Garden Finance Goes Dark: Another $450K Exploit, Another Awkward Pattern
2026-07-27Garden Finance—a cross-chain bridging and atomic swap protocol—took its app offline this week after Blockaid, a blockchain security firm, caught someone red-handed draining about $450,000 in USDT from the protocol's hash time-locked contracts across four separate networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
HTLCs are time-bound escrow contracts. Garden uses them to facilitate atomic swaps between Bitcoin and assets elsewhere. Think of them as smart contract vending machines: you feed in one coin, wait for the timer, and out pops another. Blockaid flagged the exploit as active—meaning it was happening in real time—but kept the specific vulnerability under wraps. They did, however, share wallet addresses linked to the attacker and the compromised contracts.
Garden's response was measured. The team detected what they called "unusual activity," killed the app to stop the bleeding, and launched a full investigation. Standard damage-control protocol. What's less standard is the company's track record.
This isn't Garden's first rodeo. Back in October 2025, an attacker breached the operating environment of one of Garden's solvers and made off with about $11.4 million. Garden claimed that breach didn't touch the protocol contracts themselves or threaten user funds. Fair enough. But now, six months later, here we are again—bleeding another $450,000. That's starting to look less like a freak accident and more like a vulnerability estate sale.
The timing is awkward because Garden Finance actually has decent credentials on paper. Trail of Bits, OtterSec, and Zellic—three of the most respected security firms in the space—have all audited the protocol. So either those audits missed something fundamental in the HTLC architecture, or the vulnerabilities are emerging in how Garden operates the protocol rather than the code itself. Either way, it's a problem.
Cross-chain bridges are a special category of risk in crypto. They sit at the intersection of multiple blockchains, which means they inherit all the attack surface of every chain they touch. Garden spans Ethereum, Solana, Base, Arbitrum, and BNB Chain—five separate threat vectors. The more chains you span, the more moving parts. More moving parts means more potential failure modes.
Blockaid did the right thing flagging this early. The protocol's already been hit hard; it needs to plug holes, not hide them. But the bigger question lingers: when a protocol with blue-chip audits still gets exploited twice in six months, what does that say about the state of cross-chain infrastructure in general?
Garden Finance will likely recover from this particular incident. They'll patch, they'll audit again, they'll communicate. That's how these things go. But the question mark over their security posture—and by extension, over cross-chain bridges as a category—just got a lot bigger.
Source & further reading:
- Garden Finance disables app as Blockaid reports $450,000 exploit — Cointelegraph
- South Korea trading giant puts receivables onchain in tokenization test with LG CNS — CoinDesk
- 2 weeks left for Clarity: State of Crypto — CoinDesk
- U.S. regulator warns prediction markets against cutting corners in event contracts — CoinDesk
- Europe's high regulatory bar could spark new crypto industry M&A wave — CoinDesk
Sources
- Garden Finance disables app as Blockaid reports $450,000 exploit
- South Korea trading giant puts receivables onchain in tokenization test with LG CNS
- 2 weeks left for Clarity: State of Crypto
- U.S. regulator warns prediction markets against cutting corners in event contracts
- Europe's high regulatory bar could spark new crypto industry M&A wave