Garden Finance took its app offline after an attacker drained $450,000 in USDT by compromising an independent solver's off-chain database. The company clarified its own smart contracts were not breached and no user funds were lost, as the exploit only affected solver-owned assets. This is the second major solver-related breach for the protocol, following an $11.4 million theft in October 2025. Garden is working with security firms to recover the funds.
Solver database breach
- ▪An attacker compromised the off-chain database of an independent solver for Garden Finance, not the protocol itself
- ▪The incident affected only solver-owned assets, and no user funds were lost or placed at risk
- ▪Garden Finance temporarily took its cross-chain bridge and atomic swap protocol app offline following a security incident
- ▪Garden Finance stated that its protocol and hash time-locked contracts (HTLC) smart contracts were not compromised
HTLC exploit mechanics
- ▪The funds were drained from contracts on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks
- ▪Security firm Blockaid reported that an attacker drained about $450,000 in USDT from Garden Finance's hash time-locked contracts (HTLC)
- ▪Garden Finance uses HTLCs, which are time-bound escrow contracts, to facilitate atomic swaps between Bitcoin and assets on other networks
- ▪The attacker inserted fraudulent transaction records into the solver's database, causing it to release funds for swaps not funded by a counterparty
Fund recovery efforts
- ▪Garden Finance is working with security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds
- ▪The protocol expects to restore services after completing security checks, but has not provided a specific timeline
Previous Garden Finance incident
- ▪In a separate incident in October 2025, an attacker stole approximately $11.4 million after compromising the operating environment of a Garden Finance solver
- ▪Garden Finance cited its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls
- ▪Garden Finance also stated that the October 2025 incident did not affect its protocol contracts or put user funds at risk
Story comments
Loading comments…