GardenFi HTLC Exploit Drains About $450K in USDT Across Four Chains
Key Takeaways
- •Blockaid reported an active exploit involving GardenFi’s hashed timelock contract system.
- •Approximately $450,000 in USDT had been drained at the time of Blockaid’s alert.
- •The reported activity spanned Ethereum, Base, Arbitrum, and BNB Chain.
- •The final impact has not been confirmed because the exploit was still described as ongoing.
- •GardenFi users are waiting for official details on affected assets, contracts, and any required actions.

GardenFi is dealing with an active security incident after blockchain security firm Blockaid reported an exploit involving the protocol’s HTLC component. According to Blockaid, roughly $450,000 in USDT had been drained at the time of its alert.
The activity was reported across Ethereum, Base, Arbitrum, and BNB Chain, placing the incident across several major decentralized finance networks rather than a single blockchain. Blockaid described the exploit as ongoing, meaning the final amount affected may still change as investigators review transactions and related wallets.
Users and market observers are now waiting for further details from GardenFi. The incident has also renewed attention on security risks for cross-chain DeFi systems, where protocols operate across multiple networks and may require rapid monitoring, emergency controls, and coordinated response procedures.
Blockaid Reports Ongoing GardenFi Exploit
Blockaid said it detected an ongoing exploit affecting GardenFi’s HTLC system. HTLC stands for hashed timelock contract, a mechanism commonly used to support conditional transactions, including workflows where a transfer is completed only if preset cryptographic and timing conditions are met. The firm said attackers had drained about $450,000 in USDT so far.
Blockaid wrote on X: “🚨 Blockaid detected an ongoing exploit on @gardenfi HTLC. ~$450k USDT drained so far on Eth, Base, Arb and BSC. More details in 🧵” — Blockaid (@blockaid_) July 26, 2026 https://x.com/blockaid_/status/2081409252489298100?ref_src=twsrc%5Etfw
The reported drain affected Ethereum, Base, Arbitrum, and BNB Chain. That indicates the activity was not confined to one network, with the attacker moving across several chains during the incident.
Because Blockaid described the exploit as active, the final loss had not been confirmed in the available update. Early figures in exploit cases can change after security teams examine additional wallets, transaction paths, and connected contracts. GardenFi had not been quoted in the provided update with a final report.
Cross-Chain Activity Highlights Security Concerns
Cross-chain protocols can face added risks because they link activity across multiple networks. A vulnerability or weakness in one component may affect funds or transaction flows on other chains. That makes security architecture especially important for protocols that handle cross-chain transfers.
In this case, the exploit involved USDT across four networks. Stablecoin liquidity is frequently used in DeFi for trading and transfers, and that liquidity can become a target during active attacks.
Blockaid’s alert also shows how real-time monitoring can identify threats while they are still unfolding. However, detection by itself may not immediately stop losses. Protocols often rely on response teams, pause mechanisms, user warnings, and contract-level interventions during security incidents. For incidents spread across several chains, response work may also require tracking separate block explorers, contract deployments, and asset movements on each network.
Users Await Guidance From GardenFi
GardenFi users are watching for official guidance on the exploit. A full response would typically identify affected contracts, impacted assets, and any recovery plan. It may also explain whether users need to take action.
Security teams are expected to review wallet movements and transaction paths across Ethereum, Base, Arbitrum, and BNB Chain. That process may help determine the full loss, identify related addresses, and show whether additional funds were affected after the initial alert.
The incident keeps attention on GardenFi’s HTLC security and broader cross-chain design. Users may also monitor whether any markets are paused or contracts are updated. Further updates from GardenFi and Blockaid may clarify the total impact of the exploit.