Cascade Protocol Hit by $1.3M Exploit, Enlists SEAL 911
Security & Exploits ·
The protocol lost $1.3M in a same-day incident and is now working with security responders and law enforcement to trace the attackers.
Cascade confirmed it was exploited for $1.3M, with the funds drained in a same-day incident that prompted an immediate response rather than a delayed disclosure. The protocol has since said it is collaborating with SEAL 911, the crypto-incident response effort, alongside law enforcement to track down those responsible, according to a post on x.com.
The involvement of SEAL 911 places Cascade among a growing list of protocols turning to dedicated incident-response networks in the immediate aftermath of an attack, rather than relying solely on internal teams. Pairing that effort with law enforcement outreach signals an attempt to pursue both technical tracing of the stolen funds and a formal legal path toward identifying the attackers, though no arrests or fund recovery have been reported.
Exploits of this kind typically involve an attacker abusing a vulnerability in a protocol's code, infrastructure, or design to gain unauthorized control over assets, a pattern broadly outlined in explainer material on the mechanics of crypto exploits at leviathan.news. That resource notes the distinction between a latent vulnerability and the exploit itself, the weaponized method used to convert a weakness into an actual theft, which is relevant to understanding how a same-day $1.3M loss can occur before a team has time to patch or pause a system.
Cascade's case sits within a broader pattern of exploit activity across the sector in recent periods, including a Hyperbridge gateway exploit that let an attacker mint 1B DOT on Ethereum for a $237K profit, and a suspected Thorchain exploit that drained more than $7.4M across Bitcoin, Ethereum, BSC, and Base. Separately, tooling aimed at catching vulnerabilities before they are exploited has also expanded, with a DeFi vulnerability scanner opened for free and an AI-based auditor moving to public testing after reportedly hitting 88.6% accuracy on real 2026 exploits.
What remains unresolved in Cascade's case is whether the collaboration with SEAL 911 and law enforcement will lead to identification of the attackers or any recovery of the $1.3M taken. It is also not yet known how the exploit was carried out, whether the vulnerability originated in Cascade's own code or in connected infrastructure, or whether the protocol plans further security measures following the incident. Coverage so far draws on two distinct sources, and further detail on the attack vector and any law enforcement findings is expected as the investigation continues.