NewsCryptoGarden Finance Suspends App After Independent Solver Database Breach

Garden Finance Suspends App After Independent Solver Database Breach

Author: CryptoMeter io·

Key Takeaways

  • •Garden Finance took its user-facing application offline after an independent solver’s off-chain database was compromised.
  • •The incident resulted in roughly $450,000 in unauthorized transfers from assets controlled by the affected solver.
  • •Garden Finance said its smart contracts, core infrastructure, atomic swap mechanism, and customer funds were not impacted.
  • •The attacker allegedly added fraudulent swap records that caused the solver to release assets for requests without counterparty funding.
  • •The project is coordinating with blockchain security firms to investigate the attack, track the funds, and strengthen monitoring controls.
Garden Finance Suspends App After Independent Solver Database Breach

Garden Finance temporarily took its application offline after an attacker compromised the off-chain database of an independent solver and triggered unauthorized cryptocurrency transfers worth about $450,000.

The cross-chain atomic swap protocol said the incident did not affect its core infrastructure, smart contracts, or user funds. Garden Finance said the losses were confined to assets controlled by the affected solver, drawing a distinction between the security of the protocol itself and the operational risks faced by independent infrastructure providers connected to decentralized systems.

In cross-chain swap systems, solvers typically help execute transactions by supplying liquidity or fulfilling swap routes for users. That role can make their internal records and operational controls important to the reliability of the overall user experience, even when the underlying protocol logic remains separate.

The platform said it disabled user-facing services as a precaution while security teams investigated the breach, isolated the affected systems, and reviewed the broader network before restoring operations.

How the Attack Occurred

According to Garden Finance, the attacker obtained unauthorized access to the independent solver’s off-chain database and inserted fraudulent swap records. Those manipulated entries caused the solver to release assets for swap requests that had not been funded by counterparties.

Garden Finance said the exploit targeted operational infrastructure rather than the protocol’s hash time-locked contract architecture. Hash time-locked contracts are designed to enforce swap conditions on-chain by requiring cryptographic proof within a set time window, which is why Garden Finance distinguished the solver database compromise from a failure of the atomic swap mechanism itself. On that basis, the project maintained that its atomic swap mechanism continued to operate as designed and that customer assets remained protected throughout the incident.

The project also said it is working with multiple blockchain security firms to investigate the attack, trace the transferred funds, and strengthen monitoring procedures before bringing the application fully back online.

Off-Chain Infrastructure Risks

The incident highlights an increasingly important risk area across the cryptocurrency industry: attacks on off-chain infrastructure rather than smart contract code. Even when decentralized protocols and on-chain mechanisms remain secure, supporting systems such as databases, servers, and validator infrastructure can create attack paths if they are compromised.

Garden Finance emphasized that its decentralized architecture helped contain the damage because the impacted solver operated independently from the protocol itself. The company said the temporary shutdown was intended to make sure no additional infrastructure was at risk while investigators completed their review.

Although the financial impact was limited to the solver’s inventory, the event illustrates that securing decentralized applications requires protecting both blockchain-based systems and the off-chain infrastructure that supports daily operations. For protocols that rely on independent operators, the response will likely be assessed not only by whether smart contracts were unaffected, but also by how quickly compromised services are isolated, funds are traced, and monitoring controls are tightened before full access resumes.