Garden Finance Hit by Ongoing Exploit Draining $450K Across Four Blockchains
Blockaid detected an ongoing exploit targeting Garden Finance's smart contracts, draining around $450,000 in USDT across four EVM-compatible blockchains. The attack hit contracts on Ethereum, Base, Arbitrum, and BNB Chain, with the vulnerability still active at detection.
The attacker exploited Hash Time Locked Contracts (HTLCs), a feature Garden Finance uses for cross-chain atomic swaps. HTLCs function as digital escrow boxes with a countdown timer: two parties lock assets on different chains, and the swap completes only if both sides fulfill conditions before time runs out.
Garden Finance has experienced two significant security incidents in under a year. The previous breach, attributed to a compromised solver, resulted in losses between $10.8 million and $11 million. This latest exploit targets the contracts themselves, raising concerns about Garden Finance's security track record.