Crypto World
Garden Finance Halts App After Blockaid Finds $450K Exploit
Garden Finance is investigating an exploit that reportedly involved its cross-chain bridge and atomic swap infrastructure after an attacker drained roughly $450,000 worth of USDT from Garden-linked hash time-locked contracts (HTLCs) across multiple networks, according to Blockaid. The incident has also triggered a temporary pause in Garden’s services while the affected systems are isolated and reviewed.
Garden’s position differs from the initial description of the breach: the company says its protocol and on-chain HTLC smart contracts were not compromised. Instead, Garden attributes the event to an intrusion into the off-chain database of an independent solver, where fraudulent transaction records were allegedly inserted—leading to incorrect swap releases.
Key takeaways
- Blockaid reported an attacker drained about $450,000 in USDT from Garden HTLCs on Ethereum, Base, Arbitrum, and BNB Smart Chain.
- Garden says the protocol and HTLC smart contracts were not altered or hacked; the compromise was limited to an off-chain database belonging to one independent solver.
- Garden stated no user funds were lost or placed at risk, and that only solver-owned assets were affected.
- Services were paused as a precaution while Garden, and multiple security firms, trace and recover the funds.
What Blockaid says happened
Earlier Sunday, Blockaid said the exploit was ongoing and involved Ethereum-based HTLCs used by Garden to coordinate atomic swaps. In its public update, Blockaid described the attacker draining approximately $450,000 in USDT from Garden’s HTLCs deployed across Ethereum, Base, Arbitrum, and BNB Smart Chain.
HTLCs function as time-bound escrow contracts that help ensure assets are released only under the correct conditions—an essential mechanism for atomic swaps spanning different chains. Blockaid also published addresses it linked to the attacker and the contracts believed to be affected.
Garden’s rebuttal: off-chain solver database breach
Garden Finance disputed the implication that its core contracts were compromised. A spokesperson told Cointelegraph that neither the Garden protocol nor its HTLC smart contracts were breached.
According to Garden, the attacker accessed the off-chain database of an independent solver and inserted falsified transaction records. In Garden’s account, those incorrect records led the solver to release funds for swaps that were not actually funded by the intended counterparty.
Garden added that the incident did not place user funds at risk and that no funds belonging to users were lost. Instead, the company said the impact was confined to solver-owned assets. Garden also indicated that it is still confirming the full extent of the event—total amount, assets, and the precise networks involved.
Why an off-chain compromise can matter
While HTLCs are executed on-chain, cross-chain swap systems often rely on off-chain infrastructure to coordinate actions, track swap state, and trigger settlement steps. Garden’s explanation centers on this split: the protocol’s on-chain components were allegedly left intact, but the solver’s off-chain data was manipulated in a way that caused settlement to occur incorrectly.
For market participants, this distinction is important. If the core smart contracts remain secure, the long-term trust impact may be smaller than in a scenario involving altered HTLC logic or compromised protocol contracts. Still, the incident highlights a persistent vulnerability class for cross-chain systems: even with audited or well-designed on-chain escrow logic, operational processes and off-chain databases can become critical attack surfaces.
Garden’s immediate response—pausing services and isolating the suspected infrastructure—reflects how quickly operational compromises can cascade into on-chain fund movements. The difference between a contract-level exploit and a solver-level data breach may affect remediation timelines, too, because recovery depends not only on stopping the bleeding but also on validating swap states and ensuring incorrect releases do not recur.
Security response and previous incident
Garden said it is working with zeroShadow, Quantstamp, and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, contingent on completing security checks, but it did not provide a specific timetable.
Garden also pointed to its SOC 2 Type II attestation as evidence of security and operational controls, framing the incident as isolated to one solver’s off-chain infrastructure within its network of independent solvers. The company emphasized that its priorities are securing the affected systems, tracing the solver’s funds, and resuming services only after relevant reviews are completed.
The reported event follows an earlier pattern. In October 2025, Garden reported a breach in which an attacker stole about $11.4 million after compromising the operating environment of one of its solvers. Garden said that earlier incident similarly did not compromise its protocol contracts or put user funds at risk.
Taken together, the two episodes suggest that Garden’s risk exposure may be closely tied to the security posture and isolation of third-party solver environments rather than flaws in its HTLC contract code. That shifts where investors and integrators should focus their monitoring: operational security, access controls, and off-chain data integrity across the solver ecosystem.
As Garden continues tracing the funds and validating affected swap records, the key question for users and builders will be whether the investigation confirms a consistent “solver off-chain” failure mode or reveals broader compromise indicators. Readers should watch for Garden’s updated totals, the specific networks and assets involved, and the results of the security checks that will determine when services fully resume.
You must be logged in to post a comment Login