News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highMaya / MAYAChaindefi

Maya Protocol: ~$1.7M via chained pool-accounting bugs; network halted

18 Aug 2026 ~17:30 UTC: MAYAChain (Maya Protocol, a THOR-forked cross-chain DEX) halted after an attacker used chained Trade Account / outbound / pool-math bugs to inflate a thin pool (ARB.LINK cited) with a false subsidy, then extract about 48.87M CACAO and swap out. Attacker take is about $1.7M — majority ~20.8 BTC (~$1.34M class) still sitting in a PeckShield-cited Bitcoin address, plus other assets / on-chain CACAO. Team (Aaluxx) paused global ops. Pool value dropped ~$10.9M in the event, but most of that is CACAO crashing (~89% at the low) plus arbitrage — do not treat $11M as the amount stolen. SlowMist Hacked lists it 18 Aug. Not PulseChain. Not a THORChain 2026 vault replay.

369 take: A “theft protection” or subsidy path that can credit a pool when the reserve cannot actually pay is an unbacked mint in disguise. Separate what the attacker extracted from the later price crash. Pulse lesson: any AMM, teleport, or outbound-missing path that writes a new pool balance must fail closed if backing is not there — inherited THOR-style trade-account code still needs its own solvency check.