CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

The Transfer Failed. Maya Logged the Error and Kept the Money Anyway

Six small bugs in a row credited a liquidity pool with nearly 50 million tokens that were never funded. When the funding transfer failed, the system wrote an error message and left the fake balance sitting there. The attacker only had to notice.

S
SYNTH·Hack Database
The Transfer Failed. Maya Logged the Error and Kept the Money Anyway - CMZ investigation
A failed transfer was logged as an error and never reversed, leaving 50 million unfunded tokens in a pool.

Around 17:30 UTC on August 18, 2026, somebody drained Maya Protocol's liquidity pools and the whole thing came down to an error message nobody had wired up properly.

Maya is a cross-chain decentralized exchange, a fork of THORChain, letting users swap assets across networks without an intermediary holding them. Its native token is CACAO. The exploit did not break its cryptography or steal a key. It walked through six separate flaws in sequence, each of which looks trivial in isolation.

The core of it is one design failure. A liquidity pool was credited with nearly 50 million tokens before the system attempted to actually fund them. The funding transfer failed. The error was logged. Nothing rolled back. The inflated balance sat in the pool as though the money had arrived.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

From there the attack is almost mechanical. The attacker added a small amount of genuine liquidity to the fattened pool. Because the pool's recorded value was enormous and mostly fictional, that small contribution bought near-total ownership of it. Then they withdrew against the inflated value and left.

Confirmed extraction to external chains came to roughly $1.36 million. Including assets still sitting on-chain in attacker control, the total is close to $1.7 million. Co-founder Aaluxx Myth put the Bitcoin portion at about 20 BTC worth $1.4 million, with another $300,000 in other assets. The stolen mix included Bitcoin, ARB-based tokens, and native CACAO. Roughly 20.83 BTC moved to a single Bitcoin address across about ten blocks.

CACAO collapsed from around $0.115 to roughly $0.013, an 88% fall, before recovering to about $0.03. MAYAChain was halted globally to stop further losses.

What followed was, by the standards of this section, unusually human. Aaluxx posted on Discord: "Sad news 😕 Will work to fix and recover in full. We carry on." He published a preliminary analysis the same day laying out the six chained bugs across trade account manipulation, outbound transaction handling and liquidity pool calculation, rather than waiting for a polished post-mortem. He committed to making liquidity providers whole and said the team would pursue the stolen funds through a bug bounty arrangement, noting that returning the roughly 20 BTC would restore a large part of the lost liquidity.

He also said the exploit would accelerate the launch of Aztec Chain, with proceeds from that expansion intended to flow back into Maya's pools. Whether that is a plan or a hope depends on how the launch goes.

The attacker has not responded to the bounty offer and has not been identified. A chain-state rollback has been floated as a more drastic option, though it would need validator coordination and would carry the same cost every rollback carries: legitimate transactions made after the exploit go with it.

Context matters here. Maya is a THORChain fork, and THORChain lost $10.7 million to a key leak in May 2026. Two protocols from the same lineage, both drained inside four months, for entirely different reasons.

It also arrived in the middle of an extraordinary run. DefiLlama had logged 219 hacks worth $1.26 billion across 2026 by the time Maya went down, against 146 incidents for all of 2025. Maya was the sixteenth separate incident in August alone, and one of the smallest.

At $1.7 million it barely registers next to the Coldcard entropy failure or Harmony's forged trillions. But the mechanism deserves to be remembered, because it is the least exotic failure in this entire section. No cryptography was broken. No insider was involved. No state actor was required. A transfer failed, an error was written to a log, and nobody had told the system to put the money back.

The Aftermath

MAYAChain remained halted while engineers assessed the damage and prepared patches to restore swaps. The team has committed to making liquidity providers whole and is pursuing the stolen Bitcoin through a bug bounty arrangement, which the attacker has not accepted. A chain-state rollback has been discussed but not executed, and would require validator coordination plus the usual cost to legitimate post-exploit transactions. No attacker has been identified, no law enforcement action has been announced, and nothing has been recovered.

LESSONS LEARNED

!An error that gets logged but not acted on is not handled. Maya's system recorded that the funding transfer failed and left the fake balance in place regardless.
!Six harmless-looking bugs in sequence are one serious bug. None of these flaws would have mattered alone.
!Same-day disclosure of the actual mechanism, before a polished post-mortem, is rarer than it should be. Aaluxx published the chain of six while the chain was still halted.
!Forking a protocol inherits its architecture, not its luck. THORChain and Maya were drained four months apart by entirely unrelated failures.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database