Crypto加密

Garden Finance app taken offline after $450,000 USDT drain from HTLC contracts

Cross-chain DeFi protocols have been a recurring attack surface through this cycle, and the pattern held again. Blockaid reported that an attacker drained approximately $450,000 in USDT from Garden Finance by exploiting the…

By Dev Okafor·July 27, 2026·二〇二六年七月二十七日·2 min read

HONG KONGJuly 27, 2026

Cross-chain DeFi protocols have been a recurring attack surface through this cycle, and the pattern held again. Blockaid reported that an attacker drained approximately $450,000 in USDT from Garden Finance by exploiting the protocol's hash time-locked contracts (HTLCs), the locking mechanisms that hold funds in escrow during atomic swaps. Garden Finance disabled its application in response.

What moved on-chain

The exploit ran across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain, according to Blockaid. That breadth is worth reading carefully. A single-chain attack typically points to one weak deployment. Four chains means either a shared logic flaw was replicable across every Garden Finance deployment, or the attacker held valid claim conditions on all four networks at once.

HTLCs function like this: one party locks funds in a contract, and the counterparty claims them by revealing a cryptographic secret before a timer expires. When the mechanism works, it enables trustless cross-chain swaps without a custodian in the middle. When it does not, the contract is a container of other people's money with a countdown attached.

Blockaid, which monitors transactions for malicious activity in real time, identified the drain and named USDT as the extracted token.

The sector read-through

Against the backdrop of a DeFi cycle that has repeatedly stressed cross-chain infrastructure, this incident follows a shape the desk has seen before. Atomic swap protocols hold user funds at the moment of peak exposure: in transit, time-locked, waiting on a cryptographic condition. That window is where attackers concentrate.

The $450,000 figure is contained by the standards of prior bridge and atomic-swap exploits, but the mechanism is the same one that has cost the sector far larger sums across two cycles. The question the source does not yet answer is whether Garden Finance's HTLC logic contained a flaw allowing the attacker to satisfy claim conditions without being the intended recipient, or whether some other vector opened the door. Garden Finance has not disclosed the specific vulnerability per the available reporting.

The application remains offline as of Blockaid's disclosure.

Related reading

Source · 來源

NewsHK

Share · 分享

Key takeaways

Frequently asked

How much was stolen from Garden Finance and in what token?

An attacker drained approximately $450,000, and the extracted token was USDT.

How did the attacker carry out the exploit?

The attacker exploited Garden Finance's hash time-locked contracts (HTLCs), the locking mechanisms that hold funds in escrow during atomic swaps.

Which blockchains were affected by the attack?

The exploit ran across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

How did Garden Finance respond to the incident?

Garden Finance disabled its application, which remained offline as of Blockaid's disclosure.

Has Garden Finance explained the specific vulnerability?

No, Garden Finance has not disclosed the specific vulnerability per the available reporting.