Warning lights are flashing once again in the cross-chain bridge sector. Hackers drained approximately $450,000 in USDT from Garden Finance’s HTLC contracts on Sunday, July 27, 2026. Initial reports from security platform Blockaid detected a flurry of exploit transactions spreading rapidly across four different networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
Blockaid even published the hacker’s wallet address, describing the draining process as still ongoing when their report first went live.
Yet the theft figure conceals a crucial detail: the hackers did not touch the application’s core code.
Vulnerability at the Third-Party Layer
Garden Finance operates as a protocol bridging cross-chain transactions, specifically enabling Bitcoin swaps with assets on other blockchains via atomic swap mechanisms. Their system relies on HTLC (hash time-locked contracts), a time-bound escrow contract that locks funds until transaction conditions are fulfilled.
In its official clarification, the Garden team emphasized that its HTLC smart contracts were not compromised at all. Instead, the hacker’s entry point was located in an off-chain database belonging to an independent solver - a third-party entity tasked with executing transactions within their ecosystem.
The hacker’s modus operandi was calculated. After successfully infiltrating the independent solver’s database, the attacker injected a series of falsified transaction records into the system. As a result, the solver’s infrastructure was duped into automatically releasing funds for fictitious swap orders, even though the counterparty had not deposited a single penny.
Because the exploit targeted the independent solver’s system, Garden fully assured that no retail user funds were lost or compromised. The entire hundreds-of-thousands-of-dollars hit purely drained the solver’s operational assets.
Not the First Incident
This third-party breach adds to a growing list of vulnerabilities across supporting infrastructure. In October 2025, a similar incident involving a security flaw in an independent solver occurred. At the time, attackers made off with approximately $11.4 million after compromising the operating environment of a solver.
To quell public concern, Garden pointed to its recently achieved SOC 2 Type II certification as evidence of its ongoing investment in defensive systems. Currently, Garden’s internal team is actively sifting through data to confirm the exact amount, asset list, and full network footprint traversed by the attacker.
Garden has also enlisted three tracking firms - zeroShadow, Quantstamp, and Blockaid - to trace the fund flows and explore opportunities to recover the solver’s stolen assets.
Even armored blockchain infrastructure appears to have blind spots. For crypto exchange developers, building bulletproof smart contracts is no longer sufficient if surrounding partner gateways can still be easily breached. For retail users, this serves as a stark reminder that platform security is often defined by its weakest link.
Reported by Cointelegraph.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




