Garden Finance has taken its app offline after blockchain security firm Blockaid reported an active exploit affecting the protocol’s hash time-locked contracts, or HTLCs, on multiple networks. According to Blockaid, roughly $450,000 in USDT was drained from those contracts.
Exploit reported across four networks
Blockaid said the attack targeted Garden Finance HTLC contracts on Ethereum, Base, Arbitrum and BNB Smart Chain. The security firm described the exploit as ongoing at the time it published its alert.
The reported losses totaled about $450,000 in USDT. Blockaid did not publicly identify the suspected vulnerability behind the attack, and it did not say whether user funds were impacted by the incident.
What the contracts do
Garden uses HTLCs as time-bound escrow contracts to enable atomic swaps between Bitcoin and assets on other blockchains. These contracts are designed to coordinate swaps across networks by setting conditions and deadlines for settlement.
Because the reported exploit centered on HTLC infrastructure spanning four chains, the incident raised immediate concerns around a core component of how Garden facilitates crosschain swaps.
Garden response
Garden said separately that it had detected “unusual activity” and was carrying out a full investigation. While that process continues, the app remains offline.
The project did not provide further public details in the source report about the cause of the exploit or the scope of any potential impact beyond the activity identified by Blockaid. As a result, key questions — including whether the issue touched user funds — remained unresolved at the time of publication.
Previous breach in 2025
The latest incident comes after a separate security breach disclosed in October 2025. In that case, an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers.
Garden said at the time that the 2025 breach did not affect its protocol contracts and did not put user funds at risk. The newly reported exploit is different in that Blockaid said it involved HTLC contracts directly, though no additional technical explanation was provided in the source article.
The back-to-back security incidents place renewed attention on the risks around crosschain infrastructure and operational components tied to swap protocols. For now, Garden’s app remains offline while the investigation continues, with the available public information limited to Blockaid’s estimate of the losses, the networks involved and Garden’s acknowledgment of unusual activity.
Source: cointelegraph.com