$450K Drained as Blockaid Flags Ongoing Garden Finance Exploit
Blockaid, a web3 security firm, has flagged an ongoing exploit targeting Garden Finance's smart contracts. The attack is draining USDT from HTLC (Hash Time Locked Contracts) across four EVM-compatible blockchains: Ethereum, Base, Arbitrum, and BNB Chain.
The $450,000 figure represents the amount siphoned off so far, with the attack still ongoing at the time of detection. This incident follows a separate breach in late 2025 that resulted in losses between $10.8 million and $11 million.
Garden Finance uses HTLCs to facilitate cross-chain atomic swaps, which are essentially digital escrow boxes with a countdown timer. The attacker was able to drain USDT directly from these contracts across multiple chains simultaneously, suggesting a vulnerability in the contract logic or deployment process.
The multi-chain nature of the exploit indicates that this is not a simple one-off bug on a single deployment but rather a more fundamental issue. This latest attack means Garden Finance has now experienced different types of attacks on various layers of its infrastructure.