Skip to main content

Garden Finance Halts App After Blockaid Finds $450K Exploit



Garden Finance is investigating an exploit that reportedly involved its cross-chain bridge and atomic swap infrastructure after an attacker drained roughly $450,000 worth of USDT from Garden-linked hash time-locked contracts (HTLCs) across multiple networks, according to Blockaid. The incident has also triggered a temporary pause in Garden’s services while the affected systems are isolated and reviewed.



Garden’s position differs from the initial description of the breach: the company says its protocol and on-chain HTLC smart contracts were not compromised. Instead, Garden attributes the event to an intrusion into the off-chain database of an independent solver, where fraudulent transaction records were allegedly inserted—leading to incorrect swap releases.



Key takeaways



  • Blockaid reported an attacker drained about $450,000 in USDT from Garden HTLCs on Ethereum, Base, Arbitrum, and BNB Smart Chain.

  • Garden says the protocol and HTLC smart contracts were not altered or hacked; the compromise was limited to an off-chain database belonging to one independent solver.

  • Garden stated no user funds were lost or placed at risk, and that only solver-owned assets were affected.

  • Services were paused as a precaution while Garden, and multiple security firms, trace and recover the funds.



What Blockaid says happened


Earlier Sunday, Blockaid said the exploit was ongoing and involved Ethereum-based HTLCs used by Garden to coordinate atomic swaps. In its public update, Blockaid described the attacker draining approximately $450,000 in USDT from Garden’s HTLCs deployed across Ethereum, Base, Arbitrum, and BNB Smart Chain.



HTLCs function as time-bound escrow contracts that help ensure assets are released only under the correct conditions—an essential mechanism for atomic swaps spanning different chains. Blockaid also published addresses it linked to the attacker and the contracts believed to be affected.



Garden’s rebuttal: off-chain solver database breach


Garden Finance disputed the implication that its core contracts were compromised. A spokesperson told Cointelegraph that neither the Garden protocol nor its HTLC smart contracts were breached.



According to Garden, the attacker accessed the off-chain database of an independent solver and inserted falsified transaction records. In Garden’s account, those incorrect records led the solver to release funds for swaps that were not actually funded by the intended counterparty.



Garden added that the incident did not place user funds at risk and that no funds belonging to users were lost. Instead, the company said the impact was confined to solver-owned assets. Garden also indicated that it is still confirming the full extent of the event—total amount, assets, and the precise networks involved.



Why an off-chain compromise can matter


While HTLCs are executed on-chain, cross-chain swap systems often rely on off-chain infrastructure to coordinate actions, track swap state, and trigger settlement steps. Garden’s explanation centers on this split: the protocol’s on-chain components were allegedly left intact, but the solver’s off-chain data was manipulated in a way that caused settlement to occur incorrectly.



For market participants, this distinction is important. If the core smart contracts remain secure, the long-term trust impact may be smaller than in a scenario involving altered HTLC logic or compromised protocol contracts. Still, the incident highlights a persistent vulnerability class for cross-chain systems: even with audited or well-designed on-chain escrow logic, operational processes and off-chain databases can become critical attack surfaces.



Garden’s immediate response—pausing services and isolating the suspected infrastructure—reflects how quickly operational compromises can cascade into on-chain fund movements. The difference between a contract-level exploit and a solver-level data breach may affect remediation timelines, too, because recovery depends not only on stopping the bleeding but also on validating swap states and ensuring incorrect releases do not recur.



Security response and previous incident


Garden said it is working with zeroShadow, Quantstamp, and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, contingent on completing security checks, but it did not provide a specific timetable.



Garden also pointed to its SOC 2 Type II attestation as evidence of security and operational controls, framing the incident as isolated to one solver’s off-chain infrastructure within its network of independent solvers. The company emphasized that its priorities are securing the affected systems, tracing the solver’s funds, and resuming services only after relevant reviews are completed.



The reported event follows an earlier pattern. In October 2025, Garden reported a breach in which an attacker stole about $11.4 million after compromising the operating environment of one of its solvers. Garden said that earlier incident similarly did not compromise its protocol contracts or put user funds at risk.



Taken together, the two episodes suggest that Garden’s risk exposure may be closely tied to the security posture and isolation of third-party solver environments rather than flaws in its HTLC contract code. That shifts where investors and integrators should focus their monitoring: operational security, access controls, and off-chain data integrity across the solver ecosystem.



As Garden continues tracing the funds and validating affected swap records, the key question for users and builders will be whether the investigation confirms a consistent “solver off-chain” failure mode or reveals broader compromise indicators. Readers should watch for Garden’s updated totals, the specific networks and assets involved, and the results of the security checks that will determine when services fully resume.



https://www.cryptobreaking.com/garden-finance-halts-app-after/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Garden%20Finance%20Halts%20App%20After%20Blockaid%20Finds%20$450K%20Exploit%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Solana Policy Institute Calls on SEC to Safeguard DeFi Developers from Overly Strict Regulations

US Crypto Policy Innovation: Advocates Push for Clear Regulations and Developer Protections The Solana Policy Institute has urged the U.S. Securities and Exchange Commission (SEC) to differentiate between centralized crypto exchanges and non-custodial decentralized finance (DeFi) software. The nonprofit emphasizes that developers creating and publishing non-custodial code should not be classified as intermediaries, advocating for balanced regulation that fosters innovation without compromising security or legality. Key Takeaways Advocates call for regulatory clarity distinguishing between non-custodial DeFi protocols and centralized exchanges. The Institute argues that applying traditional securities laws to DeFi code risks stifling innovation and pushing activity offshore. Authorities are encouraged to adopt a custody-and-control-based framework to clarify legal liabilities. Legislation proposals aim to shield developers from legal liabilities associated with blockchain code and activ...