Garden Finance disables app as Blockaid reports $450,000 exploit

cointelegraphPublished on 2026-07-27Last updated on 2026-07-27

Abstract

Garden Finance has temporarily taken its app offline following an incident reported by Blockaid involving approximately $450,000. Blockaid stated an attacker drained funds from Garden's hash time-locked contracts (HTLCs) on multiple blockchains. However, Garden Finance clarified that its protocol and HTLC smart contracts were not compromised. The company attributed the loss to a breach of an independent solver's off-chain database, where fraudulent records caused the solver to release its own funds for unfunded swaps. Garden emphasized no user funds were lost or at risk, with the incident confined to solver-owned assets. The firm is working with security companies to trace and recover the funds and expects to restore services after completing security reviews. This follows a previous solver-related breach in October 2025.

[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]

Garden Finance said an independent solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to temporarily take its app offline.

On Sunday, Blockaid said an attacker drained about $450,000 in USDT from Garden’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Smart Chain. HTLCs are time-bound escrow contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses linked to the attacker and affected contracts.

However, a Garden Finance spokesperson told Cointelegraph that neither the protocol nor its HTLC smart contracts had been compromised. The company said the attacker breached the off-chain database of an independent solver and inserted fraudulent transaction records, causing the solver to release funds for swaps that had not been funded by the counterparty.

Garden said no user funds were lost or placed at risk and that the incident affected only solver-owned assets. The company is still confirming the total amount, assets and networks involved. It said services were paused as a precaution while the affected infrastructure was isolated and reviewed.

Blockaid acknowledged Cointelegraph’s request for comments.

Garden works with security firms to trace funds

Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, subject to completing security checks, but did not give a specific timeline.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph, adding that the incident was isolated to the off-chain infrastructure of one solver in its network of independent solvers.

The company also pointed to its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. Garden told Cointelegraph that its immediate priorities are securing the affected systems, tracing the solver’s funds and ensuring services resume only after the relevant reviews are completed.

Related: WEMIX says attacker moved about $724,000 after contract breach

The incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers. Garden said that incident also did not affect its protocol contracts or put user funds at risk.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

Related Questions

QAccording to the article, what was the root cause of the $450,000 exploit affecting Garden Finance?

AThe root cause was the compromise of an independent solver's off-chain database. The attacker inserted fraudulent transaction records, which caused the solver to release funds for swaps that were not actually funded by the counterparty.

QDid the exploit compromise Garden Finance's core protocol or smart contracts, according to the company's statement?

ANo, according to Garden Finance's statement, neither the protocol nor its HTLC smart contracts were compromised. The incident was isolated to the off-chain infrastructure of a single independent solver.

QWhat action did Garden Finance take in response to the incident, and which security firms are they working with?

AGarden Finance temporarily took its app offline as a precaution. They are working with the security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.

QWhat type of contracts were specifically targeted by the attacker, and on which networks?

AThe attacker targeted hash time-locked contracts (HTLCs) on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks.

QHow does this recent incident relate to a previous security event involving Garden Finance mentioned in the article?

AThe article mentions a previous breach in October 2025 where an attacker stole about $11.4 million after compromising a solver's operating environment. Similar to the recent incident, Garden stated that the 2025 breach also did not affect its protocol contracts or user funds.

Related Reads

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbit1h ago

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbit1h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbit1h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbit1h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru6h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru6h ago

Trading

Spot
活动图片