Cross-chain bridge and atomic-swap protocol Garden Finance temporarily took its application offline on July 26 after blockchain security firm Blockaid flagged an active exploit that drained roughly $450,000 in USDT from its hash time-locked contracts (HTLCs) across Ethereum, Base, Arbitrum, and BNB Smart Chain.
Garden later clarified that the protocol and its HTLC smart contracts were not compromised, and that the incident was traced to a breach of one independent solver’s off-chain database.
Blockaid first raised the alarm in a post on X at 9:30 PM UTC on July 26, 2026, describing the incident as an ongoing exploit on Garden’s HTLC contracts. HTLCs are time-bound escrow contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. The firm followed up with a second post publishing the exploiter address and an example exploit transaction.
On-Chain Footprint of the Attacker
The exploiter address flagged by Blockaid is 0x25b….6999. Etherscan tagged the wallet with an exploit warning and shows the externally owned account holding approximately $424,707.21 across four chains with 20 transactions logged as of July 26, 2026, aligning with the four networks identified as affected: Ethereum, Base, Arbitrum, and BNB Smart Chain.
One of the example malicious transactions surfaced by Blockaid on Ethereum begins with the hash 0x9d7a961aa… and can be traced through Etherscan. The multi-chain nature of the drain, executed against contracts deployed across four EVM networks in quick succession, is what initially led on-chain observers to suspect a contract-level vulnerability rather than an operational breach.
Garden’s Response: Solver Database, Not Contracts
A few hours after the alert, Garden Finance posted on X that it had detected “unusual activity” and had paused the app as a precaution while a full investigation was underway.
In a subsequent statement, a Garden Finance spokesperson said neither the protocol nor its HTLC smart contracts were compromised. According to the team, the attacker breached the off-chain database of one independent solver in Garden’s network and inserted fraudulent transaction records. That caused the solver to release funds for swaps that were never actually funded by the counterparty on the other side of the trade.
Garden said no user funds were lost or placed at risk, and that the losses were limited to solver-owned assets. The company added that it is still confirming the exact amount, assets, and networks involved, and that services were paused so the affected infrastructure could be isolated and reviewed. Garden is working with security firms zeroShadow, Quantstamp, and Blockaid to trace and attempt to recover the funds.
Garden also pointed to its recent SOC 2 Type II attestation as part of its case that operational controls were in place before the incident. The team has not given a timeline for restoring services, saying only that the app will return once security reviews are complete.
A Second Incident in Under a Year
The July 26 event is the second known security incident to hit Garden Finance in under a year. In October 2025, Garden lost approximately $11.4 million after an attacker compromised the operating environment of one of its solvers on Arbitrum and other chains. Details are laid out in Garden’s own October 30, 2025 incident report, where co-founder Jaz Gulati stated the incident was limited to a single solver and did not affect the protocol itself.
That earlier breach came with heavier baggage. On-chain investigator ZachXBT attributed the attack to a DPRK-affiliated group tracked as DangerousPassword and stated that most of the freezable assets were rapidly swapped into ETH before any takedown could be coordinated.
Around the same time, ZachXBT and Tayvano publicly criticized Garden for processing sizeable volumes of illicit funds tied to earlier incidents including the Bybit and Swissborg hacks, alleging that a meaningful share of the protocol’s total flows had illicit provenance.
Garden’s smart contracts have been audited by Trail of Bits, OtterSec, and Zellic, and the protocol supports Bitcoin swaps into and out of Ethereum, Solana, Base, Arbitrum, and BNB Chain.
Wider Context: Bridges Remain the Softest Target
The Garden incident lands in a stretch where bridge and cross-chain infrastructure have been under sustained pressure. Just days earlier, Wanchain’s Cardano-BNB Chain bridge was drained of roughly 515.2 million NIGHT tokens due to a non-injective signed-message encoding flaw, and the Verus Ethereum Bridge was exploited for $7.54 million in a repeat attack on July 23 that abused the same submitImports path used in a May breach.
Weekly damage across confirmed incidents from July 19 to July 25, covering AFX Trade, Wanchain, Verus, Allbridge Core, B² Network, Lien Finance, and Robinhood’s compromised social account, has already been documented at more than $47 million, extending a first-half tally that CertiK put at over $1.31 billion across 344 incidents. Bridge-related losses alone crossed $328 million in 2026 even before this latest Garden event, according to PeckShield figures cited earlier in the year.
For Garden, the pattern is now specific: two incidents inside nine months, both traced to solver-layer infrastructure rather than the audited contracts. The protocol’s core defense, that HTLCs and user funds were untouched, holds up on-chain. But it also underscores that the security perimeter of a modern atomic-swap system extends well past its smart contracts and into the databases, keys, and operational stacks of the third-party solvers that quote and settle its trades.
Garden has not confirmed which solver was affected or how the attacker gained access to its off-chain database. The app remained offline at the time of writing.
Also Read: Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit
