Garden Finance exploit drains $450,000 in crypto
A Garden Finance exploit saw attackers drain $450,000 in USDT across multiple blockchains, forcing the platform to disable its app.

Key Takeaways
- Garden Finance suffered a $450,000 exploit targeting HTLC contracts across four blockchains
- The Garden Finance exploit forced the platform to take its app offline to prevent further losses
- Cross-chain protocols carry elevated risk because they must coordinate security across multiple networks
A Garden Finance exploit has resulted in the loss of approximately $450,000 in USDT stablecoin, according to security firm Blockaid. The attacker drained funds from Garden Finance’s HTLC (Hashed Time-Locked Contract) smart contracts spread across Ethereum, Base, Arbitrum and BNB Smart Chain, prompting Garden Finance to immediately disable its application.
HTLC contracts are a specific type of blockchain program designed to lock assets temporarily, typically used in cross-chain bridges and swaps where different blockchains need to exchange value safely. The fact that the Garden Finance exploit targeted HTLC contracts specifically suggests the vulnerability lay in how these time-locked mechanisms were coded or protected.
Why cross-chain platforms are vulnerable
A Garden Finance exploit of this scale reveals a core challenge in decentralised finance: coordination across multiple blockchains. When a protocol like Garden Finance operates on four separate networks at once, it must maintain identical security standards on each one.
Single-chain platforms face one potential attack surface. A cross-chain protocol multiplies that risk. Attackers only need to find a weakness on one network to drain funds held in HTLC contracts across all of them. In this Garden Finance exploit, that weakness proved costly.
The speed of the attack also matters. Unlike traditional finance, where suspicious transactions might be flagged by human operators, blockchain transactions execute instantly and are permanent. By the time users or the platform noticed the Garden Finance exploit, the attacker had already withdrawn the funds.
The decision to disable Garden Finance’s app was a damage-control measure. It prevents the exploit from continuing to drain additional funds while the team investigates what went wrong and users cannot interact with the contracts.
What this tells us about smart contract risk
The Garden Finance exploit is not an isolated incident. Similar attacks on cross-chain bridges have occurred repeatedly across the crypto industry, often targeting the exact type of HTLC contracts involved here. In 2021, the Poly Network suffered an $611 million exploit. In 2023, the Ronin bridge lost $625 million.
These recurring breaches suggest that even widely-used contract designs can harbour critical flaws. Code audits, where external firms review smart contracts before launch, can catch many bugs, but not all.
Attackers who discover new vulnerabilities, as appears to have happened with the Garden Finance exploit, face a powerful incentive: they can drain funds instantly and move them across multiple blockchains before anyone can respond. The attacker here extracted $450,000 in USDT, a stablecoin pegged to the US dollar, meaning the funds retained their full value during the theft.
How do attackers find these vulnerabilities?
Some vulnerabilities are found through careful code analysis by skilled security researchers or attackers who study blockchain contracts line by line. Others emerge only under real-world conditions, when thousands of users interact with the code in ways the developers did not anticipate. The Garden Finance exploit may have revealed either type of flaw.
What this means for you
If you use decentralised finance platforms or hold assets in cross-chain protocols, the Garden Finance exploit illustrates practical risks to understand.
- Cross-chain platforms multiply your exposure to smart contract risk because they operate across multiple networks simultaneously, as the Garden Finance exploit demonstrated.
- When a platform disables its app or service, as Garden Finance did, your funds may become temporarily inaccessible while they investigate.
- Not all exploits result in user compensation. Recovery depends on whether the platform maintains insurance, whether the attacker is caught, or whether the team has reserves to cover losses.
For deeper understanding of how smart contract security works and what to evaluate before using any DeFi platform, explore Thewealthora’s detailed guides on cryptocurrency risk and blockchain platform selection.
Go deeper on Thewealthora
- Crypto home invasions surge to 20 cases in first half of 2026
- London Stock Exchange plans 24-hour trading by 2027
- Budget miner just won $200K, here’s what it means for you
Originally reported by Cointelegraph. Facts verified; analysis and wording are Thewealthora’s own.