Garden Finance Solver Layer Exploited for $450k in USDT Across Four Chains
Garden Finance, a cross-chain Bitcoin swap protocol, has taken its app offline after a $450,000 exploit hit its solver layer. The attack did not compromise the HTLC smart contracts or the core protocol itself.
The breach occurred in an independent solver's off-chain database, where the attacker inserted fraudulent transaction records and drained approximately $450,000 in USDT across four chains: Ethereum, Base, Arbitrum, and BNB Smart Chain.
Garden Finance noted that user funds were not at risk because the losses came from solver-owned inventory. However, this incident highlights a crucial aspect of DeFi security: solvers, relayers, oracles, sequencers, database workers, admin panels, and alert systems are often overlooked but play a significant role in determining what happens when something goes wrong.
Garden Finance has stated that it is working with Blockaid, zeroShadow, and Quantstamp to trace and recover the funds. This incident serves as a reminder that even technically intact protocols can leave their users waiting due to operator layer failures.