Garden Finance paused its cross-chain swap application after detecting unusual activity on July 26. Blockaid tracked approximately $450,000 in USDT leaving Garden-linked HTLC contracts across Ethereum, Base, Arbitrum and BNB Smart Chain.
Garden later attributed the loss to the off-chain database of one independent solver, rather than a compromise of its protocol or HTLC smart contracts. The attacker allegedly inserted fraudulent transaction records that caused the solver to release assets for swaps that counterparties had not funded.
we identified unusual activity on garden today and are looking into it.
the app is temporarily offline while we complete a full investigation.
we'll share updates as soon as we have more information.
— Garden 🌸 (@gardenfi) July 26, 2026
Solver Operations Became the Primary Attack Surface
Garden uses an open network of independent solvers to supply liquidity and execute cross-chain orders. Users and solvers lock assets through Hashed Timelock Contracts, which are designed to complete both sides of an atomic swap or return funds when settlement conditions are not met.
In this incident, the contracts reportedly processed instructions derived from corrupted off-chain records. That distinction matters because audited smart contracts can continue functioning as designed while external databases, credentials or transaction-monitoring systems cause an operator to authorize an economically invalid payment.
Garden said no user funds were lost or placed at risk, with the exposure limited to assets owned by the affected solver. The protocol is still confirming the precise loss, asset composition and full network footprint, so the $450,000 estimate remains preliminary.
App Recovery Depends on Wider Security Review
The application was taken offline to isolate the affected infrastructure and examine whether other solvers shared the same weakness. Garden has engaged Blockaid, Quantstamp and zeroShadow to trace the transferred assets and assist with recovery, but no reopening time has been published.
The incident exposes a broader dependency inside intent-based and solver-driven protocols. Non-custodial settlement can protect users from pooled bridge-custody risk, but liquidity providers still depend on secure databases, signing environments and internal verification systems before releasing their own capital.
Garden faces an operational security failure at the solver layer rather than a confirmed HTLC contract exploit. The next critical disclosures will be the final loss calculation, database-compromise method, solver-control changes, fund-recovery results and confirmation that the application can resume without exposing other independent operators.
