Blockchain security firm Blockaid reported an attacker drained about $450,000 in USDT from Garden Finance's hash time-locked contracts across Ethereum, Base, Arbitrum and BNB Smart Chain.
"An active exploit has been identified targeting Garden Finance's HTLC contracts across multiple EVM-compatible chains," Blockaid said in an alert on July 26. The firm shared addresses associated with the attacker and the affected contracts, describing the exploit as ongoing at the time of publication.
Garden Finance said separately it detected "unusual activity" and temporarily disabled its app while conducting a full investigation. The protocol uses HTLCs — time-bound escrow contracts that function like digital lockboxes with countdown timers — to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid identified that the attacker drained USDT directly from these contracts across four chains simultaneously, suggesting a vulnerability in the contract logic itself rather than a single deployment bug.
The exploit marks the second significant security incident for Garden Finance in under a year. In October 2025, an attacker stole roughly $11.4 million after compromising the operating environment of one of the protocol's solvers — the network participants that execute swaps. Garden said at the time that user funds were unaffected and that the breach did not involve its protocol contracts. The latest attack targets the contracts directly, meaning the protocol has now experienced fundamentally different types of breaches on separate layers of its infrastructure. Garden Finance has undergone audits by Trail of Bits, OtterSec, and Zellic, three of the most respected security firms in the crypto space. Blockaid and Garden Finance acknowledged requests for comment.
This article is for informational purposes only and does not constitute investment advice.