Jul 27, 2026 · 8:00 AM
Subscribe
Home Crypto

Garden Finance shuts down after a $450,000 exploit hits its solver layer, not its protocol

Garden Finance disabled its app on July 27 after Blockaid detected an active $450,000 HTLC drain across Ethereum, Base, Arbitrum, and BNB Smart Chain. The protocol's smart contracts were untouched , the attacker compromised an independent solver's off-chain database, the second time Garden's solver layer has been the attack vector in under a year.

Julian Lim
· 5 min read · 528 reads
Garden Finance shuts down after a $450,000 exploit hits its solver layer, not its protocol

Garden Finance says its contracts and user funds were not hit, but a solver database compromise still drained about $450,000 across four chains.

Garden Finance took its app offline after Blockaid flagged an active drain from its HTLC contracts across Ethereum, Base, Arbitrum, and BNB Smart Chain. According to Cointelegraph's report on the July 26 incident, the attacker took about $450,000 in USDT. The protocol held. The solver didn't.

That's the awkward part. Garden is a cross-chain Bitcoin swap protocol built around atomic swaps, with independent solvers supplying liquidity and executing orders through hash time-locked contracts. In normal language, the solver is the actor that fronts capital so your swap can complete without Garden taking custody of your funds. If that solver's own records are corrupted, the contracts can still behave as designed while money walks out the door.

The breach was not where users usually look

Garden said the attacker didn't compromise the HTLC smart contracts or the core protocol. The breach, by its account, sat in an independent solver's off-chain database. The attacker inserted fraudulent transaction records, and the solver released funds it believed had been legitimately claimed. No reentrancy bug was needed. No faulty access control had to fail. Someone just changed the book the solver was reading.

If you judge a bridge only by its audit badges, you miss the part of the system that actually moves under pressure. Garden's own FAQ says its smart contracts and solver infrastructure have been audited by Trail of Bits, OtterSec, and Zellic. That still didn't make a solver database immune to compromise. An audit can tell you something useful about code. It can't tell you enough about every server, operator account, database, and runbook sitting around that code.

This is also not Garden's first solver-layer failure. On October 30, 2025, an attacker gained unauthorized access to one of Garden's largest independent solver operators and drained approximately $11.4 million in crypto assets across multiple chains, according to Garden's own January incident report. The report said no user funds were at risk and no Garden protocol contracts were compromised. Good. But losing solver-owned assets twice in nine months is still a pattern you can't wave away.

The January report also gave the kind of dull technical detail that matters. Garden said Ernst and Young reviewed the incident and found suspicious SSH access from four IP addresses with indicative locations in Japan and China on October 30. Garden said the stolen funds were later consolidated, bridged, swapped, and deposited into Tornado Cash. It also said zeroShadow linked the laundering patterns with high confidence to a North Korea-affiliated threat actor known as DangerousPassword.

The October loss was larger. This one was cleaner to explain.

Blockaid caught it while it was happening

Blockaid's role here is the better part of the story, although not a happy one. The security firm detected the drain while it was active across four chains, rather than after the funds had already vanished into a post-mortem thread. That's real progress for DeFi monitoring. It still didn't stop the roughly $450,000 from leaving.

You should be careful with that distinction. Real-time detection isn't the same thing as prevention, and the Garden incident shows the gap clearly. Blockaid can identify malicious movement. Garden can take the app down. The money is still gone unless the attacker returns it or investigators recover it - and security firms tracing funds after the fact, with zeroShadow and Quantstamp, doesn't change that.

Garden stressed again that user funds were not at risk because the losses came from solver-owned inventory. That is an important fact, and it should stay in the story. It doesn't make the incident harmless. Solvers are not decorative pieces in a cross-chain protocol. They are the part that makes the swap work at all - liquid, usable, fast enough that you don't notice the machinery. If their infrastructure is weak, your experience can break even when the protocol's contracts remain untouched.

Frankly, this is where a lot of DeFi security language becomes too tidy. Users are told to look for audits and contract verification, maybe a non-custodial design. Useful checks, all of them. But not the whole risk surface. Solvers, relayers, oracles, sequencers, database workers, admin panels, alert systems, you name it: the machinery around the contract often decides what happens when something goes wrong.

According to Cointelegraph, Garden said it was working with Blockaid, zeroShadow, and Quantstamp to trace and recover the funds, and the app would return after security checks were completed. No restart timeline had been announced in the reports available on July 27.

The cleanest version of Garden's argument is true: the protocol didn't lose user funds. The harder version is true as well: a protocol can be technically intact and still leave its users waiting because an operator layer failed. That is the risk cross-chain apps need to explain before the next solver gets hit.

Also read: Samsung is putting stablecoin support in Galaxy Wallet and 241 million phones are the distribution playStorj Labs filed for Chapter 11 bankruptcy and token holders are last in lineSberbank is building a crypto exchange faster than Russia can pass the law that permits one

TOPICS
Julian Lim is an entrepreneur, technology writer, and a researcher. He started JL Data Analysis after graduating from NUS in Intelligent Systems. Julian writes about technology innovations and entrepreneurship on Business Times, Asia Pacific Magazine and occasionally contributes to Startup Fortune.
Related Articles
More posts →
Loading next article…
You're all caught up