Monday, July 27, 2026

Garden Finance Pauses App After $450K Solver Exploit

Cross-chain hub scene showing paused app banner and breaking links across Ethereum, Arbitrum, and BNB Smart Chain.

Garden Finance paused its cross-chain swap application after detecting unusual activity on July 26. Blockaid tracked approximately $450,000 in USDT leaving Garden-linked HTLC contracts across Ethereum, Base, Arbitrum and BNB Smart Chain.

Garden later attributed the loss to the off-chain database of one independent solver, rather than a compromise of its protocol or HTLC smart contracts. The attacker allegedly inserted fraudulent transaction records that caused the solver to release assets for swaps that counterparties had not funded.

Solver Operations Became the Primary Attack Surface

Garden uses an open network of independent solvers to supply liquidity and execute cross-chain orders. Users and solvers lock assets through Hashed Timelock Contracts, which are designed to complete both sides of an atomic swap or return funds when settlement conditions are not met.

In this incident, the contracts reportedly processed instructions derived from corrupted off-chain records. That distinction matters because audited smart contracts can continue functioning as designed while external databases, credentials or transaction-monitoring systems cause an operator to authorize an economically invalid payment.

Garden said no user funds were lost or placed at risk, with the exposure limited to assets owned by the affected solver. The protocol is still confirming the precise loss, asset composition and full network footprint, so the $450,000 estimate remains preliminary.

App Recovery Depends on Wider Security Review

The application was taken offline to isolate the affected infrastructure and examine whether other solvers shared the same weakness. Garden has engaged Blockaid, Quantstamp and zeroShadow to trace the transferred assets and assist with recovery, but no reopening time has been published.

The incident exposes a broader dependency inside intent-based and solver-driven protocols. Non-custodial settlement can protect users from pooled bridge-custody risk, but liquidity providers still depend on secure databases, signing environments and internal verification systems before releasing their own capital.

Garden faces an operational security failure at the solver layer rather than a confirmed HTLC contract exploit. The next critical disclosures will be the final loss calculation, database-compromise method, solver-control changes, fund-recovery results and confirmation that the application can resume without exposing other independent operators.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.