Blockaid detects $450,000 security breach prompting Garden Finance to shut down platform

Blockaid detects $450,000 security breach prompting Garden Finance to shut down platform

After blockchain security company Blockaid identified an active security breach that resulted in the extraction of approximately $450,000 worth of USDT spanning four different blockchain networks, Garden Finance has temporarily disabled access to its application.

Following reports from blockchain security company Blockaid regarding a security breach affecting the protocol's hash time-locked contracts (HTLC) distributed across four separate blockchain networks, Garden Finance, a cross-chain bridging and atomic swap protocol, has temporarily disabled its application platform.

According to Blockaid's announcement on Sunday, an unauthorized actor successfully extracted approximately $450,000 worth of USDT from Garden's HTLC contracts deployed on Ethereum, Base, Arbitrum and BNB Smart Chain networks. HTLCs represent time-bound escrow smart contracts that Garden Finance employs to enable atomic swaps between Bitcoin and digital assets on alternative blockchain networks.

At the time Blockaid published its security warning, the firm characterized the security breach as actively ongoing but chose not to reveal details about the suspected security vulnerability or clarify whether individual user funds had been compromised. The security alert issued by Blockaid contained wallet addresses linked to the malicious actor and the compromised smart contracts.

In a separate statement, Garden acknowledged it had identified "unusual activity" and announced it was undertaking a comprehensive investigation while keeping its application temporarily unavailable to users.

Both Garden Finance and Blockaid have received and acknowledged Cointelegraph's inquiries requesting additional comments on the matter.

This security incident comes after a previous breach that occurred in October 2025, during which a malicious actor successfully extracted approximately $11.4 million following the compromise of the operational environment belonging to one of Garden's solvers. According to Garden's statement regarding that earlier breach, it did not compromise the protocol's smart contracts and did not expose user funds to risk.

← Back to Blog