Key Takeaways
- Garden Finance pulled its application offline following an off-chain database compromise affecting one of its solvers
- Hackers stole approximately $450,000 in USDT spread across Ethereum, Base, Arbitrum and BNB Chain networks
- The protocol’s HTLC smart contracts remain secure, with no user deposits compromised
- Losses exclusively impacted the breached solver’s own funds, not customer assets
- Investigation and recovery efforts involve zeroShadow, Quantstamp and Blockaid security firms
On July 27, Garden Finance shut down its application following a security incident targeting one of the independent solvers operating within its cross-chain bridge ecosystem.
According to the company’s disclosure, threat actors successfully infiltrated the off-chain database belonging to a single solver. Once inside, they injected fraudulent transaction entries, deceiving the solver into authorizing fund releases for exchanges that were never legitimately initiated or funded.
Blockchain security provider Blockaid confirmed the breach resulted in approximately $450,000 worth of USDT being siphoned away. The theft spanned multiple networks including Ethereum, Base, Arbitrum and BNB Chain.
Garden Finance emphasized that the underlying protocol architecture and its hash time-locked contractsāthe time-sensitive escrow mechanisms facilitating atomic swaps between Bitcoin and other blockchainsāremained completely intact throughout the incident.
The organization stressed that customer deposits were never exposed or endangered during the attack. All financial losses were absorbed entirely by the compromised solver’s treasury.
As a protective measure, Garden Finance suspended platform operations while conducting a thorough examination of the compromised infrastructure. The company has yet to announce a concrete date for service restoration.
Recovery Efforts Underway With Security Partners
Garden Finance has engaged three specialized security organizations to track down and potentially retrieve the stolen digital assets. The investigation team includes zeroShadow, Quantstamp and Blockaid.
Platform functionality will remain suspended until comprehensive security audits have been finalized. Garden Finance referenced its recent SOC 2 Type II certification as demonstration of its commitment to infrastructure security.
Pattern Emerges: Second Solver Breach in Recent Months
This security incident marks the second solver-related breach Garden Finance has experienced in less than twelve months. Previously, in October 2025, a comparable attack resulted in approximately $11.4 million in losses after malicious actors gained access to a solver’s operational environment.
Garden Finance maintained that the earlier incident similarly left protocol contracts and user balances untouched.
The repeated nature of these breaches highlights an ongoing weakness in the off-chain solver infrastructure layer, distinct from the fundamental protocol design.
Garden Finance continues working to determine precise loss figures, identify all affected digital assets and confirm every impacted blockchain network.
Blockaid initially detected and publicly disclosed the exploit while it was still active, releasing wallet addresses associated with the perpetrators.
Garden Finance stated its current priorities center on hardening compromised systems, tracking stolen funds and establishing conditions for safely resuming operations.
No information has been released regarding whether any portion of the $450,000 has been successfully recovered to date.


