TechNewsReel
Live

Garden Finance Shuts App After $450K HTLC Exploit Across Four Chains

Cross-chain bridge protocol suffers second major breach in under a year as Blockaid flags ongoing drain.

TechNewsReel Newsroom · July 27, 2026

Garden Finance disabled its app this week after security firm Blockaid detected an active exploit draining approximately $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Chain.

Blockaid flagged the exploit as ongoing at the time of reporting, indicating the final loss amount could exceed initial estimates. The attack targeted the protocol's Hashed Time-Lock Contract (HTLC) mechanisms directly.

Second Breach in Less Than a Year

This marks Garden Finance's second major security failure in under a year. In October 2025, the protocol suffered an estimated $10.8 million to $11 million loss stemming from a compromised solver's off-chain database. That earlier breach targeted infrastructure outside the smart contracts themselves.

The July 2026 exploit represents a distinct attack vector, striking the HTLC smart contracts directly. Blockaid did not disclose the specific vulnerability exploited within the contracts, and the attacker's identity remains unknown.

HTLCs and Cross-Chain Risk

Garden Finance operates as a cross-chain bridge protocol, using HTLCs to facilitate asset transfers between different blockchains. Hashed Time-Lock Contracts require recipients to provide cryptographic proof of payment within a specified timeframe, or the transaction reverts.

While the protocol disabled its application following Blockaid's alert, sources did not confirm whether user funds were directly impacted or whether the drained USDT originated from protocol reserves, liquidity pools, or user deposits.

Off-Chain Infrastructure Remains a Weak Point

The distinction between the two breaches highlights a vulnerability pattern in intent-based cross-chain architectures. Protocols in this category often rely on off-chain "solvers" to fulfill user transfer requests, introducing infrastructure outside the smart contract layer.

The October 2025 incident demonstrated how solver databases can become single points of failure. The July 2026 HTLC exploit shows that even when attack vectors shift to on-chain contracts, repeated breaches erode user confidence in a protocol's security posture.

Six independent outlets, including Cointelegraph and Crypto Briefing, confirmed the core details of the exploit. Garden Finance has not yet published a post-mortem or timeline for resuming operations.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.