← Cascade Protocol1 decision on this page
Audit log
Every state-changing event for Cascade Protocol: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-30 17:03:49ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
5i3yBQnXF8e1…7u8SYBR2sha256 → base58
verifying row…canonical bytes (17475 B) ▸
{"actor":"system:backfill","investigation_id":"559460d8-b58f-4bc7-9687-2c9b92ecff5c","kind":"publish","page_slug":"cascade-protocol","published_at":"2026-07-30T17:03:49.630Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Cascade Protocol","sections":[{"content":"Cascade Protocol (operating at cascade.xyz) markets itself as a 24/7 perpetual trading neo-brokerage offering unified margin accounts across crypto assets, major U.S. equities, and tokenized pre-IPO shares in companies such as OpenAI, SpaceX, and Stripe. In December 2025, the company closed a $15 million seed round led by Polychain Capital and Variant, with additional participation from Coinbase Ventures and Archetype. At launch, the platform offered invite-only access through a campaign called First Wave, which solicited USDC deposits on Arbitrum in exchange for reward points. Deposited funds were locked until the platform's public mainnet launch. The CoinDesk announcement of the raise made no mention of completed security audits or formal smart contract reviews.","heading":"Background and Fundraising","severity":"medium","sources":[{"credibility":1,"name":"Cascade Unveils 24/7 Neo-Brokerage Offering Perpetuals on Cryptos, U.S. Stocks — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/09/cascade-unveils-247-neo-brokerage-offering-perpetuals-on-cryptos-us-stocks"},{"credibility":1,"name":"Polychain and Variant-backed neo-brokerage Cascade wants to open 24/7 perps trading for any asset class — The Block","type":"news_article","url":"https://www.theblock.co/post/381986/polychain-variant-neo-brokerage-cascade-wants-24-7-perps-trading-any-asset-class"},{"credibility":2,"name":"Cascade Raises $15M To Bring 24/7 Perps Trading to Everything — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/cascade-raises-15m-to-bring-24-7-perps-trading-to-everything-even-pre-ipo-stocks/"}]},{"content":"On July 16, 2026, Cascade Protocol's Cascade Liquidity Strategy (CLS) vault was exploited, resulting in the theft of approximately 1.34 million USDC. The CLS vault held pre-allocated First Wave deposits that were contractually locked until the platform's public launch, meaning affected depositors had no mechanism to withdraw funds prior to the attack. The exact technical vulnerability has not been publicly disclosed by the team or any independent researcher at the time of this writing. Cascade announced the incident via Discord. PeckShield tracked the attacker's laundering path: the exploiter first consolidated funds on Arbitrum (moving from wallet 0x2B59...9b55 to 0x5fa1...72cef), then bridged the full 1.34 million USDC to the Solana address GkfyojBJqYiASWnepUpTzytep3GsCxg8BoRgUaRhejcX via Relay Protocol. The funds were then converted to DAI and routed back to Ethereum, landing in two tranches at wallet 0x858...eC206: approximately 801,212 DAI and 536,000 DAI. The exploit occurred the day after Ostium, another DeFi protocol, lost $18 million in a separate attack, making it the second major vault hack within 48 hours.","heading":"The CLS Vault Exploit (July 16, 2026)","severity":"critical","sources":[{"credibility":2,"name":"Polychain-Backed Cascade Hacked for $1.34M in Locked User Funds — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"credibility":2,"name":"Cascade Loses $1.3 Million In Hack As Trading Halts Across Platform — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/cascade-loses-1-3-million-in-hack-as-trading/"},{"credibility":2,"name":"The Cascade XYZ protocol suffered an attack, with 1.34 million USDC stolen and transferred across chains — Bitget News","type":"news_article","url":"https://www.bitget.com/asia/news/detail/12560605507640"},{"credibility":3,"name":"Cascade CLS Vault Suspected Security Vulnerability Leads to $1.3 Million Loss — ABAB News","type":"news_article","url":"https://www.ababnews.com/news/facf18e2-603d-4b01-921f-c7813024777b"}]},{"content":"Multiple on-chain analysts issued public warnings about Cascade in the weeks leading up to the exploit. Analyst @mztacat posted warnings on July 6, 2026 — ten days before the exploit — advising depositors to withdraw funds. The analyst noted the protocol had been inactive for over a month with no observable admin activity. Analyst @0xGwoni similarly recommended withdrawing funds approximately ten days before the attack, noting vault liquidity had declined by more than 95% from its peak. Analyst Morsy (@morsyxbt) had previously described Cascade as a 'scam project' and reposted withdrawal warnings in the days before the incident. The team is reported to have gone largely silent for approximately two months between its final pre-allocation event in January 2026 and the hack disclosure in mid-July 2026, with almost no substantive public communication during that period. Because First Wave deposits were locked until public launch, users who received these warnings had no contractual ability to act on them.","heading":"Prior Warnings and Team Inactivity","severity":"high","sources":[{"credibility":2,"name":"Users were warned before Polychain-backed Cascade suffers $1.3M exploit — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33158435/"},{"credibility":2,"name":"Polychain-Backed Cascade Hacked for $1.34M in Locked User Funds — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"}]},{"content":"Blockchain security firm PeckShield provided on-chain attribution for the exploit. The attacker's flow was: (1) aggregation of 1.34 million USDC on Arbitrum across wallets 0x2B59...9b55 and 0x5fa1...72cef; (2) cross-chain bridge to Solana at address GkfyojBJqYiASWnepUpTzytep3GsCxg8BoRgUaRhejcX; (3) conversion to DAI and return bridge to Ethereum via Relay Protocol; (4) receipt of approximately 1.337 million DAI across two tranches at Ethereum address 0x858...eC206. The use of multiple chains and the conversion from USDC to DAI were consistent with deliberate steps to complicate USDC freeze actions by Circle, which has the technical ability to blacklist addresses holding USDC on supported chains. No on-chain freezes or recoveries have been publicly reported as of the time of this writing.","heading":"Funds Laundering and On-Chain Tracing","severity":"high","sources":[{"credibility":3,"name":"Security Alert: Cascade CLS vault hack — Crypto Patel on X (citing PeckShield)","type":"social_media","url":"https://x.com/CryptoPatel/status/2077672085011255534"},{"credibility":2,"name":"Polychain-Backed Cascade Hacked for $1.34M in Locked User Funds — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"credibility":3,"name":"Cascade CLS Vault Suspected Security Vulnerability Leads to $1.3 Million Loss — ABAB News","type":"news_article","url":"https://www.ababnews.com/news/facf18e2-603d-4b01-921f-c7813024777b"}]},{"content":"Following the exploit, Cascade announced via Discord that all platform trading and withdrawals had been suspended pending investigation. The team engaged SEAL 911 — the Security Alliance's 24/7 incident-response group — along with unnamed third-party security firms to investigate the breach and determine next steps. As of the date of reporting, Cascade had not published a public post-mortem, had not disclosed the technical root cause of the vulnerability, and had not announced any reimbursement or compensation plan for affected depositors. The team's prolonged prior silence (approximately two months) and the absence of a post-exploit disclosure plan are noted as concerns by multiple outlets covering the incident.","heading":"Team Response and Recovery Status","severity":"high","sources":[{"credibility":2,"name":"Cascade Loses $1.3 Million In Hack As Trading Halts Across Platform — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/cascade-loses-1-3-million-in-hack-as-trading/"},{"credibility":2,"name":"Users were warned before Polychain-backed Cascade suffers $1.3M exploit — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33158435/"},{"credibility":2,"name":"Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"}]},{"content":"The CLS vault's design presents a structural user-protection risk that is separate from the exploit's technical mechanism. Depositors in Cascade's First Wave campaign locked their USDC on Arbitrum with no withdrawal capability until a public launch date that had not been firmly committed. When multiple analysts publicly flagged declining vault liquidity and team inactivity starting in early July 2026, the fund-lock design meant depositors could not respond to these signals. Commentary from crypto security researchers suggested the contracts may have been deployed to mainnet without rigorous formal verification or economic stress modeling. No completed third-party audit report had been publicly linked by Cascade's team at the time of the exploit.","heading":"Design Risk: Locked Deposits and User Protections","severity":"high","sources":[{"credibility":2,"name":"Polychain-Backed Cascade Hacked for $1.34M in Locked User Funds — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"credibility":3,"name":"Cascade Platform Suffers $1.3 Million Hack — Intellectia AI","type":"news_article","url":"https://intellectia.ai/news/crypto/cascade-platform-suffers-13-million-hack"}]},{"content":"The Cascade exploit occurred within a concentrated period of DeFi attacks. In the same week (approximately July 14-19, 2026), Ostium lost approximately $18 million and Across Protocol also suffered a separate attack, bringing total crypto losses for that seven-day period to over $20 million across the three incidents. DeFi hack aggregators including DefiLlama track the Cascade incident as part of a broader 2026 trend in which over $1 billion in total assets had been lost to DeFi exploits year-to-date. The Cascade incident received attention partly because it followed a high-profile seed round from well-regarded institutional investors and because the locked-deposit mechanism left users unable to self-protect.","heading":"Broader Context: DeFi Exploit Wave (July 2026)","severity":"medium","sources":[{"credibility":2,"name":"Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026: $1 Billion+ Lost and Counting — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"},{"credibility":2,"name":"DeFi Hacks & Exploits Database — DefiLlama","type":"research","url":"https://defillama.com/hacks"}]}],"sources_used":[{"credibility":2,"name":"Polychain-Backed Cascade Hacked for $1.34M in Locked User Funds — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"credibility":2,"name":"Users were warned before Polychain-backed Cascade suffers $1.3M exploit — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/33158435/"},{"credibility":2,"name":"Cascade Loses $1.3 Million In Hack As Trading Halts Across Platform — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/cascade-loses-1-3-million-in-hack-as-trading/"},{"credibility":2,"name":"Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"},{"credibility":1,"name":"Cascade Unveils 24/7 Neo-Brokerage Offering Perpetuals on Cryptos, U.S. Stocks — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/09/cascade-unveils-247-neo-brokerage-offering-perpetuals-on-cryptos-us-stocks"},{"credibility":1,"name":"Polychain and Variant-backed neo-brokerage Cascade wants 24/7 perps trading for any asset class — The Block","type":"news_article","url":"https://www.theblock.co/post/381986/polychain-variant-neo-brokerage-cascade-wants-24-7-perps-trading-any-asset-class"},{"credibility":3,"name":"Cascade Platform Suffers $1.3 Million Hack — Intellectia AI","type":"news_article","url":"https://intellectia.ai/news/crypto/cascade-platform-suffers-13-million-hack"},{"credibility":2,"name":"The Cascade XYZ protocol suffered an attack — Bitget News","type":"news_article","url":"https://www.bitget.com/asia/news/detail/12560605507640"},{"credibility":3,"name":"Cascade CLS Vault Suspected Security Vulnerability Leads to $1.3 Million Loss — ABAB News","type":"news_article","url":"https://www.ababnews.com/news/facf18e2-603d-4b01-921f-c7813024777b"},{"credibility":3,"name":"Security Alert: Cascade CLS vault hack — Crypto Patel on X (citing PeckShield)","type":"social_media","url":"https://x.com/CryptoPatel/status/2077672085011255534"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026: $1 Billion+ Lost and Counting — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"},{"credibility":2,"name":"DeFi Hacks & Exploits Database — DefiLlama","type":"research","url":"https://defillama.com/hacks"},{"credibility":2,"name":"Cascade Raises $15M To Bring 24/7 Perps Trading to Everything — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/cascade-raises-15m-to-bring-24-7-perps-trading-to-everything-even-pre-ipo-stocks/"}],"summary":"Cascade Protocol is a Polychain Capital and Variant-backed perpetual trading platform (self-described as a neo-brokerage) that suffered a $1.34 million USDC exploit of its Cascade Liquidity Strategy (CLS) vault on July 16, 2026. The affected funds came from locked First Wave depositor accounts that users were unable to withdraw prior to the attack, compounding losses. Multiple on-chain analysts had issued public warnings about the protocol's inactivity and declining vault liquidity in the weeks preceding the exploit, but no timely remediation occurred.","timeline":[{"date":"2025-12-09","event":"Cascade raises $15 million seed round led by Polychain Capital and Variant, with Coinbase Ventures and Archetype participating. Platform announced as a 24/7 perpetual trading neo-brokerage.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/12/09/cascade-unveils-247-neo-brokerage-offering-perpetuals-on-cryptos-us-stocks"},{"date":"2026-01-21","event":"Cascade holds its final pre-allocation event (First Wave), locking user USDC deposits on Arbitrum pending platform public launch. Team then goes largely silent.","source":"CryptoNews","source_url":"https://cryptonews.net/news/security/33158435/"},{"date":"2026-07-06","event":"On-chain analyst @mztacat issues public warning urging Cascade depositors to withdraw funds, noting over one month of protocol inactivity and no admin activity. Users are unable to withdraw due to deposit lock.","source":"CryptoNews","source_url":"https://cryptonews.net/news/security/33158435/"},{"date":"2026-07-06","event":"Analyst @0xGwoni recommends pulling funds from Cascade, noting vault liquidity had declined by more than 95%.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"date":"2026-07-16","event":"Cascade Protocol's CLS vault is exploited. Approximately 1.34 million USDC is drained from locked First Wave depositor funds on Arbitrum. The attacker routes funds through Solana and back to Ethereum via Relay Protocol, converting to DAI. Cascade announces the incident on Discord and suspends all trading and withdrawals.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"date":"2026-07-16","event":"PeckShield publishes on-chain attribution, tracing attacker wallets on Arbitrum (0x2B59...9b55, 0x5fa1...72cef), Solana (GkfyojBJqYiASWnepUpTzytep3GsCxg8BoRgUaRhejcX), and Ethereum (0x858...eC206).","source":"Crypto Times / PeckShield","source_url":"https://www.cryptotimes.io/2026/07/16/polychain-backed-cascade-hacked-for-1-34m-in-locked-user-funds/"},{"date":"2026-07-16","event":"Cascade confirms engagement of SEAL 911 and third-party security firms to investigate the exploit. No post-mortem or reimbursement plan published.","source":"Tron Weekly","source_url":"https://www.tronweekly.com/cascade-loses-1-3-million-in-hack-as-trading/"},{"date":"2026-07-19","event":"Reporting aggregates the Cascade exploit alongside Ostium ($18M) and Across Protocol hacks, citing over $20 million in total crypto losses in a single week.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 224e8aa8-1304-4ccd-985e-829570ea230e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.