Garden Finance disables app as Blockaid reports $450,000 exploit

cointelegraphОпубліковано о 2026-07-27Востаннє оновлено о 2026-07-27

Анотація

Garden Finance has temporarily taken its app offline following an incident reported by Blockaid involving approximately $450,000. Blockaid stated an attacker drained funds from Garden's hash time-locked contracts (HTLCs) on multiple blockchains. However, Garden Finance clarified that its protocol and HTLC smart contracts were not compromised. The company attributed the loss to a breach of an independent solver's off-chain database, where fraudulent records caused the solver to release its own funds for unfunded swaps. Garden emphasized no user funds were lost or at risk, with the incident confined to solver-owned assets. The firm is working with security companies to trace and recover the funds and expects to restore services after completing security reviews. This follows a previous solver-related breach in October 2025.

[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]

Garden Finance said an independent solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to temporarily take its app offline.

On Sunday, Blockaid said an attacker drained about $450,000 in USDT from Garden’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Smart Chain. HTLCs are time-bound escrow contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses linked to the attacker and affected contracts.

However, a Garden Finance spokesperson told Cointelegraph that neither the protocol nor its HTLC smart contracts had been compromised. The company said the attacker breached the off-chain database of an independent solver and inserted fraudulent transaction records, causing the solver to release funds for swaps that had not been funded by the counterparty.

Garden said no user funds were lost or placed at risk and that the incident affected only solver-owned assets. The company is still confirming the total amount, assets and networks involved. It said services were paused as a precaution while the affected infrastructure was isolated and reviewed.

Blockaid acknowledged Cointelegraph’s request for comments.

Garden works with security firms to trace funds

Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, subject to completing security checks, but did not give a specific timeline.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph, adding that the incident was isolated to the off-chain infrastructure of one solver in its network of independent solvers.

The company also pointed to its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. Garden told Cointelegraph that its immediate priorities are securing the affected systems, tracing the solver’s funds and ensuring services resume only after the relevant reviews are completed.

Related: WEMIX says attacker moved about $724,000 after contract breach

The incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers. Garden said that incident also did not affect its protocol contracts or put user funds at risk.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

Пов'язані питання

QAccording to the article, what was the root cause of the $450,000 exploit affecting Garden Finance?

AThe root cause was the compromise of an independent solver's off-chain database. The attacker inserted fraudulent transaction records, which caused the solver to release funds for swaps that were not actually funded by the counterparty.

QDid the exploit compromise Garden Finance's core protocol or smart contracts, according to the company's statement?

ANo, according to Garden Finance's statement, neither the protocol nor its HTLC smart contracts were compromised. The incident was isolated to the off-chain infrastructure of a single independent solver.

QWhat action did Garden Finance take in response to the incident, and which security firms are they working with?

AGarden Finance temporarily took its app offline as a precaution. They are working with the security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.

QWhat type of contracts were specifically targeted by the attacker, and on which networks?

AThe attacker targeted hash time-locked contracts (HTLCs) on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks.

QHow does this recent incident relate to a previous security event involving Garden Finance mentioned in the article?

AThe article mentions a previous breach in October 2025 where an attacker stole about $11.4 million after compromising a solver's operating environment. Similar to the recent incident, Garden stated that the 2025 breach also did not affect its protocol contracts or user funds.

Пов'язані матеріали

Huang Xiaoming, Li Bin, Lei Jun, Liang Wenfeng... Changxin IPO Feast, Who's the Biggest Winner?

Changxin Technology's IPO on the Shanghai STAR Market created significant wealth for its stakeholders. Founder Zhu Yiming and his family saw their wealth surge nearly 300%, with his stake in Changxin alone valued at approximately 80 billion RMB. Over 6700 employees benefited, creating at least 237 new millionaires. Several prominent figures also profited. Liang Wenfeng, founder of Deepseek, saw a paper gain of 827 million RMB through his funds' participation. Kong Jianping, founder of Nano Labs, holds an indirect stake worth around 940 million RMB, representing a roughly 44x return on his 2020 investment. Former Midea executive Huang Xiaoming gained approximately 503 million RMB. Strategic investors included industry partners. Nio, represented by founder William Li, pledged 158 million RMB for shares now showing a paper gain of about 740 million RMB. Similarly, a Xiaomi subsidiary acquired shares resulting in an over 736 million RMB gain, though the company clarified this is a corporate investment, not directly attributable to founder Lei Jun's personal wealth. Founder Zhu Yiming further plans to donate shares worth over 37.6 billion RMB for future employee incentives. The IPO solidified Changxin's position as a leading domestic memory chip maker, triggering a widespread wealth creation event for its network of founders, employees, and investors.

Odaily星球日报9 хв тому

Huang Xiaoming, Li Bin, Lei Jun, Liang Wenfeng... Changxin IPO Feast, Who's the Biggest Winner?

Odaily星球日报9 хв тому

Aave's Stable Vault

This article explores Aave's recently launched "Stable Vaults," a product designed to bridge the gap between traditional finance users and DeFi yield. It argues that while DeFi offers transparency and potentially higher returns, its complexity and volatility are major barriers for mainstream adoption. The core problem is that users pay for convenience and simplicity, often accepting lower returns to avoid decision-making and technical hurdles. Stable Vaults allow fintech apps, neobanks, or payment platforms (operators) to integrate with Aave's lending markets once and offer their users a "savings account" with a fixed, predictable yield (e.g., 4%). The operator absorbs the underlying market volatility; if Aave's pool pays 6%, the operator pockets the 2% difference, but if it pays only 2%, the operator covers the shortfall to maintain the promised 4% for users. The piece analyzes this model from three perspectives: 1. **The User:** Gains simplicity, a fixed rate, and familiar app features (customer support, account recovery). However, they lose potential upside, accept a lower fixed yield, and take on new counterparty risks from the operator and its proprietary backend systems. 2. **The Operator (e.g., a neobank):** Can monetize idle user balances easily, generating significant fee income (the spread between the fixed rate and the actual yield) with minimal integration effort, turning a cost center into revenue. 3. **Aave:** Gains "sticky," loyalty-based deposits that are less likely to flee during minor yield fluctuations, securing a stable revenue stream crucial for its tokenomics (like buybacks). It becomes a back-end infrastructure provider for the broader consumer finance ecosystem. The author acknowledges that while sophisticated users can access higher yields directly on Aave, most people prefer convenience and security over optimization. They reference behavioral studies showing that too many choices lead to inaction. Therefore, Stable Vaults represent an acceptance of human nature—prioritizing safety, predictability, and ease—and a strategic move for Aave to capture stable, large-scale deposits from mainstream finance applications. Examples like Rise (payroll) and Kraken are already using similar embedded yield models.

marsbit14 хв тому

Aave's Stable Vault

marsbit14 хв тому

Торгівля

Спот
活动图片