MAYAChain 2026 chained accounting exploit
On August 18, 2026, an attacker used a single transaction containing 23 messages to chain multiple MAYAChain accounting and state-handling defects. The sequence triggered a false theft condition and an unfunded slash-subsidy credit in the thin ARB.LINK pool, after which the attacker gained near-total pool ownership and extracted Bitcoin and other assets. Maya halted MAYAChain trading for containment and recovery work.
Incident facts
- Incident title
- MAYAChain 2026 chained accounting exploit
- Bridge
- Maya Protocol / MAYAChain
- Incident date
- 2026-08-18
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Bitcoin, Ethereum, Arbitrum, Unknown
- Affected assets
- BTC, Unknown
- Attack category
- Unknown
- Reported loss
- Approximately $1.7 million direct extraction
- Amount confidence
- Medium
- Loss amount basis
- Operator Disclosures Corroborated By Independent Reporting
- Recovery
- Unknown
- Reimbursement
- Unknown
- Restart
- Paused
- Current outcome
- Unknown
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-09-09
- Last verified
- 2026-09-09
Amount and valuation
Contemporaneous reporting based on Maya disclosures places direct attacker extraction at roughly $1.65M–$1.76M, including about 20.83 BTC moved to the attacker’s Bitcoin address. The roughly $10.9M decline in pool value is treated separately as market/arbitrage fallout, not stolen funds.
Do not add the approximately $10.9M pool-value decline to direct stolen funds; it includes CACAO price collapse and arbitrage effects.
about 20 BTC plus roughly $300,000 of other assetsapproximately $1.7 million
Direct extraction only; excludes wider pool-value decline.
Why this remains unresolved
- The attacker-controlled Bitcoin remained unrecovered at the latest admitted recovery horizon.
- Full LP/protocol recovery and reimbursement are not established.
- An unrestricted post-incident trading restart is not established in this tranche.
Timeline events
MAYANode exploit-hardening merge request opened2026-08-18
Maya opened MAYANode merge request !835 to harden outbound matching, native transaction-ID uniqueness and theft-slash subsidy handling after the incident. The change set documents the accounting/state paths involved, but it does not by itself establish mainnet state recovery, deployment completion or trading restart.
This event intentionally tracks the first-party technical remediation record instead of creating a separate pause event supported only by secondary reporting.
Evidence records
- Maya Protocol exploit drains bitcoin and other assets as pool value drops by $11 millionCoinDesk · Tier 1 · High reliability · secondary · 2026-08-19Claim scope: Incident Case
Contemporaneous reporting citing Maya founder disclosure and on-chain reconstruction. Supports approximately $1.7M direct extraction, 20.83 BTC transfer, network halt, and separation from the wider approximately $10.9M pool-value decline.
- Web3 Security: Term Finance & MAYAChain ExploitsBlockSec · Tier 1 · High reliability · secondary · 2026-08-25Claim scope: Root Cause
Independent technical analysis supporting the chained accounting/state-validation failure and approximately $1.76M incident estimate.
- harden outbound matching, native txID uniqueness and theft-slash subsidyMaya Protocol / MAYANode · Tier 1 · High reliability · primary · 2026-08-18Claim scope: Security Patch
First-party MAYANode merge request opened on the incident date. Supports the exploit-hardening and root-cause remediation paths; it does not establish full mainnet state recovery, compensation, or unrestricted restart.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final recovered amount is not established.
- Final pool-level recovery and reimbursement treatment remain unresolved.
- MAYAChain and CACAO lack dedicated keys in the current BIR reference vocabulary.
Conflicting claims
Current treatment: BIR records the direct extraction as canonical reported loss and preserves the larger pool-value decline only as secondary impact.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.