Login
Sign Up
Woofun AI reports that Garden Finance temporarily disabled its application interface after Blockaid identified a significant exploit targeting the protocol’s hash time-locked contracts (HTLC) across multiple blockchain networks.
The attack, detected on Sunday, resulted in the drainage of approximately $450,000 in USDT from Garden’s HTLC contracts deployed on Ethereum, Base, Arbitrum, and BNB Smart Chain. These contracts are critical infrastructure used by the protocol to facilitate atomic swaps between Bitcoin and assets residing on other networks. Blockaid classified the exploit as ongoing at the time of its alert, though it withheld details regarding the specific suspected vulnerability. The security firm also did not clarify whether the incident directly compromised user funds, but it did publish the wallet addresses associated with the attacker and the affected contracts for transparency.
Woofun AI data shows that in response to the incident, Garden Finance stated that it had detected "unusual activity" and initiated a full investigation while keeping its app offline. Both Garden Finance and Blockaid acknowledged the request for comments regarding the breach. This event marks a recurring security challenge for the protocol, following a major breach in October 2025 where an attacker stole roughly $11.4 million. That previous incident involved the compromise of the operating environment of one of Garden’s solvers, which the company asserted did not affect its protocol contracts or put user funds at risk.
The current halt in operations underscores persistent vulnerabilities in cross-chain bridging mechanisms. With user funds potentially at risk and the technical root cause still under investigation, the incident highlights the ongoing fragility of atomic swap infrastructure.