Garden Finance Halted After $450K USDT Exploit Hits Four Blockchains
Garden Finance temporarily shut down its application after discovering an exploit that drained approximately $450,000 in USDT from its hash time-locked contracts (HTLCs) across four blockchain networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
The incident was flagged by blockchain security firm Blockaid, which described it as an ongoing exploit on Garden's HTLC contracts. The exploiter address flagged by Blockaid is 0x25b….6999, holding approximately $424,707.21 across the four chains with 20 transactions logged.
Garden Finance clarified that neither the protocol nor its HTLC smart contracts were compromised; instead, an attacker breached the off-chain database of one independent solver in Garden's network and inserted fraudulent transaction records, causing the solver to release funds for swaps that were never actually funded by the counterparty on the other side of the trade.
Garden said no user funds were lost or placed at risk, but losses were limited to solver-owned assets. The company is working with security firms zeroShadow, Quantstamp, and Blockaid to trace and attempt to recover the stolen funds.