Garden Finance Says Independent Solver Database Breach Led to $450,000 Drain
Key Takeaways
- •Garden Finance said the incident involved the off-chain database of one independent solver, not its protocol or HTLC smart contracts.
- •Blockaid reported about $450,000 in USDT was drained and identified activity across Ethereum, Base, Arbitrum and BNB Smart Chain.
- •Garden said user funds were not lost or placed at risk, and only assets owned by the solver were affected.
- •The app was paused while Garden isolated affected infrastructure and reviewed systems before resuming services.
- •Garden is working with zeroShadow, Quantstamp and Blockaid to trace and recover the affected funds.

Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.
Garden Finance said a breach of an independent solver’s off-chain database led the cross-chain bridge and atomic swap protocol to temporarily take its app offline while it isolated and reviewed affected infrastructure.
On Sunday, Blockaid said in an X post that an attacker had drained about $450,000 in USDT from Garden’s hash time-locked contracts, or HTLCs, on Ethereum, Base, Arbitrum and BNB Smart Chain. HTLCs are time-limited escrow contracts that Garden uses to support atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses it linked to the attacker and impacted contracts.
A Garden Finance spokesperson told Cointelegraph, however, that neither Garden’s protocol nor its HTLC smart contracts were compromised. According to the company, the attacker gained access to the off-chain database of an independent solver and inserted fraudulent transaction records. Those records caused the solver to release funds for swaps that had not been funded by the counterparty.
In Garden’s model, independent solvers provide liquidity and execute swaps around the protocol’s HTLC-based settlement process. That makes the distinction between a smart contract compromise and a solver-side infrastructure breach central to assessing which funds were exposed and which systems needed to be reviewed.
Garden said no user funds were lost or placed at risk, and that only solver-owned assets were affected. The company said it was still confirming the total amount involved, the affected assets and the networks impacted. Services were paused as a precaution while the affected systems were isolated and examined, Garden said.
Blockaid acknowledged Cointelegraph’s request for comment.
Garden works with security firms to trace funds
Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol expects to restore services shortly once security checks are completed, but it did not provide a specific timeline.
“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph. Garden said the incident was limited to the off-chain infrastructure of one solver within its network of independent solvers.
The company also cited its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. Garden told Cointelegraph that its immediate priorities are securing the affected systems, tracing the solver’s funds and ensuring that services resume only after the relevant reviews are finished.
The incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers, according to Garden’s incident report. Garden said that earlier incident also did not affect its protocol contracts or put user funds at risk.