Garden Finance is dealing with another security breach. Web3 security firm Blockaid flagged the latest incident on Sunday, reporting that an attacker had drained roughly $450,000 worth of USDT from the protocol’s hash time-locked contracts, commonly known as HTLCs.
The theft wasn’t confined to a single network. It hit Garden’s contracts simultaneously across Ethereum, Base, Arbitrum, and BNB Smart Chain, suggesting the attacker had found a way to exploit the same underlying weakness on multiple EVM-compatible chains at once. These chains refer to networks that can run ETH smart contracts and decentralised applications.
HTLCs are the mechanism Garden relies on to let users swap Bitcoin for assets on other blockchains without needing a trusted middleman.
The setup works like a conditional escrow as both sides lock up their assets, and the trade only completes if predefined conditions are met within a set window of time. If something goes wrong, or if one party doesn’t follow through, the funds are supposed to return to their original owner. That safety mechanism appears to be what the attacker managed to circumvent.
In response, Garden Finance pulled its application offline while it investigates the breach, a standard precaution meant to stop any further losses while the team assesses the damage.
However, this is not Garden’s first brush with a major security failure. In late October 2025, the protocol lost an estimated $11.4 million after an attacker compromised the operating environment of one of its solvers, the entities responsible for executing swap orders on the platform.
Garden Finance traces its roots back further than its current name suggests. Research shared on X indicates the project descends from Ren Protocol, which itself began life as Republic Protocol, an Australian venture founded in 2017 by Taiyang Zhang, Loong Wang, and Jaz Gulati.




