Maya Protocol lost an estimated $1.7 million in an exploit on Wednesday, and the numbers make the situation look even worse for the protocol as its Immunefi bug bounty, which covers the THORChain fork, puts the maximum payout for a critical vulnerability at just $35,000. 

So, whoever discovered this chain of six flaws had a pretty clear financial incentive to exploit them instead as the potential haul was about 48 times larger than the maximum reward for reporting the bugs.

According to Aaluxx’s preliminary post-mortem, the attack came down to a single 23-message transaction. It managed to fool the system’s theft-detection mechanism, artificially pump a thin liquidity pool, and ultimately pull 48.87 million CACAO from the Asgard vault. Around 20.83 BTC, worth roughly $1.34 million at the time, was transferred off the chain completely. The attacker still has about $288,000 worth of CACAO sitting on Maya, though, and the team says those funds could potentially be frozen.

What makes this more uncomfortable is that there had already been a warning.

Three months earlier, independent researchers on X had pointed out unusual slippage in Maya’s swap routing. In one $10,000 test trade, only $6,188 came back. That warning surfaced just hours before THORChain itself was drained of $10.8 million on May 15, a figure later revised down to $7.4 million. At the time, a THORChain developer dismissed the report as “fake news.”

What stands out even more is the audit trail. Maya’s ETH Router contract, which is at the center of this incident, has reportedly carried a “Draft 3” label from auditor Halborn since earlier this year, with the review never reaching a final version. Aaluxx has now acknowledged that the flaws exploited in the attack made it through both the Halborn review and a separate AI-assisted audit.

There’s another uncomfortable piece of history here. Maya inherited its Bifrost-style cross-chain architecture from THORChain, the same underlying design that suffered two separate incidents in July 2021, losing a combined $15 million.

Then there’s CACAO. The token fell from around $0.115 to roughly $0.013, putting a huge dent in Maya’s long-running “we’ve never lost user funds” security pitch. That claim had been one of the protocol’s biggest selling points for more than three years.

And this isn’t happening in isolation. PeckShield’s 2026 figures put losses from bridge-style exploits across cross-chain protocols at more than $328 million so far this year. Now the question is what Maya does next. The quality of its fix, and whether the team rethinks that $35,000 bounty ceiling, could determine whether this ends up as a one-off incident or the beginning of a much bigger problem.


Delogg Media