{"investigation":{"slug":"garden","entity_name":"Garden","trust_score":14,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Garden Finance (garden.finance) is a Bitcoin cross-chain bridge and swap protocol launched in December 2023 by former Ren Protocol core team members, using Hashed Timelock Contracts (HTLCs) and an intents-based solver network to enable non-custodial Bitcoin swaps across chains. In October 2025, a compromised solver operator lost approximately $11.4 million in a security incident attributed by forensic investigators to a North Korea-linked threat actor. Prior to the exploit, blockchain investigator ZachXBT alleged that a substantial portion of Garden's volume — with estimates ranging from 25% to over 75% — originated from illicit sources including funds stolen in the $1.46 billion Bybit hack by Lazarus Group, allegations the team disputed but did not fully refute.","sections":[{"content":"Garden Finance was founded in 2023 by Jaz Gulati and Susruth Nadimpalli, both former core contributors to Ren Protocol (originally Republic Protocol), an earlier Bitcoin-on-Ethereum bridge project founded in 2017 in Australia. Gulati and Nadimpalli were named to the Forbes 30 Under 30 class of 2022 during their time at Ren. Ren Protocol collapsed following the bankruptcy of FTX in late 2022, which had acquired Ren Labs. Garden was positioned as a spiritual successor, incorporating lessons from Ren's custodial-wrapper model by adopting a non-custodial atomic swap architecture. The protocol launched publicly in late 2023 and claimed to have bridged over $2 billion in crypto assets by mid-2025. Garden is incorporated as a legal entity and has received grant funding from the Arbitrum ecosystem. The SEED governance token launched on January 18, 2024, with a total supply of 147 million tokens. A 24-month cliff applies to team and investor allocations from TGE. Elliptic, a blockchain intelligence firm, separately reported that Ren Protocol processed over $540 million in illicit funds between 2020 and 2025, including funds linked to the Conti and Ryuk ransomware groups and North Korea's Lazarus Group, raising questions about continuity of risk culture between the two protocols.","heading":"Background","sources":[{"url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","name":"","type":"other","credibility":3},{"url":"https://forum.arbitrum.foundation/t/garden-finance-ltipp-application-final/21926","name":"","type":"other","credibility":3},{"url":"https://docs.garden.finance/home/governance/tokenomics","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Garden operates as a non-custodial cross-chain bridge using Hashed Timelock Contracts (HTLCs) and an intents-based architecture. Users express an intent to swap assets (e.g., native BTC to WBTC on Ethereum), and independent solver operators fulfill those orders by locking their own capital on the destination chain. The HTLC mechanism ensures atomicity: either both legs of the swap complete with a shared cryptographic secret, or both sides time out and assets are refunded. This design means user funds are never directly custodied by Garden or its solvers during a swap. Solvers must hold a minimum of 210,000 SEED tokens to operate, aligning economic incentives. The SEED token also governs protocol parameters and treasury allocation via staking. A Gardener NFT pass can be minted by permanently burning 21,000 SEED. The protocol claims sub-30-second settlement for BTC swaps. Garden has published a developer SDK and APIs to allow third-party dApps to integrate its bridge functionality. Despite the trustless design at the user layer, the October 2025 exploit demonstrated that solver operators themselves represent a material operational risk surface, as their private key infrastructure sits outside the cryptographic guarantees of the HTLC contracts.","heading":"Protocol Mechanics","sources":[{"url":"https://garden.finance/blog/what-are-htlcs","name":"","type":"other","credibility":3},{"url":"https://www.garden.finance/","name":"","type":"other","credibility":3},{"url":"https://docs.garden.finance/home/governance/tokenomics","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Garden Finance's atomic swap smart contracts have been audited by Trail of Bits, OtterSec, and Zellic. Audit reports are published in the official GitHub repository at gardenfi/audits. Specific audit dates and finding severities are not publicly detailed in the repository index. A Code4rena competitive audit has also been referenced in secondary sources. Despite these smart-contract-level audits, an operational security breach occurred on October 30, 2025, when an attacker gained unauthorized access to the private key infrastructure of one of Garden's largest independent solver operators and drained approximately $11.4 million in crypto assets (WBTC, USDC, USDT, and ETH) across multiple blockchain networks. Ernst and Young conducted a forensic investigation and confirmed unauthorized server access from IP addresses with indicative locations in Japan and China. ZeroShadow, a web3 security firm engaged post-incident, attributed the compromise to a leaked private key on a compromised device and linked the attacker's behavioral profile to DangerousPassword, a threat actor also known as CryptoCore, Sapphire Sleet, and UNC1069, which is assessed to be affiliated with North Korea. Garden offered a 10% whitehat bounty (~$1.1 million) for the return of funds and disclosure of the exploit method. As of the forensic report published January 29, 2026, no funds had been returned. Blockchain investigator ZachXBT contested Garden's framing that the compromised solver was independently operated, citing on-chain messages sent to the attacker from an address identified as a Garden deployer address, which ZachXBT alleged suggested the solver was actually operated by a team member. Garden disputed this characterization. The protocol's smart contracts and user-layer assets were reportedly unaffected by the exploit due to the HTLC isolation of user funds.","heading":"Security & Audits","sources":[{"url":"https://github.com/gardenfi/audits","name":"","type":"other","credibility":3},{"url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/press-releases/387636/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","name":"","type":"other","credibility":3},{"url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-october-2025","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Garden Finance was co-founded by Jaz Gulati (CEO) and Susruth Nadimpalli. Both previously worked on Ren Protocol, with Gulati credited with helping scale Ren to over $10 billion in cumulative volume. Both were named to Forbes 30 Under 30 in 2022. The team operates under a legal entity, Garden Finance Limited, registered in the United Kingdom (Companies House number 09763192). On-chain analysis by ZachXBT alleged that at least one of the solver operators drained in the October 2025 exploit was operated by or closely affiliated with a Garden team member, based on gas-funding transactions and on-chain messages from a Garden deployer address. Garden denied that the solver was team-operated and maintained that solvers are independent third-party operators. The team's transparency around the exploit and its aftermath has been mixed: a forensic report was published approximately three months post-incident, and Garden engaged reputable firms (EY, zeroShadow) for investigation, but ZachXBT's allegations regarding team-operated solvers and illicit volume facilitation were never fully addressed with on-chain counter-evidence. The Ren Protocol predecessor faced documented use by sanctioned entities and ransomware groups, which is a relevant lineage risk factor.","heading":"Team & Ownership","sources":[{"url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","name":"","type":"other","credibility":3},{"url":"https://find-and-update.company-information.service.gov.uk/company/09763192/officers","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/garden-finance-exploit-drains-over-10m-across-multiple-chains/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Garden Finance presents a high-to-critical risk profile based on multiple converging factors. First, the protocol suffered a confirmed $11.4 million security incident in October 2025 attributed to a North Korea-affiliated threat actor, with no fund recovery as of the forensic report date. Second, prior to the exploit, blockchain investigator ZachXBT published allegations — corroborated by on-chain evidence — that a substantial portion of Garden's volume, estimated at between 25% and over 75% depending on the time window examined, was attributable to stolen funds. Specifically, $160 million alleged to be connected to the $1.46 billion Bybit hack by North Korea's Lazarus Group transited the platform within 48 hours of that incident, generating over $300,000 in fees for Garden. Third, ZachXBT alleged that the protocol collected six-figure profits from illicit flows between April and July 2025 while ignoring victim requests for fee refunds, a conduct allegation that remains disputed but unrefuted with on-chain evidence by Garden. Fourth, the protocol's predecessor, Ren Protocol, was documented by Elliptic to have processed over $540 million in illicit funds, including for sanctioned ransomware operators. Fifth, ZachXBT alleged that the October 2025 solver breach may have involved a team-operated solver rather than a truly independent third party, raising questions about the accuracy of Garden's public disclosures. Countervailing factors include: (a) smart-contract-level audits from Trail of Bits, OtterSec, and Zellic; (b) the HTLC architecture does provide cryptographic guarantees that user funds are not custodied; (c) Garden engaged EY and zeroShadow for post-incident forensics, demonstrating some incident response capability; and (d) the SEED token and governance structure represent a good-faith attempt at decentralization. On balance, the combination of confirmed illicit fund facilitation at scale, a major operational security breach, alleged internal misrepresentation of solver independence, and lineage from a protocol with a documented sanctions-evasion record result in an overall trust score of 14 out of 100. Users should treat the protocol as high-risk for regulatory, reputational, and security reasons.","heading":"Risk Assessment","sources":[{"url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","name":"","type":"other","credibility":3},{"url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","name":"","type":"other","credibility":3},{"url":"https://cybernews.com/crypto/btc-bridge-flagged-laundering-money-hacked/","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/garden-finance-exploit-drains-over-10m-across-multiple-chains/","name":"","type":"other","credibility":3},{"url":"https://www.xt.com/en/blog/post/zachxbt-accuses-garden-finance-of-laundering-funds-from-bybit-hack","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"Republic Protocol (later Ren Protocol), predecessor project to Garden Finance, founded in Australia by Taiyang Zhang, Loong Wang, and Jaz Gulati.","source":"","date_original":"2017-01-01"},{"date":"2022-11","event":"FTX, which had acquired Ren Labs, files for bankruptcy. Ren Protocol collapses, prompting Gulati and Nadimpalli to begin work on Garden Finance.","source":"","date_original":"2022-11-01"},{"date":"2023-12","event":"Garden Finance publicly launches as a Bitcoin cross-chain bridge using HTLC atomic swaps and an intents-based solver network.","source":"","date_original":"2023-12-01"},{"date":"2024-01-18","event":"SEED governance token launches with a total supply of 147 million tokens. Team and investor allocations subject to 24-month cliff from TGE.","source":""},{"date":"2025-02-21","event":"Bybit exchange suffers a $1.46 billion hack attributed to North Korea's Lazarus Group. ZachXBT later alleges $160 million of these stolen funds transited Garden within 48 hours.","source":""},{"date":"2025-06-21","event":"ZachXBT publicly alleges that more than 80% of Garden Finance's recent fee income was generated from facilitating movement of Lazarus Group-linked Bybit stolen funds. Garden co-founder Jaz Gulati disputes the characterization.","source":""},{"date":"2025-07","event":"ZachXBT publishes a broader analysis alleging 25% or more of Garden's total historical volume is linked to stolen assets, with six-figure profits from illicit flows between April and July 2025.","source":"","date_original":"2025-07-01"},{"date":"2025-10-30","event":"Security breach: an attacker gains unauthorized access to the private key infrastructure of a major Garden solver operator and drains approximately $11.4 million in WBTC, USDC, USDT, and ETH across multiple chains. Garden temporarily shuts down its app.","source":""},{"date":"2025-10-31","event":"Garden co-founder Jaz Gulati states user funds are safe and the protocol remains unaffected. Garden offers a 10% whitehat bounty (~$1.1M) for fund return and exploit disclosure. ZachXBT alleges the compromised solver was operated by a Garden team member based on on-chain evidence from a deployer address.","source":""},{"date":"2026-01-29","event":"Garden publishes forensic findings from Ernst and Young and zeroShadow, confirming unauthorized server access from IP addresses located in Japan and China on October 30, 2025, with the compromise attributed to a leaked private key on a compromised device. The attacker is linked to North Korea-affiliated threat actor DangerousPassword (also known as CryptoCore / Sapphire Sleet / UNC1069). No funds recovered.","source":""}],"sources_used":[{"url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260224200319/https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","credibility":3,"archive_timestamp":"2026-02-24T20:03:19+00:00"},{"url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","name":"","type":"other","archive_url":"http://web.archive.org/web/20251112211504/https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","credibility":3,"archive_timestamp":"2025-11-12T21:15:04+00:00"},{"url":"https://forum.arbitrum.foundation/t/garden-finance-ltipp-application-final/21926","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://docs.garden.finance/home/governance/tokenomics","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:invalid-host-resolution","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://garden.finance/blog/what-are-htlcs","name":"","type":"other","archive_url":"http://web.archive.org/web/20260518190412/https://garden.finance/blog/what-are-htlcs","credibility":3,"archive_timestamp":"2026-05-18T19:04:12+00:00"},{"url":"https://www.garden.finance/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613062207/https://www.garden.finance/","credibility":3,"archive_timestamp":"2026-06-13T06:22:07+00:00"},{"url":"https://github.com/gardenfi/audits","name":"","type":"other","archive_url":"http://web.archive.org/web/20260531123230/https://github.com/gardenfi/audits","credibility":3,"archive_timestamp":"2026-05-31T12:32:30+00:00"},{"url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","name":"","type":"other","archive_url":"http://web.archive.org/web/20260419201034/https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","credibility":3,"archive_timestamp":"2026-04-19T20:10:34+00:00"},{"url":"https://www.theblock.co/press-releases/387636/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-october-2025","name":"","type":"other","archive_url":"http://web.archive.org/web/20260812011242/https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-october-2025","credibility":3,"archive_timestamp":"2026-08-12T01:12:42+00:00"},{"url":"https://find-and-update.company-information.service.gov.uk/company/09763192/officers","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829114937/https://find-and-update.company-information.service.gov.uk/company/09763192/officers","credibility":3,"archive_timestamp":"2026-08-29T11:49:37+00:00"},{"url":"https://cryptonews.com/news/garden-finance-exploit-drains-over-10m-across-multiple-chains/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251030213055/https://cryptonews.com/news/garden-finance-exploit-drains-over-10m-across-multiple-chains/","credibility":3,"archive_timestamp":"2025-10-30T21:30:55+00:00"},{"url":"https://cybernews.com/crypto/btc-bridge-flagged-laundering-money-hacked/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251031184736/https://cybernews.com/crypto/btc-bridge-flagged-laundering-money-hacked/","credibility":3,"archive_timestamp":"2025-10-31T18:47:36+00:00"},{"url":"https://www.xt.com/en/blog/post/zachxbt-accuses-garden-finance-of-laundering-funds-from-bybit-hack","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:20.579952+00:00","updated_at":"2026-08-29T23:26:11.992247+00:00"}}