Home/ Breaking News/ 19 August 2026
AI Digest
8 Sources Updated 6h ago H9 Edition 1 min read

Maya Protocol Hacked: Six Flaws, $11 Million Gone

A cross-chain trading network has been drained of $11 million in bitcoin and other digital assets after an attacker exploited a chain of six separate security flaws in Maya Protocol's liquidity infrastructure, according to CoinDesk.

AI-generated digest · 8 verified sources · Updated twice daily Add as preferred source
What You Missed Today
Durable
Durable
Every Malta business needs a website. Durable builds one in under a minute.
Learn more →
Gusto
Gusto
Gusto handles US payroll, benefits, and HR compliance automatically.
Learn more →
Bolt Business
Bolt Business
Corporate rides in Malta — 25% off for FreeMalta readers. Promo code: BB25OFF20
Learn more →
Tresorit
Tresorit
Client files, contracts, sensitive documents — Tresorit keeps them encrypted in transit and at rest.
Learn more →
Marblism
Marblism
Describe your SaaS. Marblism builds the full stack in minutes.
Learn more →

A cross-chain trading network has been drained of $11 million in bitcoin and other digital assets after an attacker exploited a chain of six separate security flaws in Maya Protocol's liquidity infrastructure, according to CoinDesk.

The mechanism was precise and damaging: the protocol's code credited a liquidity pool with nearly 50 million tokens that were never actually deposited, creating a phantom balance that the attacker then used to withdraw real, funded assets from the other side of the pool. Six distinct vulnerabilities had to align for the exploit to work — and they did.

Maya Protocol operates as a cross-chain decentralised exchange, routing trades across multiple blockchains including Bitcoin. Its core promise is trustless, permissionless trading without a centralised custodian. That promise is now suspended pending a post-mortem and patch cycle that the team has not yet publicly scheduled.

The exploit arrives at an awkward moment for decentralised finance broadly — Bitcoin is holding near $64,000 and institutional attention has returned to the sector after months of outflows. Hacks of this architecture, where the flaw is not one vulnerability but a cascade of six, are particularly difficult to catch in audit cycles that typically stress-test individual components rather than their interaction.

No user funds have been publicly guaranteed as recoverable. The pool value, according to CoinDesk, dropped $11 million in the window of the attack.

Six flaws. Each one survivable alone. Together, they emptied the room.

Editor's Note
Six flaws. Not one — six. Anyone who greenlit that code for production deserves to have their LinkedIn profile audited as aggressively as that liquidity pool was.
Sophia Borg
Sophia Borg
News & Politics Editor
Sophia Borg grew up in one of Malta's oldest families and spent her twenties proving she didn't need any of it — volunteering in Lagos, interning in Brussels, loving the wrong man in the south of France. She came back to Malta with a pen and a score to settle. Not with people. With the gap between what this island could be and what it keeps choosing instead.
View all articles →
Ilhan Irem Yuce
Edited by Ilhan Irem Yuce · Chief Editor, News Beast