← Radar

Incident case file

Sign in to watch

Cascade — CLS Vault Drain via Compromised Signer / Operator Key (pidzhachello Polymarket Attribution Lead)

Incident date July 16, 2026

4 views

PausedArbitrum → Solana → Ethereum (via Relay Protocolconverted to DAI to evade USDC blacklisting)Signer / operator key compromiseCluster: CAS-KEY-2026-07

Estimated loss

$1.3M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Initial recipient EOA (Arbitrum): 0x285996ba0B464F841D3a63e88c7cc319d70D9b55. Relay/laundering EOA: 0x5fa1Fa848D25E2b65664869C2819DB5E26b72cef. Gas funder (attribution lead): 0xf5c8DC07f24F53FEeEB7368119398333dF000af6 — labeled by Arkham as 'pidzhachello' on Polymarket (active profile confirmed via Polymarket public API). Direct 2-second timing between stolen USDC arrival on relay wallet and gas funding from this account is an on-chain fact that makes this the strongest attribution lead of the

Funds moved to: Primary exploit tx 0xcd801d24...2578314 (Arbitrum, July 16 22:34:35 UTC): 1,343,921.875 USDC exits through Cascade's Arbitrum Orbit outbox + USDC gateway, executed as an EIP-4337 UserOperation. Recipient: 0x285996ba...70D9b55. 22:37:10 UTC: 100K USDC arrives on relay wallet 0x5fa1Fa8...72cef. 22:37:12 UTC (+2 seconds): gas funding of 0.003 ETH arrives from 'pidzhachello' account 0xf5c8DC07f24F53FEeEB7368119398333dF000af6 (gas tx 0x2d772feb...d2eed2d). Full 1.34M USDC pushed to relay wallet, then
Attacker cluster: recipient 0x285996ba0B464F841D3a63e88c7cc319d70D9b55, relay wallet 0x5fa1Fa848D25E2b65664869C2819DB5E26b72cef, gas funder 0xf5c8DC07f24F53FEeEB7368119398333dF000af6 (Arkham-labeled 'pidzhachello' on Polymarket, live profile). Solana intermediate GkfyojBJqYiASWnepUpTzytep3GsCxg88oRgUaRhejcX. Final DAI holding EOAs on Ethereum (4). Real DAI contract 0x6B175474E89094C44Da98b954EedeAC495271d0F (beware fake DAI spam). Rehearsal test wallets used the same EIP-7702 account that handle

Timeline: December 9, 2025: Cascade seed round $15M closed (Coinbase Ventures, Polychain, Variant, Archetype). Late April 2026: on-chain sleuth traces of a suspected earlier exploit surface (unconfirmed by Cascade). July 6, 2026: @0xGwoni publicly warns users to withdraw citing >95% liquidity decline, project inactivity, and prior exploit traces. July 16, 2026 (all UTC): 21:07 UTC first rehearsal — 500 USDC bridged via Cascade OrbitBridge to test the extraction path. 21:43 UTC second rehearsal — 50 USDC test bridge. Same EIP-7702 account handles both rehearsals and the final execution — professional-grade preparation pattern consistent with a compromised signer / operator key testing extraction capability before the full drain. 22:34:35 UTC: primary exploit tx 0xcd801d24...2578314 — 1,343,921.875 USDC exits through Cascade's Arbitrum Orbit outbox + USDC gateway, executed as an EIP-4337 UserOperation via Entry Point 0.7.0. Recipient: 0x285996ba...70D9b55. 22:37:10 UTC: 100K USDC arrives on relay wallet 0x5fa1Fa8...72cef. 22:37:12 UTC (+2 seconds): 0.003 ETH gas arrives from Arkham-labeled 'pidzhachello' Polymarket wallet — the strongest attribution lead of the week. Laundering: 4 USDC bridges Arbitrum→Solana via Relay Protocol (100K + 400K + 500K + 340K). 1,339,604 USDC lands on Solana address. Re-bridge Solana→Ethereum + conversion to DAI (evasion of USDC blacklisting) across 4 Ethereum EOAs. Cascade Discord announcement by 'Max' at 22:56 UTC (~05:56 local depending on timezone display): 'Earlier this afternoon, Cascade detected a security exploit affecting our CLS vault, resulting in a loss of approximately $1.3M in user funds. We immediately paused all trading and withdrawals while we investigate. We've engaged SEAL 911 and other third-party security teams and are actively working to secure the platform.' Trading + withdrawals paused. Coverage: PeckShield diagram published July 16 (Arbitrum→Solana→Ethereum flow). Vector hypothesis (independent investigator): 'compromised strategy signer, operator key or withdrawal authorization path. so there is no contract exploit or anything like this' — not a smart contract vulnerability, but signer/key compromise + EIP-4337/EIP-7702 abuse. As of July 17, no public technical post-mortem from Cascade explaining the vulnerable component, signer topology, or reimbursement plan. This is one of the most significant attribution leads of the week — the direct funding link + 2-second timing between stolen USDC arrival and gas from the Polymarket-labeled wallet 'pidzhachello' is an on-chain fact. Attribution requires platform-side confirmation from Polymarket, but the on-chain evidence is definitive.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)