Garden Finance app taken offline after $450,000 USDT drain from HTLC contracts
Cross-chain DeFi protocols have been a recurring attack surface through this cycle, and the pattern held again. Blockaid reported that an attacker drained approximately $450,000 in USDT from Garden Finance by exploiting the…
HONG KONG— July 27, 2026
Cross-chain DeFi protocols have been a recurring attack surface through this cycle, and the pattern held again. Blockaid reported that an attacker drained approximately $450,000 in USDT from Garden Finance by exploiting the protocol's hash time-locked contracts (HTLCs), the locking mechanisms that hold funds in escrow during atomic swaps. Garden Finance disabled its application in response.
What moved on-chain
The exploit ran across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain, according to Blockaid. That breadth is worth reading carefully. A single-chain attack typically points to one weak deployment. Four chains means either a shared logic flaw was replicable across every Garden Finance deployment, or the attacker held valid claim conditions on all four networks at once.
HTLCs function like this: one party locks funds in a contract, and the counterparty claims them by revealing a cryptographic secret before a timer expires. When the mechanism works, it enables trustless cross-chain swaps without a custodian in the middle. When it does not, the contract is a container of other people's money with a countdown attached.
Blockaid, which monitors transactions for malicious activity in real time, identified the drain and named USDT as the extracted token.
The sector read-through
Against the backdrop of a DeFi cycle that has repeatedly stressed cross-chain infrastructure, this incident follows a shape the desk has seen before. Atomic swap protocols hold user funds at the moment of peak exposure: in transit, time-locked, waiting on a cryptographic condition. That window is where attackers concentrate.
The $450,000 figure is contained by the standards of prior bridge and atomic-swap exploits, but the mechanism is the same one that has cost the sector far larger sums across two cycles. The question the source does not yet answer is whether Garden Finance's HTLC logic contained a flaw allowing the attacker to satisfy claim conditions without being the intended recipient, or whether some other vector opened the door. Garden Finance has not disclosed the specific vulnerability per the available reporting.
The application remains offline as of Blockaid's disclosure.
Related reading
Source · 來源