Blockaid detects ongoing exploit draining $450K from Garden Finance across four chains

1 hour ago 1



Web3 security firm Blockaid has flagged an active exploit targeting Garden Finance’s smart contracts, with roughly $450,000 in USDT siphoned across four EVM-compatible blockchains. The attack hit contracts on Ethereum, Base, Arbitrum, and BNB Chain, and as of detection, it was still ongoing. For a protocol that already lost an estimated $10.8 million to $11 million in a separate breach late last year, this is starting to look less like bad luck and more like a pattern. What happened and how the exploit works Garden Finance uses Hash Time Locked Contracts, or HTLCs, to facilitate cross-chain atomic swaps. Think of HTLCs as digital escrow boxes with a countdown timer: two parties lock assets on different chains, and the swap only completes if both sides fulfill the conditions before time runs out. Blockaid identified that the attacker was able to drain USDT directly from these HTLC contracts across multiple chains simultaneously. The multi-chain nature of the exploit suggests this wasn’t a simple one-off bug on a single deployment, but rather a vulnerability in the contract logic itself or in how it was deployed across different networks. The $450,000 figure, while significant, is no...

Read Entire Article