Garden Finance took its app offline following a security breach that led to fraudulent swap data insertion, but no user funds or smart contracts were compromised. The breach stemmed from an attacker targeting an independent solver’s off-chain database.
Details of the Incident
The attacker managed to compromise the off-chain system that Garden Finance relies on for processing swaps. By injecting fake swap records, they created an exploit reportedly worth $450,000. Garden Finance quickly disabled the app as a precautionary measure to investigate and prevent further damage.
Impact and Response
Despite the sizeable exploit, Garden Finance confirmed that users’ funds remained safe, and their smart contracts were untouched. The breach raises questions about the security of off-chain components interacting with decentralized finance platforms. Prompt detection and response arguably minimized potential losses.



