
The signal
Maya Protocol halted swaps on August 18 after an attacker combined six flaws in its cross-chain network. A preliminary report shared by its co-founder describes one transaction containing 23 messages. About $1.36 million allegedly left the system, while $291,000 remained in positions controlled by the attacker, bringing the direct estimate to roughly $1.7 million.
Why it matters
Maya lets users exchange native assets across blockchains without a centralised platform. The attack did not depend on one isolated weakness. It chained errors in trade accounts, outbound transaction processing and reserve calculations. The incident shows how components that appear safe separately can create a severe failure when their assumptions collide.
What changes
Swaps and network-managed transfers remain halted while developers patch the flaws. Liquidity providers therefore cannot rely on normal access to their positions. The protocol has promised to make losses whole, but that statement is not yet a funded recovery plan or an executable timetable.
The caveat
The accounting remains preliminary. CACAO’s sharp price decline reduced the value of the pools, but that market loss should not be confused with assets directly extracted. The technical report came from the affected team and still needs a full independent review. No detailed compensation mechanism has been published.
What to watch
The next verifiable milestones are released patches, an independent post-mortem, any operator vote and the actual reopening of swaps. Evidence should also show where reimbursement funds will come from, how liquidity providers are treated and whether new controls prevent the same sequence of failures.