$450K Gone in Hours: Garden Finance Just Pulled Its Own Plug

An attacker quietly drained $450,000 in USDT from Garden Finance's HTLC contracts across four blockchains before most users even knew the protocol was under attack.

Blockaid, the onchain security firm that caught the exploit, confirmed the damage spanned Ethereum, Base, Arbitrum, and BNB Smart Chain simultaneously. This wasn't a single-chain smash-and-grab. The attacker moved across networks in a coordinated sweep, targeting Hash Time Locked Contracts, the same trustless swap infrastructure Garden Finance uses to power its cross-chain trading.

Garden Finance responded by doing the one thing that signals a team takes security seriously: it killed its own app. The protocol disabled its front end entirely, cutting off user access to stop further exposure. No slow patch. No "we're investigating" tweet followed by three days of silence. The plug got pulled fast.

Why HTLC Exploits Are Particularly Nasty

HTLC contracts are supposed to be the safe part of cross-chain DeFi. They use cryptographic locks and time windows to ensure swaps either complete or refund. When an attacker finds a way to drain them, it typically means a flaw in how the contract logic handles edge cases, timeouts, or refund conditions, not just a simple reentrancy bug. That makes this harder to patch and harder to fully audit after the fact.

The multi-chain nature of this exploit adds another layer of concern. Executing a coordinated drain across Ethereum, Base, Arbitrum, and BNB Smart Chain in a single attack window suggests either deep protocol knowledge or a vulnerability so fundamental it worked identically across every deployment.

What This Means for DeFi Right Now

Garden Finance is not the first cross-chain protocol to get hit in 2024 and 2025, and it will not be the last. Bridges and cross-chain swap protocols remain the highest-value targets in DeFi because they hold pooled liquidity across multiple environments at once. One exploit, four chains drained.

Blockaid flagging this in real time is the only reason the damage stopped at $450,000. Without active threat detection sitting between users and contracts, that number almost certainly climbs.

What to watch: If you hold funds in any cross-chain protocol using HTLC mechanics, check whether that protocol has active security monitoring and a documented incident response process. If the answer is no to either, that is your signal to reassess your exposure.

Garden Finance has not yet published a full post-mortem. When it does, the specific vulnerability will tell the broader DeFi ecosystem whether this is an isolated implementation flaw or a systemic risk across HTLC-based protocols. Watch for that report closely.