Web3 security firm Blockaid has flagged an active exploit targeting Garden Finance’s smart contracts, with roughly $450,000 in USDT siphoned across four EVM-compatible blockchains. The attack hit contracts on Ethereum, Base, Arbitrum, and BNB Chain, and as of detection, it was still ongoing.
For a protocol that already lost an estimated $10.8 million to $11 million in a separate breach late last year, this is starting to look less like bad luck and more like a pattern.
What happened and how the exploit works
Garden Finance uses Hash Time Locked Contracts, or HTLCs, to facilitate cross-chain atomic swaps. Think of HTLCs as digital escrow boxes with a countdown timer: two parties lock assets on different chains, and the swap only completes if both sides fulfill the conditions before time runs out.
Blockaid identified that the attacker was able to drain USDT directly from these HTLC contracts across multiple chains simultaneously. The multi-chain nature of the exploit suggests this wasn’t a simple one-off bug on a single deployment, but rather a vulnerability in the contract logic itself or in how it was deployed across different networks.
The $450,000 figure, while significant, is notably smaller than the late 2025 incident. That earlier attack, attributed to a compromised solver (the network participants who actually execute the swaps), resulted in losses between $10.8 million and $11 million. Garden Finance claimed at the time that user funds were unaffected by that breach.
Garden Finance’s security track record
Garden Finance has undergone audits by Trail of Bits, OtterSec, and Zellic, three of the most respected security firms in the crypto space.
Garden Finance supports a multi-chain footprint, operating across Ethereum, Solana, Base, Arbitrum, and BNB Chain. The protocol’s core value proposition is enabling fast cross-chain swaps, particularly between Bitcoin and USDT.
The late 2025 breach was traced to a compromised solver rather than a smart contract vulnerability. This latest exploit appears to target the contracts themselves, which means Garden Finance has now experienced fundamentally different types of attacks on different layers of its infrastructure.
What this means for investors
The immediate concern for anyone with funds on Garden Finance is straightforward: get them out until the exploit is confirmed as resolved and a thorough post-mortem has been published. Blockaid flagged this as an ongoing attack, meaning the vulnerability may still be actively exploitable at the time of detection.
Garden Finance now carries the weight of two significant security incidents in under a year. The first cost roughly $11 million. This one appears smaller at $450,000.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

3 hours ago
7







English (US) ·