Garden Finance took its app offline this week after security firm Blockaid reported an exploit that drained roughly $450,000 in USDT from its HTLC contracts. The attack hit four blockchains — Ethereum, Base, Arbitrum, and BNB Smart Chain — before the team could respond. The move left users unable to access the platform as the team scrambled to assess the damage.
Blockaid flags the attack
Blockaid, a security platform that monitors on-chain threats, said it detected the exploit and alerted Garden Finance. The firm reported that an attacker managed to pull about $450,000 in USDT from the project's HTLC contracts. HTLC — or hash time-locked contracts — are a common tool in cross-chain and atomic swap protocols, but they can be vulnerable if not properly secured.
The HTLC contracts targeted
The exploit didn't just hit one chain. It spread across Ethereum, Base, Arbitrum, and BNB Smart Chain, suggesting the attacker found a flaw that applied to all of Garden Finance's deployments. HTLC contracts rely on cryptographic hashlocks and timeouts; if an attacker can manipulate the lock or the refund path, they can siphon funds before the legitimate user claims them. Blockaid didn't release technical details of the exact method, but the multi-chain nature points to a systemic issue rather than a single misconfiguration.
App disabled, users wait
Garden Finance disabled its app shortly after the report. The team hasn't said when it will be back online or whether affected users will be reimbursed. For now, the app remains down, and the $450,000 hole is a reminder that even well-audited DeFi protocols can get caught off guard. The timing isn't great — the broader market has been shaky, and a high-profile exploit can spook liquidity providers.
The team has not yet published a post-mortem or announced a timeline for reopening. Users are left watching the project's social channels for updates.




