{"investigation":{"slug":"garden-finance","entity_name":"Garden Finance","trust_score":14,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Garden Finance is a cross-chain Bitcoin bridge protocol launched in 2023 by former Ren Protocol developers, using Hash Time Locked Contracts (HTLCs) and an intents-based solver network to enable atomic swaps across Ethereum, Solana, Arbitrum, Base, and other chains. On October 30–31, 2025, one of its largest solver operators was compromised via a leaked private key, resulting in approximately $11.4 million in stolen assets that were subsequently laundered through Tornado Cash. Prior to the exploit, blockchain investigator ZachXBT alleged that over 80% of the protocol's recent fee revenue was derived from laundering funds stolen in the February 2025 Bybit hack, which the Lazarus Group (DPRK) perpetrated for approximately $1.4 billion.","sections":[{"content":"Garden Finance is a decentralized cross-chain bridge and swap protocol founded in 2023 by Jaz Gulati and Susruth Nadimpalli, both former core developers of Ren Protocol and Forbes 30 Under 30 alumni (2022 class). The protocol is built on Hash Time Locked Contracts (HTLCs), which enable trustless atomic swaps by ensuring that either both legs of a cross-chain transaction complete successfully or both revert. Garden employs an intents-based architecture where independent solver operators hold their own liquidity and fill user swap orders across supported chains — including Bitcoin, Ethereum, Solana, Arbitrum, Base, and Berachain — in approximately 30 seconds. The protocol is non-custodial: user funds are never held by Garden or its solvers during swaps. Garden is positioned as a spiritual successor to Ren Protocol, which processed over $13 billion in Bitcoin transactions before collapsing following the bankruptcy of its backer Alameda Research and FTX in late 2022. The protocol claimed to have bridged over $2 billion in cumulative assets as of late 2025. Security audits were conducted by Trail of Bits, Zellic, and Ottersec, though the October 2025 breach did not originate from smart contract vulnerabilities.","heading":"Protocol Overview","sources":[],"severity":"medium"},{"content":"On June 21, 2025, blockchain investigator ZachXBT published findings on X (formerly Twitter) alleging that over 80% of Garden Finance's recent fee revenue was derived from illicit transactions — specifically, the laundering of funds stolen in the February 21, 2025 Bybit hack attributed to North Korea's Lazarus Group. The Bybit hack involved the theft of approximately 401,347 ETH (valued at approximately $1.4 billion at the time) via exploitation of multi-signature authentication vulnerabilities. ZachXBT alleged that a single entity — described as Chinese-based operators linked to Lazarus Group — was continuously supplying cbBTC (Coinbase's wrapped Bitcoin) liquidity to Garden's solver network from Coinbase accounts, enabling the conversion of stolen ETH into Bitcoin at scale. ZachXBT documented 16 wallets connected to the Bybit hack executing synchronized large transactions through Garden within minutes of each other. He further alleged that Garden earned six-figure profits from these illicit flows between April and July 2025, and that over 25% of the protocol's entire historical $2 billion in bridged volume involved stolen assets — with some analyses suggesting the figure may have exceeded 75% of recent volume. ZachXBT also cited connections to the WazirX hack as an additional source of illicit inflows. Garden Finance co-founder Jaz Gulati publicly disputed these findings, stating that 30 BTC in fees had been collected prior to the Bybit hack and characterizing the laundering claims as 'misinformation.' Gulati noted that Garden had subsequently integrated blockchain screening tools, engaged analytics firms, and began working with Bybit, Binance, and Coinbase to trace illicit flows. ZachXBT reportedly 'doubled down' with additional on-chain evidence after Gulati's denial.","heading":"ZachXBT Money Laundering Allegations (June 2025)","sources":[],"severity":"medium"},{"content":"On October 30–31, 2025, Garden Finance suffered a security incident in which one of its largest independent solver operators was compromised, resulting in the theft of approximately $11.4 million in cryptocurrency assets across multiple blockchain networks including Ethereum, Solana, Arbitrum, and BNB Chain. The stolen assets included wETH (wrapped Ether), WBTC (wrapped Bitcoin), cbBTC (Coinbase Bitcoin), LBTC (Lombard-locked BTC), and SEED (Garden's native token). According to a forensic investigation by Ernst & Young commissioned by Garden Finance, the breach originated from a leaked private key on a compromised device. EY's examination of SSH authentication logs identified suspicious access from four IP addresses with indicative locations in Japan and China occurring on October 30, 2025. The attacker used the compromised access to drain the solver's holdings across chains, then used the MetaMask router to rapidly convert all freezeable assets into ETH. Garden Finance publicly confirmed the breach in an on-chain message and offered a 10% white-hat bounty to the attacker in exchange for return of funds and disclosure of the exploit method. The attacker did not respond. Garden disputed characterizing the incident as a 'protocol exploit,' maintaining that the HTLC smart contracts and user funds were unaffected, and that only the independently operated solver's proprietary funds were taken. ZachXBT challenged this characterization, noting that on-chain messages to the attacker appeared to originate from a Garden team deployer address (0x347ff38dbb8ef026ce65756268443f1bd47932bc), raising questions about whether the 'independent solver' was in fact operated by the Garden team itself. A second address linked to the incident was 0x98bcc6c34a489cefdd9dfa8d792cfefb02ea2d12. Security analysts at zeroShadow assessed that on-chain laundering patterns following the exploit were 'consistent with those of other attacks attributed to the North Korea-affiliated threat actor DangerousPassword (also known as CryptoCore, Sapphire Sleet, and UNC1069).' Estimates of total losses varied across sources: initial reports cited approximately $5.5 million, with later forensic analysis revising the figure to approximately $10.8–$11.4 million.","heading":"October 2025 Exploit — Solver Compromise","sources":[],"severity":"medium"},{"content":"Following the October 2025 exploit, security firm CertiK tracked the attacker's fund movements and identified that the exploiter transferred approximately $6.65 million in stolen assets to Tornado Cash, the sanctioned Ethereum mixing service. Specifically, CertiK documented deposits of 501 BNB and 1,910 ETH through the mixer. As of reporting, approximately $500,000 remained in EVM-chain addresses controlled by the attacker, and approximately $1.8 million in SOL tokens remained in a Solana account linked to the exploit. The attacker address on Ethereum was identified as 0x98BC...2D12 and a corresponding Solana address was also flagged. The routing of stolen funds through Tornado Cash substantially diminished the probability of asset recovery. No funds had been returned to Garden Finance as of subsequent reporting.","heading":"Post-Exploit Fund Movements and Tornado Cash Laundering","sources":[],"severity":"medium"},{"content":"Garden Finance markets itself as a trustless, non-custodial protocol in which users retain control of assets throughout swaps. The HTLC mechanism is intended to guarantee atomicity: if either leg of a cross-chain swap fails or times out, funds are returned to the initiating party. Garden's solver network is presented as a decentralized set of independent market makers who hold their own capital and compete to fill swap orders. However, ZachXBT's on-chain analysis raised questions about the degree of actual decentralization, noting that a single entity appeared to control a dominant share of cbBTC liquidity provisioning, and that on-chain messages sent during the October 2025 exploit appeared to originate from a Garden team-controlled deployer address rather than a third-party operator. Garden Finance co-founder Jaz Gulati denied that the protocol was 'fake decentralized.' Garden's forensic report, prepared by EY, maintained that the solver layer is architecturally separated from the user-facing HTLC contracts, and that the smart contracts themselves were not compromised in the October exploit. Post-exploit remediation steps announced by Garden included expanded solver redundancy, removal of public infrastructure exposure requirements, appointment of a dedicated CISO, third-party security standards for solver operators, and regular penetration testing.","heading":"Protocol Architecture and Decentralization Claims","sources":[],"severity":"medium"},{"content":"Garden Finance was founded by former core developers of Ren Protocol, specifically Jaz Gulati and Susruth Nadimpalli. Ren Protocol (originally Republic Protocol, founded 2017) raised approximately $67 million and facilitated over $13 billion in Bitcoin cross-chain transactions before its collapse. Ren was acquired by Alameda Research in 2021. When FTX and Alameda collapsed in late 2022, Ren Protocol shut down, leaving approximately $12 million in user Bitcoin stranded. Blockchain intelligence firm Elliptic reported that Ren processed over $540 million in illicit funds between 2020 and 2025, with funds linked to the Conti and Ryuk ransomware groups and North Korea's Lazarus Group passing through the protocol. The founders' prior association with a protocol that processed large volumes of illicit funds is noted as relevant background context, though Garden Finance launched as a separate entity with new contracts and audits.","heading":"Ren Protocol Lineage and Predecessor Risk","sources":[],"severity":"medium"}],"timeline":[{"date":"2017","event":"Jaz Gulati, Susruth Nadimpalli, Taiyang Zhang, and Loong Wang co-found Republic Protocol (later rebranded Ren Protocol) in Australia, raising approximately $67 million.","source":"","source_url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/","date_original":"2017-01-01"},{"date":"2021","event":"Alameda Research acquires Ren Protocol.","source":"","source_url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","date_original":"2021-01-01"},{"date":"2022-11","event":"FTX and Alameda Research collapse; Ren Protocol shuts down, stranding approximately $12 million in user Bitcoin.","source":"","source_url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html","date_original":"2022-11-01"},{"date":"2023","event":"Jaz Gulati and Susruth Nadimpalli launch Garden Finance as a decentralized HTLC-based Bitcoin bridge, positioning it as a successor to Ren Protocol.","source":"","source_url":"https://renproject.io/","date_original":"2023-01-01"},{"date":"2025-02-21","event":"Bybit exchange is hacked by North Korea's Lazarus Group via multi-signature authentication exploitation; approximately 401,347 ETH (~$1.4 billion) is stolen.","source":"","source_url":"https://www.cryptotimes.io/2025/06/21/zachxbt-claims-garden-finances-illicit-role-in-laundering-1-4b-bybit-hack-funds/"},{"date":"2025-06-21","event":"ZachXBT publishes on-chain investigation alleging that over 80% of Garden Finance's recent fee revenue was derived from laundering Bybit hack proceeds linked to Lazarus Group, and that 16 wallets connected to the hack executed synchronized transactions through the protocol.","source":"","source_url":"https://www.cryptotimes.io/2025/06/21/zachxbt-claims-garden-finances-illicit-role-in-laundering-1-4b-bybit-hack-funds/"},{"date":"2025-06-21","event":"Garden Finance co-founder Jaz Gulati publicly disputes ZachXBT's laundering allegations, claiming 30 BTC in fees were collected prior to the Bybit hack and citing integration of screening tools.","source":"","source_url":"https://www.bitdegree.org/crypto/news/zachxbt-claims-80-of-garden-finance-fees-tied-to-stolen-bitcoin"},{"date":"2025-10-30","event":"Garden Finance's largest independent solver operator is compromised via a private key leak. SSH logs show suspicious access from IP addresses located in Japan and China. The attacker begins draining solver assets across Ethereum, Solana, Arbitrum, and BNB Chain.","source":"","source_url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer"},{"date":"2025-10-31","event":"Garden Finance publicly acknowledges the breach, offers a 10% white-hat bounty to the attacker for return of funds and exploit disclosure. Protocol goes offline. ZachXBT notes that the on-chain message to the attacker originated from a Garden team deployer address.","source":"","source_url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"},{"date":"2025-10-31","event":"Total losses estimated at approximately $5.5 million in initial reports; later revised upward to approximately $10.8–$11.4 million across multiple chains. Stolen tokens include wETH, WBTC, cbBTC, LBTC, and SEED.","source":"","source_url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-october-2025"},{"date":"2025-11","event":"Security firm CertiK reports that the exploiter transferred approximately $6.65 million (501 BNB and 1,910 ETH) to Tornado Cash. Approximately $1.8 million in SOL and $500K in EVM funds remain in attacker-controlled addresses.","source":"","source_url":"https://ambcrypto.com/garden-finance-exploiter-moves-6-65m-to-tornado-cash-after-10-8m-hack/","date_original":"2025-11-01"},{"date":"2025-11","event":"zeroShadow security analysts assess that on-chain laundering patterns from the exploit are consistent with North Korea-affiliated threat actor DangerousPassword (CryptoCore / Sapphire Sleet / UNC1069). Ernst & Young forensic report confirms private key leak as root cause.","source":"","source_url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer","date_original":"2025-11-01"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:06.224654+00:00","updated_at":"2026-08-29T01:35:54.113+00:00"}}