Research · curated 24 Aug 2026
AI vs AI: How Cascade exploited an AI agent in production
First reported escape.tech
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Cascade's guardrail bypass shows that AI-driven attackers can autonomously talk agents out of enforcing prompt-injection defenses, leaking system prompts and tool metadata that hand attackers a roadmap to the agent's callable tools and sessions.
Escape's AI pentesting engine, Cascade, bypassed a production AI agent's prompt-injection guardrail on its second attempt by reframing the same request as an innocuous research/documentation query, causing the agent to disclose its full system prompt, tool list, tool-calling rules, output formatting, and session identifiers. The bypass relied on social-engineering-style pretexting rather than a technical exploit, with Cascade autonomously rewording its payload after reading the initial refusal.