Overview
- Garden Finance suspended its application after unusual activity on Monday when security firm Blockaid flagged an active exploit that drained about $450,000 in USDT across Ethereum, Base, Arbitrum and BNB Chain.
- Garden says its HTLC smart contracts and user funds were not compromised and that the attacker accessed an independent solver’s off‑chain database to insert fraudulent transaction records that caused the solver to release its own funds.
- The protocol has engaged zeroShadow, Quantstamp and Blockaid to trace and attempt recovery of the stolen assets while it isolates affected systems and completes security reviews, and it has given no timeline for restoring services.
- This is the second solver‑related breach in under a year after an October 2025 compromise that cost roughly $11 million, a pattern that points to operational risk in off‑chain solver environments rather than flaws in Garden’s core contracts.
- The incident raises broader questions for cross‑chain swap models because attackers can target third‑party operator infrastructure; the key next developments to watch are forensic findings, any recovered funds, and Garden’s measures to harden solver controls.