparty works as long as the code holds. Where it does not, there is no body that makes good the damage of its own accord. Anyone who knows that spreads their holdings differently.
(As of August 20, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
0
1
Securely connect the portfolio you’re using to start.
