Blockchain security firm Peckshield says Maya Protocol was exploited for roughly $1.7 million, with the bulk of the stolen funds, 20 BTC worth $1.34 million, sitting untouched in a single wallet.
Key Takeaways
Peckshield flagged the Maya Protocol exploit on August 18, tracing 20 BTC to one address.The stolen funds total roughly $1.7 million, with most of it still unmoved onchain.Maya Protocol has acknowledged the incident but the team is yet to outline a holistic remediation plan.Maya Protocol operates as a fork of Thorchain, using Cosmos-SDK, Tendermint consensus, and threshold signature schemes to let users swap assets across chains, such as bitcoin, ether, and USDC, without wrapping tokens or relying on a centralized custodian. That cross-chain design, moving native assets between blockchains that were never built to talk to each other, is exactly the kind of plumbing that has made bridges and liquidity routers a favorite target for hackers over the course of this year.
At the time of writing, Maya Protocol co-founder and strategic lead Aaluxx Myth issued a public statement confirming the exploit’s root cause, adding that they’ve halted global operations until further notice.
A Familiar Pattern for Cross-Chain ProtocolsAcross all categories, monitoring firms have put cumulative 2026 hack losses north of $1.65 billion, once again shining a spotlight on the fact that even mature, audited protocols remain exposed when cross-chain logic is involved.
The mechanics of these attacks vary, some exploit smart contract logic, others compromise validator keys or bridge relayers, but the outcome is consistent, i.e. liquidity that is supposed to move seamlessly between chains instead flows straight into an attacker’s wallet.
What to Watch NextLooking ahead, a few factors stand to determine how things play out from here. First, whether the exact attack vector comes to light, followed by whether the 20 BTC sitting in the flagged wallet moves, and if so, whether it heads to a mixer, a bridge, or an exchange that could freeze it.
Lastly, it will be interesting to see whether the team’s offer of a bug bounty is accepted in exchange for returning funds, a negotiation tactic that has become increasingly common in 2026 after several protocols recovered assets by offering white-hat deals rather than pursuing legal action alone. Interesting few days ahead, to say the least!


















