Key highlights:

  • Garden Finance says an independent solver suffered a security compromise, losing $450,000.
  • The protocol has set things in motion to recover the funds, tapping a raft of on-chain security companies.
  • Exploits have reached an all-time high in 2026, with Q2 becoming the worst quarter on record.

Cross-chain Bitcoin bridging protocol Garden Finance has disabled its services amid emerging reports of a security breach by bad actors. While Garden Finance claims no user funds were affected, an attacker siphoned $11.4 million from the protocol after a daring hack.

Garden Finance says the protocol is safe despite the report

According to on-chain security firm Blockaid, Garden Finance suffered an exploit to its hashed time-locked contract (HTLC) on Sunday. Consequently, bad actors drained $450,000 in USDT on Ethereum, Base, Arbitrum, and BNB Smart Chain.

HTLCs are smart contracts that lock cryptocurrency transactions using cryptographic puzzles and strict expiration times. It allows Garden Chain to facilitate atomic swaps between Bitcoin and assets on other networks it or safely returns the funds to their original owners.

However, Garden Finance revealed that its HTLC smart contracts were not compromised, arguing that the protocol is safe. Garden Finance clarified that the attacker gained access to an off-chain database of an independent solver, adding fraudulent transaction records to trigger a fund release.

The protocol added that no user funds were affected in the incidents. Per the statement, only the solver's funds were affected, with Garden Finance taking down the app pending a full postmortem.

“We identified unusual activity on Garden today and are looking into it,” read the statement. “The app is temporarily offline while we complete a full investigation.

Back in October 2025, an attacker stole nearly $11.5 million after exploiting one of Garden’s solvers. Following the incident, Garden Finance bolstered its security standards to prevent a repeat of the event.

Post-mortem of the October 2025 incident

Garden Finance races to recover the lost funds

According to a statement, Garden Finance has enlisted the services of onchain security firms Quantstamp, Blockaid and zeroShadow to recover the $450,000. Blockaid published the addresses linked to the attacker and affected contracts, with a postmortem underway.

Garden Finance added that it is focusing on securing the affected system to prevent any contagion risk. However, it is unclear when the full services will be restored on the app, with the project dispelling fears that it will join the list of crypto projects shutting down in 2026.

In the early hours of Monday, blockchain game platform Wemix suffered a smart contract exploit. Bad actors minted 5.2 million unauthorized WEMIX tokens, with Wemix suspending bridges and other services.

Last week, AFX Trade offered a deal to a hacker to keep 30% of stolen funds and return 70% of stolen funds in a rare arrangement. Crypto firms have lost over $1 billion in the first half of 2026 from hacks, with Q2 2026 recording the most incidents in history.