Garden Finance Hack
What happened
On July 26, 2026, cross-chain atomic swap protocol Garden Finance suffered a supply chain compromise affecting its Hash Time-Locked Contracts (HTLC), resulting in an initial drain of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, BNB Chain, and Solana.
The exploit was an off-chain supply chain attack rather than a direct smart contract code vulnerability. An attacker compromised the off-chain database of an independent solver integrated with Garden Finance and injected forged transaction records. Because the protocol relies on solver state data to process cross-chain atomic swaps between Bitcoin and EVM/Solana networks, these fraudulent records deceived the HTLC contracts into releasing escrowed USDT assets directly to the attacker without valid matching inputs.
Garden Finance immediately took its front-end web application offline to prevent further improper fund releases, confirming that while core smart contracts remained secure, the breach stemmed entirely from off-chain solver infrastructure.
EVM Attacker Address: 0x25b224c0…316999
Solana Attacker Address: WZy4xxpqktWa1b6MPMRiWsD487CT8mDcapB6GufBJCH
Example EVM Exploit Transaction: 0x9d7a961a…29d395
Case & protocol details
Market Context at Time of Hack
Security review history
- OtterSec Report
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.