Garden Finance disables app as Blockaid reports $450,000 exploit

cointelegraphPublicado em 2026-07-27Última atualização em 2026-07-27

Resumo

Garden Finance has temporarily taken its app offline following an incident reported by Blockaid involving approximately $450,000. Blockaid stated an attacker drained funds from Garden's hash time-locked contracts (HTLCs) on multiple blockchains. However, Garden Finance clarified that its protocol and HTLC smart contracts were not compromised. The company attributed the loss to a breach of an independent solver's off-chain database, where fraudulent records caused the solver to release its own funds for unfunded swaps. Garden emphasized no user funds were lost or at risk, with the incident confined to solver-owned assets. The firm is working with security companies to trace and recover the funds and expects to restore services after completing security reviews. This follows a previous solver-related breach in October 2025.

[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]

Garden Finance said an independent solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to temporarily take its app offline.

On Sunday, Blockaid said an attacker drained about $450,000 in USDT from Garden’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Smart Chain. HTLCs are time-bound escrow contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses linked to the attacker and affected contracts.

However, a Garden Finance spokesperson told Cointelegraph that neither the protocol nor its HTLC smart contracts had been compromised. The company said the attacker breached the off-chain database of an independent solver and inserted fraudulent transaction records, causing the solver to release funds for swaps that had not been funded by the counterparty.

Garden said no user funds were lost or placed at risk and that the incident affected only solver-owned assets. The company is still confirming the total amount, assets and networks involved. It said services were paused as a precaution while the affected infrastructure was isolated and reviewed.

Blockaid acknowledged Cointelegraph’s request for comments.

Garden works with security firms to trace funds

Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, subject to completing security checks, but did not give a specific timeline.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph, adding that the incident was isolated to the off-chain infrastructure of one solver in its network of independent solvers.

The company also pointed to its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. Garden told Cointelegraph that its immediate priorities are securing the affected systems, tracing the solver’s funds and ensuring services resume only after the relevant reviews are completed.

Related: WEMIX says attacker moved about $724,000 after contract breach

The incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers. Garden said that incident also did not affect its protocol contracts or put user funds at risk.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

Perguntas relacionadas

QAccording to the article, what was the root cause of the $450,000 exploit affecting Garden Finance?

AThe root cause was the compromise of an independent solver's off-chain database. The attacker inserted fraudulent transaction records, which caused the solver to release funds for swaps that were not actually funded by the counterparty.

QDid the exploit compromise Garden Finance's core protocol or smart contracts, according to the company's statement?

ANo, according to Garden Finance's statement, neither the protocol nor its HTLC smart contracts were compromised. The incident was isolated to the off-chain infrastructure of a single independent solver.

QWhat action did Garden Finance take in response to the incident, and which security firms are they working with?

AGarden Finance temporarily took its app offline as a precaution. They are working with the security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.

QWhat type of contracts were specifically targeted by the attacker, and on which networks?

AThe attacker targeted hash time-locked contracts (HTLCs) on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks.

QHow does this recent incident relate to a previous security event involving Garden Finance mentioned in the article?

AThe article mentions a previous breach in October 2025 where an attacker stole about $11.4 million after compromising a solver's operating environment. Similar to the recent incident, Garden stated that the 2025 breach also did not affect its protocol contracts or user funds.

Leituras Relacionadas

Crypto.com, Backed by Citadel Securities, Transfers XYO and XL1 into Regulated Custody

Crypto.com, with backing from Citadel Securities, has placed XYO and XL1 tokens into regulated custody. This move provides eligible institutions and high-net-worth clients with a regulated mechanism for storing, managing, and exchanging these tokens without first having to transfer assets onto an exchange. The custody structure utilizes segregated MPC wallets managed by a bankruptcy-remote entity, with private keys secured via multi-party computation. Clients benefit from cold storage, audit trails, and direct access to Crypto.com's institutional liquidity while their assets are custodied, removing the operational step of pre-trade transfers. Company leadership positioned this as a strategic step to provide "unmatched security and seamless liquidity" for digital asset organizations, and to protect and scale the XYO ecosystem. The partnership builds on an existing relationship since XYO's initial listing on the exchange. This development follows Citadel Securities' $400 million investment in Crypto.com and comes as the company expands its regulatory standing, having received conditional approval to establish a national trust bank. For institutional investors, this custody agreement addresses a key barrier by demonstrating that smaller market-cap assets like XYO and XL1 can be held under the same regulatory and security standards as larger tokens. XYO operates a large DePIN network generating real-world data for AI and robotics, with XL1 handling its blockchain transactions and infrastructure.

cryptonews.ruHá 1h

Crypto.com, Backed by Citadel Securities, Transfers XYO and XL1 into Regulated Custody

cryptonews.ruHá 1h

Less Than Two Weeks Left — Bitcoin's BIP-110 Countdown Begins as Miner Support Grows Ahead of Decisive Moment

The BIP-110 activation process for Bitcoin, which proposes a temporary soft fork to limit specific data-heavy transaction types (like Ordinals inscriptions), is entering its critical final phase. As of July 27, 2026, there are roughly 1,790 blocks remaining until the mandatory signaling window begins at block 961,632 (estimated for August 9). Starting then, nodes enforcing BIP-110 will reject blocks not signaling for the proposal. While support from miners has grown from below 1% to around 3% recently, it remains concentrated among smaller pools and independent miners, with major pools like Foundry, Antpool, ViaBTC, and F2Pool largely not signaling. Foundry's stance is particularly decisive, as it holds a large share of the network's hashrate and has tied its signaling to a client vote. Without a major pool's shift, widespread activation is unlikely. If the current low signaling levels persist after the window opens, nodes enforcing BIP-110 will follow a slower, minority chain, potentially creating a chain split from the majority chain followed by legacy (e.g., Bitcoin Core) nodes. This activation mechanism differs from past soft forks like SegWit, resembling the 2017 UASF BIP-148 more closely. Proponents argue BIP-110 is necessary to curb spam-like data transactions that increase node costs and distort fee markets, framing opposition as a contentious hard fork. Critics, however, view the activation method as a radical overreaction to a minor issue. The final outcome in the coming two weeks hinges on whether a major pool switches support, if major exchanges clarify their chain preference, and how miners actually behave once the mandatory window is open.

cryptonews.ruHá 1h

Less Than Two Weeks Left — Bitcoin's BIP-110 Countdown Begins as Miner Support Grows Ahead of Decisive Moment

cryptonews.ruHá 1h

Trading

Spot
活动图片