NewsCryptoGarden Finance Pauses App After Blockaid Reports $450K USDT Exploit

Garden Finance Pauses App After Blockaid Reports $450K USDT Exploit

Author: CryptoBreaking·

Key Takeaways

  • •Blockaid said roughly $450,000 in USDT was drained from Garden-linked HTLCs on Ethereum, Base, Arbitrum, and BNB Smart Chain.
  • •Garden said its protocol and on-chain HTLC smart contracts were not breached during the incident.
  • •Garden attributed the event to manipulated records in an independent solver’s off-chain database that triggered incorrect swap releases.
  • •The company said user funds were not lost or placed at risk, with the impact limited to assets owned by the solver.
  • •Garden has paused services while it isolates the suspected infrastructure, traces funds, and completes security checks.
Garden Finance Pauses App After Blockaid Reports $450K USDT Exploit

Garden Finance is investigating an exploit that reportedly affected infrastructure connected to its cross-chain bridge and atomic swap system after an attacker drained roughly $450,000 worth of USDT from Garden-linked hash time-locked contracts, or HTLCs, across multiple networks, according to Blockaid. The incident prompted Garden to temporarily pause its services while the relevant systems are isolated and reviewed.

Garden has challenged the initial characterization of the incident. The company says its protocol and on-chain HTLC smart contracts were not compromised. Instead, Garden attributes the event to an intrusion into the off-chain database of an independent solver, where fraudulent transaction records were allegedly inserted and later caused incorrect swap releases.

Blockaid’s account of the incident

Earlier Sunday, Blockaid said the exploit was ongoing and involved Ethereum-based HTLCs used by Garden to coordinate atomic swaps. In its public update, Blockaid reported that an attacker drained approximately $450,000 in USDT from Garden HTLCs deployed across Ethereum, Base, Arbitrum, and BNB Smart Chain.

HTLCs are time-bound escrow contracts designed to release assets only when specified conditions are met. They are commonly used in atomic swaps that span multiple blockchains because they help coordinate settlement between parties without requiring both sides of a transaction to trust each other directly.

Blockaid also published addresses it associated with the attacker and the contracts it believed were affected. According to Blockaid’s description, the exploit targeted Garden-linked HTLCs across several networks rather than a single deployment.

Garden says on-chain contracts were not breached

Garden Finance disputed the implication that its core protocol contracts had been compromised. A spokesperson told Cointelegraph that neither the Garden protocol nor its HTLC smart contracts were breached.

According to Garden, the attacker gained access to the off-chain database of an independent solver and inserted falsified transaction records. Garden said those incorrect records caused the solver to release funds for swaps that had not actually been funded by the intended counterparty.

In cross-chain swap systems, solvers are typically operational participants that help execute or fulfill swaps, and their systems can hold records used to determine whether a transaction should proceed. That role makes the integrity of solver-side infrastructure relevant even when the smart contract code itself is not changed.

The company said no user funds were lost and that user funds were not placed at risk. Garden stated that the impact was limited to assets owned by the solver. It also said it was still confirming the full scope of the incident, including the total amount involved, the assets affected, and the exact networks tied to the event.

Garden’s explanation separates the on-chain components of the protocol from the off-chain infrastructure used by solvers. While HTLCs execute on-chain, cross-chain swap systems often depend on off-chain systems to coordinate activity, track swap status, and trigger settlement steps. In Garden’s account, the on-chain contracts remained intact, but off-chain data used by one solver was manipulated in a way that caused settlement to occur incorrectly.

Services paused during security review

Garden paused its services as a precaution while the suspected infrastructure is isolated and examined. The company said it is working with zeroShadow, Quantstamp, and Blockaid to trace and recover the funds.

Garden said it expects to restore services shortly after security checks are completed, but it did not provide a specific timetable. The company said its priorities are securing the affected systems, tracing the solver’s funds, and resuming services only after the relevant reviews are complete.

Garden also referenced its SOC 2 Type II attestation as evidence of its security and operational controls. A SOC 2 Type II report assesses controls over a review period, but it does not by itself determine the cause or scope of a specific security incident. The company framed the incident as isolated to one solver’s off-chain infrastructure within its broader network of independent solvers.

Off-chain systems remain part of cross-chain risk

The incident highlights how cross-chain protocols can depend on both smart contracts and operational infrastructure. Even if on-chain escrow logic is not altered, off-chain databases, access controls, and transaction records can become important attack surfaces when they influence whether funds are released.

Garden’s immediate response — pausing services and isolating the suspected infrastructure — reflects the risk that operational compromises can result in on-chain fund movements. The distinction between a contract-level exploit and a solver-level data breach may also affect remediation, because resolving the issue requires not only stopping further incorrect releases but also validating swap states and confirming that the same failure mode cannot recur.

Previous solver-related breach

The reported event follows a prior incident disclosed by Garden in October 2025. In that case, Garden said an attacker stole about $11.4 million after compromising the operating environment of one of its solvers. Garden said that earlier breach also did not compromise its protocol contracts or put user funds at risk.

Together, the two incidents place attention on the security posture and isolation of third-party solver environments, as well as the integrity of off-chain data used in cross-chain settlement. Garden is continuing to trace the funds and validate affected swap records while security firms assist with the investigation.

Garden has not yet provided final confirmed totals for the latest incident, a complete list of affected assets, or a final determination of all networks involved. The timing for a full service restoration remains dependent on the completion of its security checks.