Timeline
- 7.5
Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen
Maya Protocol halted MAYAChain after an attacker exploited six bugs to drain roughly $1.7 million in Bitcoin and other assets. The network was paused to contain the damage, and CACAO plunged nearly 89% as pool value fell by about $10.9 million. This is a significant security incident for cross-chain DeFi, demonstrating that even audited protocols can contain hidden vulnerabilities. The CACAO token collapse and liquidity pool losses directly affect users and liquidity providers, while broader market sentiment toward cross-chain bridges may be damaged. The post-mortem said the attacker used a single 23-message MsgDeposit transaction to trigger a false theft detection, inflating a low-liquidity pool's CACAO balance by 49.45 million before withdrawing 48.87 million CACAO. Maya said the bugs had gone undetected for three to four years despite audits by Halborn and Fable 5, and the suspected attacker address received 20.83 BTC.
- 8.0
Maya Protocol Exploit Drains Bitcoin, Pool Value Drops $11M
Maya Protocol was exploited on August 19, 2026, draining bitcoin and other assets and causing its pool value to drop by $11 million. The cross-chain liquidity network halted operations as the team investigated the attack. This exploit directly affects user funds and represents a significant security failure in a cross-chain DeFi protocol, reinforcing concerns about the safety of trustless liquidity systems. It may prompt users and auditors to re-examine similar protocols built on Cosmos SDK. Post-mortem reports say the attacker exploited six bugs to inflate a liquidity pool by 49.45 million CACAO before gaining 99.93% control of it. Several outlets estimate the initial theft at about $1.7 million, while CoinDesk cites an $11 million drop in total pool value.
- 8.0
Maya Protocol Exploit Drains $1.7M from Shared Liquidity
Maya Protocol suffered an exploit that drained approximately $1.7 million from its shared liquidity pools. Founder Aaluxx said he would 'work to fix and recover in full,' while routing service LeoDex reported that Maya had activated a global halt. This is a confirmed exploit that directly hit user funds in a cross-chain DeFi protocol, adding to a broader pattern of security incidents across liquidity protocols. It affects Maya users, the CACAO token ecosystem, and trust in multichain non-custodial swaps. Maya Protocol is a Cosmos SDK-based decentralized liquidity protocol that enables native, non-custodial swaps across blockchains. The exploit triggered a 'global halt' — an emergency circuit breaker that pauses trading and protocol operations — and LeoDex, a cross-chain swap aggregator that routes through MAYAChain, relayed the halt to users.
- 7.0
Bedrock Protocol Loses $2M in Crypto Heist
According to a report from Yellow.com, Bedrock Protocol was hit by a $2 million crypto heist. The incident directly affected user funds, though specific exploit details have not been disclosed. This security incident underscores the ongoing risks in DeFi and the liquid restaking sector, where user funds can be exposed to exploits. It may erode user confidence in Bedrock and similar restaking protocols. Bedrock is a multi-asset liquid restaking protocol offering liquid restaking tokens for Bitcoin, Ethereum, and IoTeX, tracked as a parent protocol with products such as uniBTC, uniETH, and uniIOTX. The reported $2 million loss is relatively modest compared to major crypto exploits.