
PeckShield traced stolen user funds from Arbitrum to Solana and Ethereum after conversion into DAI, as the exploit hit pre-allocated deposits in Cascade’s invite-only First Wave campaign amid a broader run of DeFi attacks.
Cascade XYZ said a security exploit drained about $1.34 million in USDC from its CLS vault, affecting user funds tied to the platform’s invite-only First Wave campaign. PeckShield traced the stolen assets from Arbitrum to Solana and then back to Ethereum through Relay Protocol after the funds were swapped into DAI, a route that can complicate tracing and freezing. Cascade said it paused trading and withdrawals and engaged SEAL 911 and other third-party security teams while it investigates. The breach came during a broader cluster of DeFi incidents that also included attacks on FCOW and DefiTuna, even as DeFiLlama data showed industrywide losses of $1 billion as of July 2026, below the $2.135 billion stolen in the same period of 2025.