BIP Austin digital publishing platform

collapse
Home / Daily News Analysis / Garden Finance disables app as Blockaid reports $450,000 exploit

Garden Finance disables app as Blockaid reports $450,000 exploit

Jul 28, 2026  Twila Rosenbaum 7 views
Garden Finance disables app as Blockaid reports $450,000 exploit

Garden Finance, a cross-chain bridge and atomic swap protocol, temporarily disabled its application after security firm Blockaid reported an exploit involving approximately $450,000 in USDT. The incident, which came to light on July 27, 2026, initially raised concerns about the integrity of Garden’s hash time-locked contracts (HTLCs). However, the company later clarified that neither the protocol nor its HTLC smart contracts were compromised. Instead, an independent solver’s off-chain database was breached, allowing the attacker to insert fraudulent transaction records that caused the solver to release funds for swaps that had not been fully funded by the counterparty.

Blockaid, the blockchain security platform, first flagged the exploit after detecting unusual activity across Ethereum, Base, Arbitrum, and BNB Smart Chain. The attacker allegedly drained about $450,000 in Tether (USDT) from HTLCs used by Garden to facilitate atomic swaps between Bitcoin and assets on other networks. Atomic swaps rely on HTLCs to ensure that either both parties fulfill the exchange or the transaction is reversed within a time window. In this case, the attacker manipulated off-chain records to trick the solver into releasing funds without receiving the corresponding assets.

Garden Finance responded swiftly by isolating the affected infrastructure and pausing services as a precaution. The company emphasized that no user funds were lost or placed at risk. “Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” a spokesperson told Cointelegraph. The incident was confined to the off-chain database of one solver in Garden’s network of independent solvers. The company is still assessing the total amount, assets, and networks involved, but initial estimates align with Blockaid’s figure.

The exploit highlights the growing complexity of security in decentralized finance (DeFi) protocols that rely on off-chain components. While on-chain smart contracts are often rigorously audited, off-chain infrastructure such as databases, APIs, and solver software can introduce vulnerabilities. Garden’s architecture uses independent solvers to facilitate cross-chain transactions. These solvers maintain off-chain databases to track swap requests and counterparty commitments. A breach of such a database can allow attackers to fabricate transaction records, leading to unauthorized fund releases.

Garden Finance has engaged multiple security firms to trace and recover the funds. The company confirmed it is working with zeroShadow, Quantstamp, and Blockaid to investigate the incident and track the stolen assets. Garden expects to restore services shortly after completing security checks, but it has not provided a specific timeline. The company also pointed to its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. SOC 2 Type II is a rigorous auditing standard that evaluates how well an organization safeguards customer data and manages security processes over a period of time. This certification underscores Garden’s commitment to maintaining robust security, even as it faces operational challenges.

This is not the first time Garden has experienced a security incident related to its solver infrastructure. In October 2025, an attacker stole approximately $11.4 million by compromising the operating environment of one of Garden’s solvers. At that time, Garden also stated that its protocol contracts were not affected and that no user funds were at risk. The recurrence of solver-related breaches raises questions about the security model of relying on independent third parties for critical transaction processing. While Garden’s core smart contracts have not been directly exploited, the off-chain attack surface remains a concern for users and investors.

The broader DeFi ecosystem has seen a trend of attackers targeting off-chain components. In 2025, several bridge protocols suffered losses due to compromised validator nodes, private key leaks, and database intrusions. The emergence of MEV (maximal extractable value) techniques and advanced social engineering has also contributed to the evolving threat landscape. For Garden, the incident underscores the need for continuous monitoring, incident response readiness, and robust isolation between on-chain and off-chain systems.

Atomic swaps have long been touted as a trustless way to exchange assets across different blockchains without relying on centralized intermediaries or wrapped tokens. However, they require precise coordination and cryptographic verification. HTLCs use time-locked contracts and hash preimages to ensure that either both parties receive their assets or the transaction reverts. In Garden’s implementation, independent solvers act as liquidity providers and facilitators. They monitor cross-chain swap requests and use their own capital to execute the exchange. The solvers are incentivized by fees but must manage the risk of counterparty default. The attacker in this incident exploited a flaw in the off-chain record-keeping, bypassing the on-chain safeguards.

The stolen funds were traced to wallet addresses that Blockaid published in its report. Garden and the security firms are now working on recovery efforts. In many DeFi exploits, funds are quickly moved across bridges or decentralized exchanges to obfuscate the trail. The involvement of zeroShadow, a firm specializing in blockchain forensics, increases the chances of tracking and freezing assets if they reach centralized exchanges with KYC procedures.

The incident also draws attention to the role of security audits and certifications. Garden’s SOC 2 Type II attestation is a significant achievement, but it does not guarantee immunity from sophisticated attacks. SOC 2 focuses on operational controls and data security, but it may not cover all aspects of DeFi-specific risks, such as economic incentives, oracle manipulation, or off-chain database management. The company’s decision to engage multiple security firms shows proactive risk management, but users and partners will likely scrutinize the details of the recovery plan before resuming full operations.

Looking ahead, Garden Finance plans to restore services only after completing a thorough security review. The company stated that its immediate priorities are securing the affected systems, tracing the solver’s funds, and ensuring that all critical infrastructure is hardened against future attacks. The DeFi community will be watching closely to see how Garden implements additional safeguards for its solver network. Some experts suggest that implementing decentralized storage for off-chain data, using oracles to verify transaction records, or requiring multi-sig approvals for solver actions could reduce the risk of similar breaches.

In summary, the Garden Finance exploit is a reminder that security in DeFi is not just about smart contract code but also about the broader infrastructure that supports cross-chain functionality. While the protocol itself remains intact, the reliance on off-chain solvers introduces a single point of failure that attackers are eager to exploit. The industry must continue to evolve its security practices to keep pace with sophisticated threats.


Source:Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy