GardenFi: ~$450k USDT — HTLC alert, then solver off-chain DB clarification
Developing (26–27 Jul 2026): Blockaid flagged an exploit on @gardenfi HTLC rails — ~$450k USDT across Ethereum, Base, Arbitrum, and BSC. Exploiter EOA 0x25b224c05f6cc5e132165c1621de1a4c3b316999 (~$425k / ~20 txs at alert). Update (26 Jul 18:10 UTC): Garden posted that they identified unusual activity, took the app offline for a full investigation, and will share more when they have it. App shows “Garden Maintenance / under maintenance.” No official loss figure or root-cause post yet; blog has no incident article. Not the Oct 2025 ~$11M+ solver compromise — do not merge the two. Updated (28 Jul 2026): Garden told Cointelegraph (story revised 27 Jul 02:16 UTC) that protocol + HTLC contracts were not compromised; an independent solver’s off-chain database was breached and fraudulent swap records inserted, causing that solver to release funds for unbacked swaps. Team line: solver-owned assets only, no user funds at risk; still confirming totals; working with zeroShadow, Quantstamp, Blockaid. Keep Oct 2025 ~$11M+ solver-environment hit as a separate incident.
369 take: Original Blockaid HTLC drain alert still stands as the on-chain symptom. Garden’s later line shifts root cause to an independent solver’s off-chain DB — still a fund-release path you have to trust. Pulse/ramp lesson: treat every off-chain solver/keeper/DB that can trigger release as adversarial, even when “core contracts are fine.” Not the Oct 2025 hit.