Garden Finance loses $450,000 in solver database breach
Garden Finance took its app offline after an attacker drained $450,000 in USDT by compromising an independent solver's off-chain database. The company clarified its own smart contracts were not breached and no user funds were lost, as the exploit only affected solver-owned assets. This is the second major solver-related breach for the protocol, following an $11.4 million theft in October 2025. Garden is working with security firms to recover the funds.
Solver database breach
▪An attacker compromised the off-chain database of an independent solver for Garden Finance, not the protocol itself.
▪The incident affected only solver-owned assets, and no user funds were lost or placed at risk.
▪Garden Finance temporarily took its cross-chain bridge and atomic swap protocol app offline following a security incident.
▪Garden Finance stated that its protocol and hash time-locked contracts (HTLC) smart contracts were not compromised.
HTLC exploit mechanics
▪The funds were drained from contracts on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks.
▪Security firm Blockaid reported that an attacker drained about $450,000 in USDT from Garden Finance's hash time-locked contracts (HTLC).
▪Garden Finance uses HTLCs, which are time-bound escrow contracts, to facilitate atomic swaps between Bitcoin and assets on other networks.
▪The attacker inserted fraudulent transaction records into the solver's database, causing it to release funds for swaps not funded by a counterparty.
Fund recovery efforts
▪Garden Finance is working with security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.
▪The protocol expects to restore services after completing security checks, but has not provided a specific timeline.
Previous Garden Finance incident
▪In a separate incident in October 2025, an attacker stole approximately $11.4 million after compromising the operating environment of a Garden Finance solver.
▪Garden Finance cited its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls.
▪Garden Finance also stated that the October 2025 incident did not affect its protocol contracts or put user funds at risk.
Story comments
Loading comments…