Web3 security firm Blockaid has uncovered a live exploit siphoning around $450,000 in USDT from Garden Finance’s smart contracts. The attack spans four EVM-compatible blockchains: Ethereum, Base, Arbitrum, and BNB Chain. At the time of detection, the breach was still in progress.
Repeated Security Failures Raise Concerns
This marks the second major hack for Garden Finance within a year. Last year’s incident saw losses estimated between $10.8 million and $11 million, linked to a compromised solver handling cross-chain swaps. This time, the attacker targeted the core smart contracts directly.
Garden Finance relies on Hash Time Locked Contracts (HTLCs) to enable atomic swaps across chains. HTLCs act like digital escrow accounts that require both parties to meet conditions before a time limit expires. Blockaid’s investigation suggests the hacker exploited a flaw in these contracts’ logic or deployment, allowing simultaneous draining of funds across different networks.
Despite the smaller sum compared to the previous breach, the fact that Garden Finance has suffered fundamentally different types of attacks within months highlights ongoing vulnerabilities in their infrastructure. The protocol supports multiple chains including Ethereum, Solana, Base, Arbitrum, and BNB Chain, facilitating fast swaps primarily between Bitcoin and USDT.
Security audits by leading firms Trail of Bits, OtterSec, and Zellic haven't prevented these breaches, pointing to either undiscovered contract flaws or operational weak points. For users, the advice is clear: withdraw assets immediately until the team confirms the exploit is fully patched and details are disclosed.
The recent hack adds pressure on DeFi bridges, whose complexity and cross-chain nature continue to attract sophisticated attacks. Garden Finance’s repeated setbacks reflect wider challenges in securing cross-chain protocols, an issue that remains critical as decentralized finance grows more interconnected.



