Garden Finance Hit by Second Significant Security Incident
Blockaid, a Web3 security firm, has detected an ongoing exploit targeting Garden Finance's smart contracts. The attack, which is still active at the time of detection, has resulted in approximately $450,000 being drained from USDT across four EVM-compatible blockchains: Ethereum, Base, Arbitrum, and BNB Chain.
The exploit targets Garden Finance's use of Hash Time Locked Contracts (HTLCs), a mechanism for facilitating cross-chain atomic swaps. HTLCs are essentially digital escrow boxes with a countdown timer, which allows two parties to lock assets on different chains before the swap is completed. Blockaid identified that the attacker was able to drain USDT directly from these contracts across multiple chains simultaneously.
Garden Finance has experienced two significant security incidents in under a year, with this latest exploit appearing smaller than the $10.8 million to $11 million breach attributed to a compromised solver in late 2025. The protocol's multi-chain footprint and reliance on HTLCs for cross-chain swaps make it vulnerable to this type of attack.
Investors are advised to withdraw their funds until the exploit is confirmed as resolved and a thorough post-mortem has been published.