TLDR
- Garden Finance temporarily suspended its app after a solver’s off-chain database was breached
- Attackers drained roughly $450,000 in USDT across Ethereum, Base, Arbitrum and BNB Chain
- Garden says its HTLC smart contracts and user funds were not affected
- The stolen funds belonged to the compromised solver, not users
- Garden is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds
Garden Finance, a cross-chain bridge and atomic swap protocol, took its app offline on July 27 after a security breach hit one of its independent solvers.
🚨UPDATE: Garden Finance has shut down its app as a precaution, confirming that no user funds or smart contracts were affected. https://t.co/aFdBh4PWRV
— Coin Bureau (@coinbureau) July 27, 2026
The company said the attacker broke into the off-chain database of one solver in its network. The attacker then inserted fake transaction records, tricking the solver into releasing funds for swaps that had never actually been funded by the other side.
Blockchain security firm Blockaid reported the attacker drained around $450,000 in USDT. The affected chains include Ethereum, Base, Arbitrum and BNB Chain.
Garden Finance was quick to clarify that its protocol and hash time-locked contracts, known as HTLCs, were not compromised. HTLCs are the time-bound escrow contracts Garden uses to handle atomic swaps between Bitcoin and other networks.
The company said no user funds were lost or put at risk. The losses came entirely from assets owned by the affected solver.
Garden said it paused services as a precaution while it isolated and reviewed the affected infrastructure. It has not given a specific timeline for when services will resume.
Security Firms Brought In to Trace Funds
Garden Finance is working with three security firms to trace and recover the stolen assets. Those firms are zeroShadow, Quantstamp and Blockaid.
The company said services will only resume after the relevant security checks are completed. Garden also pointed to its recent SOC 2 Type II attestation as evidence of its security investment.
Second Solver Incident in Under a Year
This is not the first time Garden Finance has dealt with a solver breach. In October 2025, a similar incident led to around $11.4 million being stolen after an attacker compromised a solver’s operating environment.
Garden said that 2025 incident also did not affect protocol contracts or user funds.
The two incidents together show a recurring vulnerability in off-chain solver infrastructure rather than the core protocol itself.
Garden Finance is still verifying the exact total of losses, the specific assets involved and all networks affected.
Blockaid was first to flag the exploit publicly, describing it as ongoing and publishing addresses linked to the attacker.
Garden Finance has said its immediate focus is securing affected systems, tracing the stolen funds and ensuring a safe return to service.
The company has not said how much, if any, of the $450,000 has been recovered so far.







