What Happened To Garden Finance?

Garden Finance temporarily took its app offline after an attacker compromised the off-chain database of an independent solver and inserted fraudulent transaction records, causing the solver to release funds for swaps that had not been funded by the counterparty.

Blockchain security firm Blockaid initially estimated that about $450,000 in USDT had been drained from hash time-locked contracts linked to Garden across Ethereum, Base, Arbitrum and BNB Smart Chain. It described the incident as ongoing and published addresses associated with the attacker and affected contracts.

Garden later said its protocol and HTLC smart contracts were not compromised. The company said the breach was limited to the off-chain infrastructure operated by one solver and affected only assets belonging to that solver.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company said, adding that the affected infrastructure had been isolated while the incident was investigated.

Garden is still confirming the total value of the loss, the assets involved and the networks affected. Services were paused as a precaution while security checks and infrastructure reviews were completed.

How Did The Solver Release Unfunded Swaps?

Garden uses a network of independent solvers to help execute atomic swaps between Bitcoin and assets on other blockchains. Atomic swaps allow two parties to exchange assets without relying on a centralized custodian to hold both sides of the transaction.

The protocol uses HTLCs, which are time-bound escrow contracts designed to release assets only when specific cryptographic conditions are met. Garden’s explanation indicates that the attacker did not alter those contracts. Instead, fraudulent information was inserted into an off-chain database used by one solver to track whether counterparties had funded their side of a swap.

The manipulated records caused the solver to treat unfunded transactions as valid and release its own assets. This distinction matters because it separates a compromise of an operator’s supporting infrastructure from a flaw in the protocol’s on-chain contracts.

However, the incident still shows how off-chain systems can create financial exposure even when smart contracts perform as designed. Solvers, market makers and bridge operators often rely on databases, transaction monitoring tools and internal approval systems that sit outside the blockchain. A weakness in any of those components can undermine the safeguards built into the on-chain settlement process.

Investor Takeaway

Garden’s contracts were not breached, but the incident shows that cross-chain protocols remain dependent on off-chain operators and databases. Users and liquidity providers must assess the security of the full transaction process, not only the underlying smart contracts.

When Will Garden Restore Services?

Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace the stolen funds and support recovery efforts. The company expects to restore services after completing the required security checks, although it did not provide a specific reopening time.

Its immediate priorities include securing the affected systems, determining the full scope of the loss and confirming that other solvers in the network were not exposed to the same weakness. The app is expected to remain unavailable until those reviews are complete.

Garden also cited its SOC 2 Type II attestation as evidence of its investment in operational and security controls. Such attestations assess whether a company has established and maintained controls around areas including security, availability and data handling, but they do not eliminate the possibility of attacks on individual systems or third-party operators.

The decision to pause services reduces the risk of further losses while the company investigates, but prolonged downtime could affect swap volumes and user confidence. The speed and detail of Garden’s final incident report will be important for determining whether the breach was isolated to one solver or exposed a weakness that requires changes across the wider network.

Why Does The Previous Solver Breach Matter?

The latest incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of another Garden solver. Garden also said at the time that its protocol contracts were unaffected and user funds were not placed at risk.

The recurrence of an attack involving solver infrastructure may increase scrutiny of how independent operators are selected, monitored and secured. A decentralized solver network can reduce reliance on a single intermediary, but it also creates several separate operational environments that must maintain adequate security standards.

Garden may therefore face pressure to introduce stronger database authentication, transaction verification and safeguards preventing a solver from releasing funds based solely on off-chain records. Independent confirmation that the counterparty has funded a swap could reduce the risk of similar false entries triggering payments.

For the wider cross-chain sector, the case adds to concerns that attackers are moving beyond smart contract vulnerabilities and targeting the supporting infrastructure around bridges and atomic swap systems. The final loss may be limited to solver-owned assets, but repeated operational breaches can still weaken liquidity and make professional counterparties more cautious about committing capital.