Cascade (CLS Vault) hack — July 2026
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | July 16, 2026 |
| Target type | Decentralised exchange |
| Loss | $1,340,000Published estimates range $1,300,000 to $1,340,000Price at time of incident |
| Method | Other or undisclosedRoot cause never published. Cascade said only that a 'security exploit' affected its Cascade Liquidity Strategy (CLS) vault; as of the end of July 2026 no post-mortem or technical explanation had been released, and Spanish-language coverage noted explicitly that the company had not explained the mechanism that allowed the vault to be drained. The candidate lead describing this as price oracle manipulation is not supported by any source located. |
| Chains | Arbitrum |
| Outcome | Unresolved |
What happened
Cascade, a perpetual-trading platform that had raised a $15 million seed round from Polychain Capital and Variant in December 2025, announced on 16 July 2026 that its Cascade Liquidity Strategy (CLS) vault had been drained. The team's statement, posted to Discord, said it had "detected a security exploit affecting our CLS vault, resulting in a loss of approximately $1.3M in user funds" and that it had "immediately paused all trading and withdrawals while we investigate". PeckShield tracked 1.34 million USDC leaving an Arbitrum address, bridged to Solana and then routed to Ethereum through Relay Protocol, where it was converted to DAI to avoid centralised freezing.
The date of the exploit itself is not established. No source published a separate incident date, so this record uses the disclosure date of 16 July 2026 and marks it approximate.
The CLS vault held pre-allocated deposits from an invite-only "First Wave" campaign. Those deposits were locked until the platform's public launch, so depositors could not withdraw ahead of the attack even though several on-chain researchers had spent weeks publicly urging them to exit, citing the team's silence following the January 2026 pre-allocation event and a collapse in vault liquidity. Reporting noted the team had been effectively inactive for close to two months before the announcement.
Cascade said it engaged SEAL 911 and outside security firms to investigate. It has not published a root-cause analysis, so the mechanism that emptied the vault is not established. The company's own figure of "approximately $1.3M" and PeckShield's on-chain figure of 1.34 million USDC are consistent with each other, and this record carries both as a range.
No recovery, reimbursement or arrest has been reported and no party has been named as responsible.
Sources
- The Crypto TimesSecondary · retrieved 2026-08-01
- TronWeeklySecondary · retrieved 2026-08-01
- DiarioBitcoinSecondary · retrieved 2026-08-01
- Cryptonews (syndicated from Cryptopolitan)Aggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Cascade (CLS Vault) hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cascade-cls-vaulthttps://itokenly.com/hacks/cascade-cls-vaultPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.