Overview
- Maya Protocol detected the breach on Wednesday, August 19, 2026, when a single transaction made of 23 messages chained six separate software bugs to fake a pool balance and withdraw 48.87 million CACAO tokens.
- Preliminary accounting shows about $1.36 million of the stolen value was moved to external blockchains and roughly $291,000 remained in attacker‑controlled CACAO and trade‑account positions, for an approximate direct loss of $1.7 million.
- The team activated its Mimir emergency global halt to freeze deposits and withdrawals while developers and node operators prepare fixes and coordinate forensic analysis with security firms.
- Market effects were severe: CACAO’s price collapsed about 88.7–89% during the incident and an independent estimate placed the wider pool‑value decline at roughly $10.9 million, worsening losses for liquidity providers.
- Maya has offered a white‑hat style bug bounty to recover funds and pledged to replace about 20 BTC if unrecovered, but it has given no timetable for when swaps or normal operations will resume.