[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]
Garden Finance says the third-party solver’s off-chain database was compromised in an incident that caused the cross-chain bridge and atomic exchange protocol to temporarily take the application offline.
Blockade on Sunday he said an attacker stole approximately $450,000 in USDT from Garden’s Hash Time-Limited Contracts (HTLC) on Ethereum, Base, Arbitrum, and BNB Smart Chain. HTLCs are time-limited deposit contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses associated with the attacker and affected contracts.
However, a Garden Finance spokesperson told Cointelegraph that neither the protocol nor the HTLC shrewd contracts contained within it were compromised. The company said the attacker compromised an off-chain database of a third-party solver and posted records of bogus trades, which caused the solver to release funds for swaps that were not funded by the counterparty.
Garden stated that no user funds were lost or at risk and that the incident only affected assets owned by Solver. The company is still confirming the total amount, assets and networks involved. It said services were suspended as a precaution and the affected infrastructure was isolated and checked.
Blockaid accepted Cointelegraph’s request for comments.
Garden works with security companies to track funds
Garden stated that it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol is pending restoration services soon, subject to completion of security checks, but did not provide a specific timetable.
“The Garden Protocol and HTLC smart contracts were not compromised and user funds were not lost or at risk,” the company told Cointelegraph, adding that the incident occurred on the off-chain infrastructure of one of the solvers in its network of independent solvers.
The company also pointed to its recent SOC 2 Type II certification as evidence of its investment in security and operational controls. Garden told Cointelegraph that his immediate priorities are securing affected systems, tracking solver funds and ensuring services only resume once appropriate reviews are completed.
Related: WEMIX claims that the attacker transferred approximately $724,000 after breaching the contract
Incident follows the October 2025 breach in which an attacker stole approximately $11.4 million after compromising the operating environment of one of Garden’s solutions. Garden said the incident also did not impact the protocol’s contracts or put user funds at risk.
Warehouse: Inside the ‘bogus police raid’ that forced a $1 million Bitcoin transfer
