Security firm Blockaid detected an ongoing exploit draining $450,000 in USDT from Garden Finance's HTLC contracts across four blockchain networks, according to the firm's report.

HTLC, or hashed time-locked contracts, are a common primitive in cross-chain bridges and atomic swaps that lock funds until a cryptographic condition is met or a time window expires. The vulnerability allowed attackers to extract stablecoin value from Garden Finance's implementation of these contracts without satisfying the intended release conditions. Blockaid reported the funds remained at risk as of the detection.

Across total value locked, last 90 days
Across total value locked, last 90 days · MSB Intel data desk

Garden Finance operates a cross-chain liquidity protocol that uses HTLCs to facilitate swaps between different blockchains. The exploit affected the protocol's core bridge mechanism across four separate chains. HTLC exploits have recurred in crypto infrastructure; they arise when time parameters are misconfigured, signature schemes are weak, or hash preimages leak before the lock period expires.

MSB Intel

Blockaid's detection came within 24 hours of the attack's initiation. The firm's monitoring systems flag anomalous fund flows from smart contracts in real time. Garden Finance has not yet issued a public statement on the incident or recovery steps as of the time of Blockaid's report.

The $450,000 figure places this among medium-tier DeFi exploits by recent standards. Cross-chain bridge vulnerabilities have drawn heightened regulatory scrutiny following major collapses like Ronin's $625 million theft in 2022 and Poly Network's $611 million loss in 2021. Both incidents exposed weaknesses in HTLC configurations and validator set management.

Blockaid maintains real-time monitoring of fund flows and contract state changes across major EVM chains and Solana. The four-chain scope means Garden Finance's vulnerability was not chain-specific but architectural to the protocol's HTLC design itself.

The detection occurred while Garden Finance's bridge infrastructure remained operational and processing transactions. If the protocol does not suspend HTLC operations pending a fix, additional funds remain exposed to the same vulnerability mechanism. The number that decides the incident's severity is whether Garden Finance can recover or freeze the stolen $450,000 before the attacker moves it to a hard-to-trace address or exchange.