MAYAChain Exploit Drains $1.7M via Pool Inflation
MAYAChain suffered a roughly $1.65 million to $1.7 million exploit on 18 August 2026 after an attacker chained six flaws in its trade-account, outbound-processing and slash-subsidy systems. The attack did not involve stolen private keys or a flash loan.
A single batched deposit containing 23 messages allowed a later DONATE action to overwrite shared transaction-voter data. This reset outbound tracking and made the protocol falsely classify withdrawals from a thin ARB.LINK pool as theft. MAYAChain then credited about 49.45 million CACAO to the pool, despite it holding only around 0.11 LINK.
The inflated balance was recorded before reserve funding was confirmed. The transfer failed because the Asgard reserve held only about 168,000 CACAO, but the failed operation did not roll back the state. The attacker added limited liquidity, gained 99.93% of the pool, and withdrew about 48.87 million forged CACAO. The funds were later swapped into BTC, ETH, RUNE and stablecoins.
MAYAChain halted swaps and the wider protocol to contain the damage. About $1.36 million was reportedly moved to external blockchains, while roughly $291,000 remained on-chain. Around 20.82 BTC, worth approximately $1.34 million at the time of reporting, remained in the attacker’s wallet, along with about $300,000 in other assets. The team offered a bug bounty, committed $200,000 toward recovery and published the suspected attacker’s BTC address.
The MAYAChain exploit exposed risks from batched transactions, unbounded subsidies, thin liquidity pools and state changes made before transfer confirmation. The team said the flaws had remained undetected for three to four years despite audits by Halborn and Fable 5, and it plans to adopt more adversarial code reviews. Traders should monitor CACAO liquidity, bridge activity and any further recovery or protocol-restart announcements.
Bearish
The direct impact is bearish for CACAO and the MAYAChain ecosystem. The exploit created tens of millions of unbacked CACAO, allowing the attacker to sell into BTC, ETH, RUNE and stablecoins. This caused severe dilution, a sharp CACAO price decline and a major reduction in liquidity. The global protocol halt also removes trading utility and increases uncertainty in the short term.
CACAO may face continued selling pressure if recovered assets are liquidated or if users withdraw liquidity after the restart. Traders are also likely to demand a higher risk premium because the flaws reportedly survived multiple audits and involved core accounting and settlement logic. A successful fix, transparent compensation plan and verified protocol relaunch could support a later recovery, but these developments are unlikely to offset the immediate loss of confidence. The expected price impact on CACAO is therefore bearish.