Garden Finance has temporarily taken its application offline after an attacker compromised the off-chain database of an independent solver, leading to the loss of solver-owned digital assets while leaving protocol contracts and user funds unaffected.

Summary

  • Garden Finance temporarily took its app offline after an independent solver’s off chain database was compromised, resulting in the loss of solver owned funds.
  • The protocol said its smart contracts and user funds were not affected because the attack was limited to one solver’s infrastructure.
  • Blockaid estimated the attacker drained about $450,000 in USDT from HTLC contracts across multiple blockchains before the incident was contained.
  • Garden has engaged zeroShadow, Quantstamp and Blockaid to trace the stolen assets and support recovery efforts.
  • The incident follows a similar 2025 solver breach and comes as crypto security researchers continue tracking multiple exploits across the sector.

Blockchain security firm Blockaid reported on Sunday that an attacker drained about $450,000 in USDT from Garden Finance’s hash time-locked contracts (HTLCs) deployed across Ethereum, Base, Arbitrum and BNB Smart Chain, describing the exploit as active while publishing wallet addresses linked to the attacker and the affected contracts.

Garden Finance later told Cointelegraph that the protocol itself had not been breached. Instead, the company said the incident originated from the off-chain infrastructure of an independent solver, where an attacker gained access to the solver’s database and inserted fraudulent transaction records that triggered releases of funds for swaps that had never been funded by the corresponding counterparty.

As a precaution, Garden temporarily took its application offline while engineers isolated the affected infrastructure and reviewed the incident. The protocol said no user funds were lost or exposed because only assets owned by the affected solver were involved.

The company added that it is still verifying the total amount lost, along with the exact assets and blockchain networks affected by the attack.

Off-chain solver targeted rather than protocol

While Blockaid initially associated the incident with Garden’s HTLC infrastructure, the protocol said its smart contracts continued operating as designed and were not exploited.

Garden explained that HTLCs serve as escrow contracts that enable atomic swaps between Bitcoin and assets on other blockchains by locking funds until predefined conditions are met or time limits expire. According to the company, those contracts remained secure throughout the incident.

Instead, Garden attributed the loss to manipulated records inside the compromised off-chain database used by one of its independent solvers. The fraudulent entries caused the solver to release funds for swaps despite the corresponding deposits never being completed.

According to Garden, the incident remained isolated to a single participant within its decentralized network of independent solvers rather than affecting the broader protocol.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph while emphasizing that only solver-owned assets were affected.

The protocol also noted that it does not control the infrastructure operated by independent solvers, which execute swaps within the network.

Recovery efforts underway with security firms

Garden said it has engaged blockchain security and incident response firms zeroShadow, Quantstamp and Blockaid to trace the stolen assets and support recovery efforts.

Alongside those investigations, the company said it expects to restore normal services after completing additional security reviews, although it has not provided a timeline for bringing the application fully back online.

The protocol added that its immediate priorities include securing the affected infrastructure, tracing the compromised solver’s assets and ensuring every required security check has been completed before services resume.

Garden also pointed to its recently completed SOC 2 Type II attestation, saying the certification demonstrates ongoing investment in operational controls and security processes even though the latest incident originated from infrastructure operated by an independent network participant.

The latest disclosure comes only days after Singapore-based stablecoin payments company Triple-A confirmed unauthorized access to company treasury wallets that resulted in the loss of corporate digital assets while customer funds remained unaffected.

According to Triple-A, the July 25 incident impacted only company-owned treasury assets because customer funds are held separately in safeguarded trust accounts rather than inside company wallets. The company temporarily placed certain services into maintenance mode before restoring normal payment operations after additional security checks.

Triple-A also said it is working with blockchain forensics specialists, cybersecurity experts and the Singapore Police Force to investigate the breach and trace the stolen assets. Although blockchain investigators estimated losses eventually reached about $11.8 million, the company has not confirmed the total amount or disclosed how the unauthorized access occurred.

Garden’s latest disclosure also follows an earlier security incident involving one of its independent solvers.

According to the protocol, an attacker compromised the operating environment of another solver in October 2025 and stole approximately $11.4 million. Garden said that the attack likewise did not affect its protocol contracts or place user funds at risk because the compromise remained limited to the solver’s operating environment rather than the protocol itself.

The latest attack adds to a series of security incidents reported across the cryptocurrency sector during 2026.

Last week, decentralized finance protocol Lien Finance disclosed the loss of approximately 542,144.63 USDC after attackers exploited weaknesses in its bond validation and pricing logic. Blockchain security firm SlowMist said the flaw allowed unsupported bond tokens to be minted and exchanged for real USDC liquidity without consuming the required collateral.



Source link

Shares:
Leave a Reply

Your email address will not be published. Required fields are marked *