T
iTokenly

Cascade (CLS Vault) hack — July 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedJuly 16, 2026
Target typeDecentralised exchange
Loss$1,340,000Published estimates range $1,300,000 to $1,340,000Price at time of incident
MethodOther or undisclosedRoot cause never published. Cascade said only that a 'security exploit' affected its Cascade Liquidity Strategy (CLS) vault; as of the end of July 2026 no post-mortem or technical explanation had been released, and Spanish-language coverage noted explicitly that the company had not explained the mechanism that allowed the vault to be drained. The candidate lead describing this as price oracle manipulation is not supported by any source located.
ChainsArbitrum
OutcomeUnresolved

What happened

Cascade, a perpetual-trading platform that had raised a $15 million seed round from Polychain Capital and Variant in December 2025, announced on 16 July 2026 that its Cascade Liquidity Strategy (CLS) vault had been drained. The team's statement, posted to Discord, said it had "detected a security exploit affecting our CLS vault, resulting in a loss of approximately $1.3M in user funds" and that it had "immediately paused all trading and withdrawals while we investigate". PeckShield tracked 1.34 million USDC leaving an Arbitrum address, bridged to Solana and then routed to Ethereum through Relay Protocol, where it was converted to DAI to avoid centralised freezing.

The date of the exploit itself is not established. No source published a separate incident date, so this record uses the disclosure date of 16 July 2026 and marks it approximate.

The CLS vault held pre-allocated deposits from an invite-only "First Wave" campaign. Those deposits were locked until the platform's public launch, so depositors could not withdraw ahead of the attack even though several on-chain researchers had spent weeks publicly urging them to exit, citing the team's silence following the January 2026 pre-allocation event and a collapse in vault liquidity. Reporting noted the team had been effectively inactive for close to two months before the announcement.

Cascade said it engaged SEAL 911 and outside security firms to investigate. It has not published a root-cause analysis, so the mechanism that emptied the vault is not established. The company's own figure of "approximately $1.3M" and PeckShield's on-chain figure of 1.34 million USDC are consistent with each other, and this record carries both as a range.

No recovery, reimbursement or arrest has been reported and no party has been named as responsible.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-08-01
  2. TronWeeklySecondary · retrieved 2026-08-01
  3. DiarioBitcoinSecondary · retrieved 2026-08-01
  4. Cryptonews (syndicated from Cryptopolitan)Aggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Cascade (CLS Vault) hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cascade-cls-vault
https://itokenly.com/hacks/cascade-cls-vault

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.