Tangled yellow cables on a dark blue background
Crypto

Garden Finance pauses app after Blockaid flags ~$450K USDT drain from HTLCs

Garden blames a solver’s off-chain database breach and says protocol contracts and user funds were not impacted.

By AI News Crypto Editorial Team4 min read

Garden Finance took its app offline on July 27 after a security incident tied to its atomic-swap flow. Blockaid estimated roughly $450,000 in USDT was drained from HTLCs across four chains, while Garden said the losses were limited to solver-owned funds.

Key Takeaways

  • Garden Finance paused its app after detecting activity it attributes to fraudulent swap records inserted via a solver’s compromised off-chain database.
  • About $450,000 in USDT was drained from HTLCs on Ethereum, Base, Arbitrum and BNB Smart Chain, and the activity was described as ongoing.
  • Garden said its protocol and HTLC smart contracts were not compromised and stated no user funds were lost or put at risk.
  • The team is still confirming totals and scope and is working with zeroShadow, Quantstamp and Blockaid while services remain paused pending security checks.

Garden Finance Takes App Offline After Reported HTLC USDT Drain

Garden Finance temporarily disabled its app after an incident that intersected directly with its hash time-locked contract (HTLC) swap rails. Blockaid estimated that an attacker drained about $450,000 in USDT from Garden’s HTLCs on Ethereum, Base, Arbitrum and BNB Smart Chain, and characterized the exploit as ongoing.

Operationally, the immediate impact is downtime. For traders using atomic swaps, that matters more than the post-mortem narrative in the first hours. Even if the protocol’s on-chain code is intact, the system can still be forced offline when execution infrastructure is in question.

HTLCs are time-bound escrow contracts used to facilitate atomic swaps between Bitcoin and assets on other networks. Garden relies on a network of independent “solvers” to help execute swaps, which introduces off-chain dependencies alongside on-chain settlement.

Two Competing Narratives: On-Chain HTLC Drain vs. Off-Chain Solver Database Breach

Blockaid’s framing is straightforward: funds were drained from HTLCs across four chains, and the drain was still in progress at the time of its assessment. It also published addresses linked to the attacker and affected contracts.

Garden Finance’s explanation separates the on-chain symptom from the root cause. A spokesperson said neither the protocol nor its HTLC smart contracts were compromised. Instead, the attacker allegedly breached the off-chain database of an independent solver and inserted fraudulent transaction records, which caused the solver to release funds for swaps that “had not been funded by the counterparty.”

That distinction is not academic. If Garden’s account is accurate, the incident is a reminder that solver off-chain infrastructure can still trigger real on-chain fund releases, then force protocol-level pauses as a containment measure.

What’s Known, What’s Still Unconfirmed

Confirmed: the app is paused, USDT is the asset cited in the initial estimate, and the named networks are Ethereum, Base, Arbitrum and BNB Smart Chain. Garden also stated the incident was isolated to one solver’s off-chain infrastructure and that “Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” adding that losses were limited to solver-owned assets.

Unconfirmed: the final loss total, whether assets beyond USDT were involved, and whether additional networks are in scope. Garden said it is still confirming the total amount, assets and networks involved. Blockaid described the exploit as ongoing, but the packet provides no definitive stop-time or final accounting.

This leaves traders with a provisional blast radius. The loss figure and containment status should be treated as live variables until either party updates the situation.

Signals to Watch for Garden Finance pauses app after solver

The first signal is whether the “ongoing” label gets retired. That likely comes with updated attacker or affected-contract addresses and clearer confirmation that drains have stopped.

Second is Garden’s final accounting, including whether USDT was the only asset impacted and whether the four named chains are the complete set.

Third is the restart path. Garden said it expects to restore services shortly after completing security checks, but it has not set a timeline. Any stated milestones, partial re-enables, or constraints on solver participation will matter for near-term liquidity and execution reliability.

Finally, watch for changes to solver requirements or infrastructure controls. Garden pointed to a recent SOC 2 Type II attestation as evidence of investment in operational controls, but the practical question is whether solver-side standards tighten after this event.

Downtime Risk for Atomic-Swap Traders After a Second Solver-Linked Incident

I don’t need a smart-contract exploit to take this seriously. The threshold that matters is whether off-chain solver compromise can repeatedly cause on-chain releases and force the protocol to hit the kill switch, because that is a market-structure problem for anyone relying on atomic-swap execution.

This is also the second solver-environment incident Garden has referenced, after an October 2025 breach that it said resulted in about $11.4 million stolen following a solver operating-environment compromise. If solver security is the recurring failure mode, the real test is whether Garden responds with enforceable solver controls and a restart process that restores confidence in uptime, not just assurances about user funds.

Sources