Garden Finance disables app as Blockaid reports $450,000 exploitGarden Finance said no user funds or smart contracts were affected after an attacker compromised an independent solver’s off-chain database and inserted fraudulent swap records.
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
Garden Finance temporarily disabled its application after an attacker compromised the off-chain database of an independent solver, which is part of its network facilitating cross-chain atomic swaps. The incident involved the insertion of fraudulent swap records into the solver’s database, causing the solver to release funds for swaps without proper counterparty funding. However, Garden Finance clarified that its protocol and hash time-locked contract (HTLC) smart contracts themselves were not compromised, and no user funds were lost or placed at risk in this event.
Security firm Blockaid initially reported that around $450,000 in USDT was drained from Garden’s HTLCs on multiple networks, including Ethereum, Base, Arbitrum, and BNB Smart Chain, and characterized the exploit as ongoing. In response, Garden Finance emphasized that the affected assets were solver-owned rather than user funds, and the compromised infrastructure had been isolated while they conducted a review. The protocol is still in the process of confirming exact amounts, affected assets, and involved networks.
Garden Finance is working with several security specialists, including zeroShadow, Quantstamp, and Blockaid, to trace and recover the lost funds. They aim to resume services shortly following comprehensive security checks but have not provided a specific timeline. The company highlighted its recent SOC 2 Type II attestation as part of its broader commitment to security and operational controls. This incident follows a similar October 2025 breach where approximately $11.4 million was stolen after compromising another solver’s operating environment without affecting the protocol’s core contracts or user funds.
The Garden Finance spokesperson reiterated that the incident was isolated to one off-chain solver’s infrastructure and reassured that the protocol’s contracts and user assets remain secure. The firm’s immediate focus is securing affected systems, tracing the funds linked to the compromised solver, and ensuring a safe service resumption once investigations are complete.