Garden Finance HTLC Exploit: $450K USDT Stolen Across Ethereum, Base, Arbitrum & BNB Chain
2026/08/01 13:00:00

Garden Finance Halts Cross-Chain Bridge After
Garden Finance, a cross-chain atomic-swap protocol that primarily focuses on bridging Bitcoin to other networks, made the decision to temporarily disable its application on July 26, 2026. This action was taken after the well-known security firm Blockaid reported the discovery of an active exploit that resulted in the extraction of approximately $450,000 in USDT. The funds in question were withdrawn from hash time-locked contracts that had been deployed across multiple blockchain networks, including Ethereum, Base, Arbitrum, and BNB Smart Chain. According to the information provided by the protocol, it was revealed that an attacker managed to gain unauthorized access to the off-chain database belonging to one independent solver. This individual inserted fraudulent swap records into the system and subsequently triggered the release of liquidity that was owned by the solver, all without any corresponding deposits from the counterparty.
Importantly, it should be noted that the core smart contracts and user funds remained unaffected by this exploit, which is a critical point of reassurance for users of the platform. This incident serves to highlight the persistent operational risks that exist at the solver layer of intent-based and atomic-swap systems, even in situations where the on-chain contracts themselves remain secure. Furthermore, it echoes a larger and more concerning incident involving an $11.4 million solver compromise that impacted the same protocol back in October 2025. This pattern of vulnerabilities raises significant questions about the overall security and operational hardening of such systems in the blockchain technology ecosystem.
Blockaid Detection and Multi-Chain Scope of the Drain
Blockchain security firm Blockaid first flagged the activity on July 26, 2026, noting that roughly $450,000 in USDT had already been withdrawn from Garden Finance HTLC contracts across four networks. The firm published the exploiter address and sample transaction hashes, describing the event as ongoing at the moment of detection. On-chain data later showed the attacker address consolidating holdings near $425,000 across the affected chains with a limited number of transactions. The simultaneous targeting of Ethereum, Base, Arbitrum, and BNB Smart Chain indicates the attacker understood the multi-deployment nature of the HTLC contracts and the solver’s operational reach.
Garden Finance responded by pausing the front-end application as a precaution while it coordinated with external investigators. The speed of detection limited further losses, yet the episode demonstrates how off-chain components can still create pathways for fund extraction even when the underlying contracts function as designed. Market observers noted the relatively modest size compared with larger bridge incidents, but the recurrence of solver-related losses within nine months raised questions about operational hardening. Public statements emphasized that the protocol itself continued to operate according to its trustless design. Tracing efforts began immediately with specialized partners.
How the Off-Chain Database Compromise Enabled Fake Settlements
The attacker did not exploit a vulnerability in the HTLC smart contracts. Instead, access was obtained to the off-chain database maintained by one independent solver. Once inside, the intruder created fabricated swap records that the solver’s systems treated as legitimate. Those records instructed the solver to release USDT held in the corresponding HTLCs even though no matching deposit had been made by a counterparty. Because solvers provide liquidity and execute the matching leg of atomic swaps, their operational environments hold real assets ready for release upon apparent completion of the cryptographic conditions. The insertion of false data bypassed the normal verification that would have confirmed inbound funds.
Garden Finance confirmed that only solver-owned capital was affected and that user deposits remained untouched. This vector differs from classic smart-contract reentrancy or logic errors and instead illustrates the risk concentrated in the off-chain coordination layer that many modern intent and solver-based protocols rely upon. Independent solvers operate with their own infrastructure, creating a distributed but uneven security surface. The incident shows that database integrity and access controls around those systems are as critical as on-chain audits. Remediation will necessarily focus on stronger authentication, monitoring, and isolation of solver environments.
Protocol Response and Collaboration with Security Partners
Garden Finance publicly stated that its protocol contracts and HTLC implementations were never compromised. The team paused the application interface to prevent further interaction while forensic work proceeded. Collaboration was established with zeroShadow, Quantstamp, and Blockaid to map fund movements and identify recovery opportunities. Official communications stressed that no user funds were lost or placed at risk and that the loss was confined to assets belonging to the affected solver. The protocol indicated it expected to resume service after completing security reviews, though no precise restart date was provided.
This measured approach mirrors the response pattern used after the larger October 2025 incident. Transparency around the limited scope helped contain reputational damage, yet the need to take the app offline; still interrupted normal bridging activity for Bitcoin assets and related assets. External partners bring specialized tracing and audit capabilities that individual protocols often lack in-house. The episode reinforces the value of pre-arranged incident-response relationships. Users were advised to monitor official channels for restoration updates rather than third-party claims.
Comparison with the October 2025 Solver Incident
In October 2025, an attacker compromised the operating environment of one of Garden Finance’s largest independent solvers and extracted approximately $11.4 million across multiple chains. A subsequent forensic report prepared with external review concluded that the breach was limited to the solver layer and that protocol contracts and user funds remained secure. Stolen assets were later moved through bridges and mixers, with some analysis linking the activity to a known threat actor. The July 2026 event is smaller in absolute terms yet follows a similar pattern of targeting solver infrastructure rather than the core contracts.
Both cases demonstrate that the economic security of atomic-swap systems depends heavily on the operational hygiene of the parties providing liquidity and matching. The recurrence within less than a year suggests that lessons from the earlier incident had not fully eliminated the attack surface. Garden Finance’s January 2026 disclosure of the prior forensic findings provided a public record that now serves as a baseline for evaluating the latest response. Industry participants will examine whether additional technical or process controls are introduced after this second event. The parallel nature of the two incidents supplies a clear data point for risk assessment of solver-dependent architectures.
Role of Hash Time-Locked Contracts in Garden’s Design
Garden Finance relies on hash time-locked contracts to enable trustless cross-chain atomic swaps, particularly between Bitcoin and EVM or other networks. An HTLC locks funds that can be claimed only by presenting a preimage of a cryptographic hash within a defined time window; otherwise, the funds return to the original party. This construction allows two parties on different chains to exchange assets without a trusted intermediary holding custody. Solvers participate by providing the liquidity leg and monitoring for the release conditions. When a solver’s off-chain systems are fed incorrect data, the on-chain HTLC can still execute a release that appears valid from the contract’s perspective.
The design therefore separates the security of the cryptographic lock from the integrity of the operational systems that decide when to interact with it. Audits by firms such as Trail of Bits have examined the on-chain components, yet off-chain solver environments fall outside those reviews. The recent exploit did not break the HTLC logic; it manipulated the inputs that triggered legitimate contract functions. Understanding this distinction is essential for evaluating residual risk in similar protocols. Users of atomic-swap bridges must weigh both on-chain and operational assurances.
Impact on Users and Continuity of Bridging Services
Garden Finance reported that no user funds were lost or placed at risk during the July 2026 incident. The pause of the application interface, however, temporarily halted new swaps and bridging activity. Users with pending transactions or open positions were directed to official communication channels for status updates. Because the core contracts continued to function according to their programmed rules, existing locked positions were not unilaterally altered by the exploit. The interruption nevertheless reduced liquidity availability and delayed cross-chain transfers that rely on the protocol.
Market participants who depend on Garden for rapid Bitcoin-to-EVM movement experienced a short period of reduced optionality. Restoration plans center on completing security reviews of the solver layer before reopening the front end. The limited scope of the loss relative to total value locked helped preserve confidence among existing users. Clear differentiation between solver capital and user deposits remains a central message in the protocol’s communications. Service continuity after such events is a key metric for long-term adoption of atomic-swap infrastructure.
On-Chain Tracking of Stolen Assets
Blockaid published the primary exploiter address, enabling independent verification of fund movements. Early data showed consolidation of approximately $425,000 across the four affected chains. Subsequent transfers and potential bridging or swapping activity are being monitored by the investigation partners. In the prior 2025 incident, funds were rapidly moved through mixers and bridges, complicating recovery. The smaller size of the 2026 drain may improve the practical odds of partial recovery if freezable assets reach centralized venues.
Specialized firms such as zeroShadow bring experience in following multi-chain flows and attributing patterns to known actors. Public blockchain transparency allows any observer to follow the addresses once they are disclosed. Successful tracing can also inform future defensive measures by revealing preferred exit routes. The protocol has not announced a formal bounty for this incident at the time of initial reporting, although such incentives were used previously. Continued monitoring of the identified wallets remains an active part of the response.
Broader Implications for Solver-Based Cross-Chain Protocols
Many modern cross-chain systems rely on networks of independent solvers or solvers that compete to fulfill user intents. These operators hold inventory and execute the matching side of swaps, creating an economic surface that is separate from the core protocol contracts. Compromises of solver infrastructure therefore represent a recurring class of risk that audits of the on-chain code do not fully address. The Garden Finance events of 2025 and 2026 illustrate that even well-audited HTLC designs can experience losses when the off-chain decision layer is breached.
Other protocols employing similar architectures face parallel exposure. Industry responses may include stricter operational security standards for solvers, mandatory multi-party computation for key material, or insurance mechanisms that cover solver capital. Users evaluating atomic-swap or intent-based bridges now have concrete data points on the frequency and scale of solver-layer incidents. Transparent disclosure after each event contributes to collective learning across the sector. The pattern suggests that operational security investment must keep pace with on-chain development.
Security Audits and Residual Operational Risk
Garden Finance has subjected its core contracts to reviews by recognized firms, including Trail of Bits, covering the HTLC, staking, and fee mechanisms. Those audits focus on the deterministic on-chain logic and do not extend to the private infrastructure of independent solvers. The gap between audited contracts and unaudited operational environments is common across decentralized systems that outsource liquidity provision. After the 2025 incident, forensic work identified unauthorized SSH access and subsequent laundering patterns.
The 2026 database compromise represents a different entry point within the same general layer. Strengthening access controls, continuous monitoring, and isolation of solver databases appears to be the immediate priority. Protocols may also explore cryptographic techniques that reduce the amount of sensitive state held off-chain. Residual risk cannot be eliminated entirely, yet each incident supplies concrete improvements for the next iteration. Users should treat solver operational security as a distinct evaluation criterion alongside smart-contract audit reports.
Market Context for Cross-Chain Bitcoin Bridging
Demand for fast, non-custodial movement of Bitcoin into EVM and other ecosystems continues to support protocols such as Garden Finance. Atomic swaps using HTLCs offer a trust-minimized alternative to custodial bridges or wrapped assets. Liquidity depth and execution speed depend on active solvers willing to commit capital. Interruptions caused by security events temporarily reduce that depth and can shift volume to competing venues. The relatively contained size of the July 2026 loss limited broader market disruption, yet repeated incidents can erode confidence among larger liquidity providers.
Competitive pressure encourages rapid recovery and demonstrable hardening. Parallel developments in Bitcoin Layer-2 solutions and other bridging designs provide users with alternatives when one venue is offline. The episode fits within a longer pattern of security challenges that every major cross-chain system has confronted. Continued innovation in both cryptography and operational practices remains necessary for the category to mature.
Investigation Partners and Recovery Prospects
Garden Finance engaged zeroShadow, Quantstamp, and Blockaid to support tracing and recovery efforts. These firms specialize in on-chain forensics, smart contract review, and real-time threat detection. Their combined capabilities improve the probability of identifying exit paths and coordinating with centralized platforms if funds surface there. Recovery rates in prior solver and bridge incidents have varied widely depending on the speed of movement and the use of mixers. The smaller absolute amount involved in the 2026 case may increase the practical chance of partial retrieval compared with the earlier $11.4 million event.
Public disclosure of the exploiter address enables community monitoring that supplements professional efforts. Any recovered assets would return to the affected solver rather than to the protocol treasury or users, consistent with the ownership of the lost capital. Progress updates are expected through official channels as the investigation advances. The collaborative model reflects current best practice for post-incident response in decentralized systems.
Lessons for Users of Atomic-Swap and Intent Protocols
Users of systems that rely on independent solvers should recognize that operational security of those solvers constitutes part of the overall risk profile. Even when smart contracts are correctly designed and audited, the parties that supply liquidity and execute matches can become points of failure. Diversification across multiple bridging venues reduces exposure to any single operational interruption. Monitoring official communication channels during incidents provides the most reliable status information.
The clear separation maintained by Garden Finance between user funds and solver capital is a positive design feature that limited direct user losses in both recent events. Nevertheless, temporary unavailability of the interface still affects practical usability. Prospective users may wish to review historical incident reports and the scope of external audits before committing significant volume. The two Garden Finance cases supply concrete examples that can inform due diligence checklists for similar protocols. Ongoing improvement in solver operational standards will benefit the entire category of trust-minimized cross-chain tools.
🔥 Join KuCoin 9th Anniversary Trading CampaignKuCoin is celebrating its 9th anniversary with a special platform campaign filled with exclusive rewards, trading activities, and limited-time offers. Don’t miss the chance to participate and enjoy the benefits as the exchange marks nine years of growth and innovation. Visit the official campaign page now:
|
FAQs
Were any user funds lost in the Garden Finance exploit?
Garden Finance stated that neither user deposits nor the core protocol contracts were compromised. The approximately $450,000 in USDT drained from HTLCs belonged to the affected independent solver. The application interface was paused as a precaution, but existing user positions were not altered by the attack.
How did the attacker extract funds without breaking the smart contracts?
The attacker compromised the off-chain database of one solver and inserted false swap records. Those records caused the solver to release USDT held in HTLCs even though no matching counterparty deposit had occurred. The on-chain contracts executed legitimate release functions based on the manipulated inputs.
Which blockchains were affected by the drain?
The withdrawals occurred on Ethereum, Base, Arbitrum, and BNB Smart Chain. Blockaid identified activity across all four networks and published the primary exploiter address for public verification.
Is this related to the earlier $11.4 million incident?
Yes. In October 2025, a different compromise of a solver’s operating environment resulted in the loss of approximately $11.4 million of solver-owned assets. Both events left the core protocol and user funds intact, highlighting repeated risk at the solver layer.
What steps is Garden Finance taking to resume operations?
The protocol is working with ZeroShadow, Quantstamp, and Blockaid to complete forensic analysis and security reviews of the solver infrastructure. Service is expected to resume after those checks, although no specific date has been announced.
Can the stolen USDT be recovered?
Investigation partners are tracing the funds across chains. Recovery depends on whether the assets reach venues that can freeze them and on the speed of movement. No formal recovery amount has been confirmed at the time of initial reporting.
Disclaimer: This content is for informational purposes only and does not constitute investment advice. Cryptocurrency investments carry risk. Please do your own research (DYOR).

