Peckshield: Maya Protocol Loses $1.7M, 20 BTC Traced to Wallet
Blockchain security firm Peckshield says Maya Protocol was exploited for roughly $1.7 million, with the bulk of the stolen funds, 20 BTC worth $1.34 million, sitting untouched in a single wallet.

Key Takeaways
- Peckshield flagged the Maya Protocol exploit on August 18, tracing 20 BTC to one address.
- The stolen funds total roughly $1.7 million, with most of it still unmoved onchain.
- Maya Protocol has acknowledged the incident but the team is yet to outline a holistic remediation plan.
What Peckshield Found
Peckshield said Maya Protocol, a decentralized multi-chain liquidity network, was exploited for approximately $1.7 million, with the largest single piece of the haul, 20 BTC, traced to the address ‘bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646.’
Bitcoin.com News independently verified the wallet and confirmed it held 20.82730682 BTC as of publication, all of it deposited in 10 separate transactions on August 18 at 17:32 UTC, indicating that the funds were drained and consolidated rather than accrued through organic trading activity.

Maya Protocol operates as a fork of Thorchain, using Cosmos-SDK, Tendermint consensus, and threshold signature schemes to let users swap assets across chains, such as bitcoin, ether, and USDC, without wrapping tokens or relying on a centralized custodian. That cross-chain design, moving native assets between blockchains that were never built to talk to each other, is exactly the kind of plumbing that has made bridges and liquidity routers a favorite target for hackers over the course of this year.
At the time of writing, Maya Protocol co-founder and strategic lead Aaluxx Myth issued a public statement confirming the exploit’s root cause, adding that they’ve halted global operations until further notice.

A Familiar Pattern for Cross-Chain Protocols
Maya Protocol’s exploit adds to a year that has been especially punishing for cross-chain infrastructure. Peckshield’s own tally found that bridge exploits alone drained $328.6 million across eight major incidents in May, and the firm separately flagged a $5.25 million exploit that saw funds bridged from Hedera to Ethereum in a suspected attack earlier this year.
Across all categories, monitoring firms have put cumulative 2026 hack losses north of $1.65 billion, once again shining a spotlight on the fact that even mature, audited protocols remain exposed when cross-chain logic is involved.
The mechanics of these attacks vary, some exploit smart contract logic, others compromise validator keys or bridge relayers, but the outcome is consistent, i.e. liquidity that is supposed to move seamlessly between chains instead flows straight into an attacker’s wallet.
What to Watch Next
Looking ahead, a few factors stand to determine how things play out from here. First, whether the exact attack vector comes to light, followed by whether the 20 BTC sitting in the flagged wallet moves, and if so, whether it heads to a mixer, a bridge, or an exchange that could freeze it.
Lastly, it will be interesting to see whether the team’s offer of a bug bounty is accepted in exchange for returning funds, a negotiation tactic that has become increasingly common in 2026 after several protocols recovered assets by offering white-hat deals rather than pursuing legal action alone. Interesting few days ahead, to say the least!
