Key Takeaways
Peckshield flagged the Maya Protocol exploit on August 18, tracing 20 BTC to 1 deal with.The stolen funds complete roughly $1.7 million, with most of it nonetheless unmoved onchain.Maya Protocol has acknowledged the incident however the workforce is but to stipulate a holistic remediation plan.
What Peckshield Discovered
Peckshield mentioned Maya Protocol, a decentralized multi-chain liquidity community, was exploited for roughly $1.7 million, with the biggest single piece of the haul, 20 BTC, traced to the deal with ‘bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646.’
Bitcoin.com Information independently verified the pockets and confirmed it held 20.82730682 BTC as of publication, all of it deposited in 10 separate transactions on August 18 at 17:32 UTC, indicating that the funds had been drained and consolidated moderately than accrued by natural buying and selling exercise.
Maya Protocol operates as a fork of Thorchain, utilizing Cosmos-SDK, Tendermint consensus, and threshold signature schemes to let customers swap belongings throughout chains, equivalent to bitcoin, ether, and USDC, with out wrapping tokens or counting on a centralized custodian. That cross-chain design, transferring native belongings between blockchains that had been by no means constructed to speak to one another, is strictly the type of plumbing that has made bridges and liquidity routers a favourite goal for hackers over the course of this 12 months.
On the time of writing, Maya Protocol co-founder and strategic lead Aaluxx Fantasy issued a public assertion confirming the exploit’s root trigger, including that they’ve halted world operations till additional discover.

A Acquainted Sample for Cross-Chain Protocols
Maya Protocol’s exploit provides to a 12 months that has been particularly punishing for cross-chain infrastructure. Peckshield’s personal tally discovered that bridge exploits alone drained $328.6 million throughout eight main incidents in Could, and the agency individually flagged a $5.25 million exploit that noticed funds bridged from Hedera to Ethereum in a suspected assault earlier this 12 months.
Throughout all classes, monitoring corporations have put cumulative 2026 hack losses north of $1.65 billion, as soon as once more shining a highlight on the truth that even mature, audited protocols stay uncovered when cross-chain logic is concerned.
The mechanics of those assaults range, some exploit sensible contract logic, others compromise validator keys or bridge relayers, however the consequence is constant, i.e. liquidity that’s supposed to maneuver seamlessly between chains as a substitute flows straight into an attacker’s pockets.
What to Watch Subsequent
Wanting forward, a number of elements stand to find out how issues play out from right here. First, whether or not the precise assault vector involves mild, adopted by whether or not the 20 BTC sitting within the flagged pockets strikes, and in that case, whether or not it heads to a mixer, a bridge, or an trade that would freeze it.
Lastly, will probably be attention-grabbing to see whether or not the workforce’s provide of a bug bounty is accepted in trade for returning funds, a negotiation tactic that has turn out to be more and more widespread in 2026 after a number of protocols recovered belongings by providing white-hat offers moderately than pursuing authorized motion alone. Fascinating few days forward, to say the least!









