"Our smart contracts and user funds remain secure," a Garden Finance spokesperson emphasized as the protocol took its app offline following an off-chain breach linked to one of its independent solvers. The attacker targeted the solver's database, injecting fake transaction data that caused unauthorized releases of assets, yet the protocol’s core infrastructure stood firm.
Blockchain security firm Blockaid reported that approximately $450,000 in USDT was siphoned from Garden Finance’s hash time-locked contracts (HTLCs) across Ethereum, Base, Arbitrum, and BNB Smart Chain. The exploit went active before being contained, with affected wallet addresses disclosed publicly. Garden promptly engaged security experts from zeroShadow, Quantstamp, and Blockaid to trace stolen funds and bolster recovery efforts.
While HTLCs are designed as escrow contracts facilitating atomic swaps by locking funds until certain conditions are met, Garden clarified that these smart contracts functioned without compromise. The breach originated solely from the solver’s off-chain infrastructure. Manipulated transaction records triggered fund releases for swaps never initiated by counterparties, underlining the vulnerability of external components integrated into DeFi protocols.
The company is currently verifying the full scope of losses, including affected assets and blockchains. This incident follows a similar solver breach earlier in 2025, reflecting ongoing challenges in securing hybrid on-chain/off-chain systems. As crypto security researchers continue monitoring exploits, Garden’s swift response highlights the necessity of isolating risks away from user funds.


