Key Points
- Garden Finance halted its application following an off-chain database breach affecting one of its solvers
- Hackers stole approximately $450,000 in USDT from Ethereum, Base, Arbitrum, and BNB Chain
- The protocol’s HTLC smart contracts remained secure and no user deposits were compromised
- Losses were limited to the solver’s own assets, not customer funds
- Three security firms—zeroShadow, Quantstamp, and Blockaid—are assisting with fund recovery efforts
On July 27, Garden Finance, a protocol specializing in cross-chain bridging and atomic swaps, suspended its application following a security incident targeting one of its independent solver operators.
According to Garden Finance, the perpetrator gained unauthorized access to an off-chain database maintained by a single solver within its network. By injecting fraudulent transaction entries into the system, the hacker manipulated the solver into releasing funds for transactions that were never legitimately initiated or funded.
Blockchain security company Blockaid identified that the exploit resulted in approximately $450,000 in USDT being siphoned across multiple networks, including Ethereum, Base, Arbitrum, and BNB Chain.
Garden Finance emphasized that its underlying protocol infrastructure and hash time-locked contracts (HTLCs) remained completely unaffected. HTLCs serve as the foundation for Garden’s atomic swap mechanism, providing time-sensitive escrow functionality for cross-chain transactions involving Bitcoin and other blockchains.
The platform stressed that customer assets were never endangered or accessed during the incident. All monetary losses stemmed exclusively from the compromised solver’s proprietary funds.
As a preventative measure, Garden Finance temporarily disabled its services while conducting a comprehensive security audit of the impacted infrastructure. The company has not disclosed a specific date for service restoration.
Investigation and Recovery Efforts Underway
Garden Finance has enlisted three prominent blockchain security organizations to assist with tracking and potentially recovering the stolen cryptocurrency. The investigation team includes zeroShadow, Quantstamp, and Blockaid.
According to the company, operations will remain suspended until all necessary security protocols and assessments have been successfully completed. Garden Finance referenced its recently obtained SOC 2 Type II attestation as demonstration of its commitment to security infrastructure.
Pattern Emerges: Second Solver Compromise Within a Year
This marks the second solver-related security breach Garden Finance has experienced in less than twelve months. In October 2025, a comparable attack resulted in the theft of approximately $11.4 million when an attacker successfully compromised a solver’s operational environment.
Garden Finance confirmed that the previous 2025 breach similarly left protocol smart contracts and user balances unaffected.
The pattern of these two separate incidents highlights a persistent security weakness in the off-chain solver infrastructure layer, while the core protocol architecture has remained resilient.
Garden Finance continues to verify precise loss figures, identify all affected digital assets, and confirm which blockchain networks were impacted by the attack.
Blockaid was the first organization to publicly report the ongoing exploit, releasing blockchain addresses associated with the suspected attacker.
Garden Finance stated that its current priorities include strengthening compromised systems, tracking the movement of stolen assets, and guaranteeing a secure resumption of platform operations.
The organization has not disclosed whether any portion of the $450,000 has been successfully retrieved at this time.





