Skip to main content
Sign in

Audit log

Every state-changing event for Garden Finance Cross-Chain Bridge — July 2026 Solver Database Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-07 12:20:39Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5uXrhm5FbaWS…As4CQgtwsha256 → base58
    verifying row…
    canonical bytes (21030 B) ▸
    {"actor":"system:backfill","investigation_id":"8f995061-a7d5-44c2-b533-3d550f96d862","kind":"publish","page_slug":"garden-finance-cross-chain-bridge-july-2026-solver-database-exploit","published_at":"2026-08-07T12:20:39.554Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Garden Finance Cross-Chain Bridge — July 2026 Solver Database Exploit","sections":[{"content":"Garden Finance is a cross-chain bridge and atomic swap protocol designed to facilitate trustless swaps between Bitcoin and assets on EVM-compatible networks. The protocol was launched in December 2023 and was developed by former members of the RenBTC core team, with co-founder Jaz Gulati among its publicly named leadership. Garden uses Hash Time-Locked Contracts (HTLCs) as its core settlement mechanism — time-bound escrow contracts that enforce all-or-nothing trade finality without requiring custodians. Liquidity is provided by independent 'solvers,' market-maker agents that hold their own capital and fulfill user swap orders. The protocol's architecture is designed such that solver assets are segregated from user deposits, a design the team has consistently cited when characterizing its security incidents.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":1,"name":"Garden Finance official website","type":"official","url":"https://garden.finance/"},{"credibility":2,"name":"Garden Finance: Unlocking Bitcoin Liquidity with Trustless Swaps — Bitget Wallet","type":"news_article","url":"https://web3.bitget.com/crypto-news/garden-finance-unlocks-bitcoin-liquidity-with-new-cross-chain-staking-solutions"},{"credibility":2,"name":"ZachXBT: 80% of Garden Finance Fees from Stolen Bitcoin — BitDegree","type":"news_article","url":"https://www.bitdegree.org/crypto/news/zachxbt-claims-80-of-garden-finance-fees-tied-to-stolen-bitcoin"}]},{"content":"On July 26, 2026, at approximately 9:30 PM UTC, Web3 security firm Blockaid published an alert on X describing an active, ongoing exploit targeting Garden Finance's HTLC contracts across four blockchain networks: Ethereum, Base, Arbitrum, and BNB Smart Chain. Blockaid flagged the exploiter's wallet address (0x25b…6999), which Etherscan tagged with an exploit warning. The wallet held approximately $424,707.21 across the four chains, with 20 transactions logged at the time of reporting. Garden Finance confirmed the incident was caused by an attacker gaining access to the off-chain database of one of its independent solvers and inserting fraudulent transaction records. These records caused the solver's system to release funds for swaps that had never been funded by the corresponding counterparty — effectively tricking the solver's infrastructure into authorizing unauthorized fund releases. Garden confirmed total losses of approximately $450,000 in USDT. The protocol's core HTLC smart contracts were not modified or directly exploited. Garden temporarily took its application offline as a precautionary measure while it isolated the affected infrastructure.","heading":"July 2026 Solver Database Exploit","severity":"critical","sources":[{"credibility":1,"name":"Garden Finance Says Solver Breach Caused $450K Drain — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/garden-finance-app-offline-450k-htlc-exploit"},{"credibility":2,"name":"Garden Finance Halts App After $450K USDT Exploit Hits Four Blockchains — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/garden-finance-halts-app-after-450k-usdt-exploit-hits-four-blockchains/"},{"credibility":2,"name":"Blockaid detects ongoing exploit draining $450K from Garden Finance across four chains — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/blockaid-garden-finance-exploit-450k/"},{"credibility":2,"name":"Garden Finance takes app offline after independent solver database compromise — Crypto.news","type":"news_article","url":"https://crypto.news/garden-finance-takes-app-offline-after-independent-solver-database-compromise/"},{"credibility":1,"name":"Garden Finance disables app as Blockaid reports $450,000 exploit — TradingView / CoinTelegraph","type":"news_article","url":"https://www.tradingview.com/news/cointelegraph:adffd80d9094b:0-garden-finance-disables-app-as-blockaid-reports-450-000-exploit/"}]},{"content":"Garden Finance's solver architecture relies on off-chain databases to track swap state. In the July 2026 incident, the attacker did not exploit a vulnerability in the HTLC smart contract code itself. Instead, they gained unauthorized access to the database layer of an independent solver's infrastructure and injected fraudulent records representing swaps that had been funded, when in fact the counterparty funds had not been deposited. The solver's automated systems, trusting its own database, then released the locked assets — completing swaps for which no legitimate counterpart existed. This pattern of exploiting the off-chain coordination layer while leaving on-chain smart contract logic intact is consistent with the October 2025 incident, where a leaked private key on a compromised device gave an attacker access to a solver's operating environment. Security firm zeroShadow noted in forensic findings from the 2025 incident that 'the incident originated from a leaked private key on a compromised device,' though the specific entry vector for the July 2026 database breach had not been publicly confirmed at time of reporting.","heading":"Technical Mechanism and Attack Vector","severity":"critical","sources":[{"credibility":2,"name":"Garden Finance Shares Forensic Findings: Security Breach Limited to Solver Layer — Decrypt","type":"research","url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer"},{"credibility":2,"name":"Garden Finance hit by another exploit, loses $450,000 across 4 chains — CoinCodeCap","type":"news_article","url":"https://coincodecap.com/garden-finance-hit-by-another-exploit-loses-450000-across-4-chains"},{"credibility":2,"name":"Garden Finance Halts Operations Following $450K Solver Database Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/garden-finance-halts-operations-following-450k-solver-database-exploit"}]},{"content":"Following Blockaid's public alert, Garden Finance confirmed the incident and took its application offline to contain further losses and conduct a security review. The team engaged three external security firms: Blockaid (which had detected the exploit), zeroShadow (on-chain asset tracing and incident response), and Quantstamp (security review). Garden Finance stated that no user funds were lost or placed at risk, as the losses were limited to assets held by the compromised solver, not user deposits. The protocol cited its SOC 2 Type II attestation controls in communications surrounding the incident. No timeline was provided for restoration of service at the time of initial reporting.","heading":"Incident Response","severity":"high","sources":[{"credibility":1,"name":"Garden Finance Says Solver Breach Caused $450K Drain — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/garden-finance-app-offline-450k-htlc-exploit"},{"credibility":2,"name":"Garden Finance Halts App After $450K Solver DB Breach — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/garden-finance-pauses-app-after-independent-solver-database-breach/"},{"credibility":2,"name":"Garden Finance Disables App After Solver Breach — CoinInsider","type":"news_article","url":"https://www.coininsider.com/news/garden-finance-disables-app-after-solver-breach/"}]},{"content":"The July 2026 exploit is not Garden Finance's first major security incident. On October 30, 2025, an attacker drained approximately $11.4 million from one of Garden's largest independent solver operators. The breach was attributed by blockchain investigator ZachXBT and security firm zeroShadow to the North Korea-affiliated threat actor group tracked as 'DangerousPassword.' Ernst & Young (EY), engaged by Garden for an independent forensic investigation, confirmed unauthorized access to the solver's infrastructure and identified suspicious SSH access from IP addresses with indicative locations in Japan and China. zeroShadow's analysis concluded the compromise originated from a leaked private key on a compromised device. Garden offered the attacker a 10% bounty for return of funds. Following the incident, Garden Finance implemented additional security controls including solver infrastructure isolation, expanded solver operators, formal security standards, and appointment of a dedicated CISO. ZachXBT alleged at the time that the compromised solver may have been operated by a Garden team member rather than a fully independent party, pointing to an on-chain message from a Garden deployer address stating 'our systems have been compromised.' Garden disputed this characterization.","heading":"Prior Security Incident: October 2025 $11 Million Solver Breach","severity":"critical","sources":[{"credibility":1,"name":"Attackers dig up $11M in Garden Finance crypto exploit — The Register","type":"news_article","url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"},{"credibility":2,"name":"Crypto bridge Garden Finance suffers $11M hack via compromised solver — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/garden-finance-bridge-11m-hack/"},{"credibility":2,"name":"Garden Finance Shares Forensic Findings: Security Breach Limited to Solver Layer — Decrypt","type":"research","url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer"},{"credibility":2,"name":"DeFi karma: Garden hacked for $11M after bridging Lazarus' loot — Protos","type":"news_article","url":"https://protos.com/defi-karma-garden-hacked-for-11m-after-bridging-lazarus-loot/"}]},{"content":"Prior to and independent of the exploit incidents, Garden Finance faced serious allegations from on-chain investigators regarding the provenance of funds bridged through its protocol. ZachXBT alleged in a June 2026 post on X that over 80% of the fees Garden Finance collected in a 12-day window ending June 2, 2026 — totaling 38.86 BTC and approximately $300,000 in revenue — came from laundering efforts involving assets stolen in the February 2025 Bybit hack, which was attributed to the Lazarus Group (a North Korea state-sponsored cybercriminal organization). ZachXBT further alleged that approximately 25% of the protocol's total bridged volume consisted of stolen funds, including proceeds from the Swissborg hack. Security researcher Taylor Monahan, of MetaMask, separately alleged that a sizable portion of Garden Finance's bridging activity was carried out by North Korean cybercriminals. Co-founder Jaz Gulati disputed the ZachXBT claims, stating that 30 BTC in fees were collected before the Bybit incident, arguing that much of the revenue predated the alleged laundering activity. These allegations have not resulted in any publicly disclosed regulatory action as of the time of reporting. The protocol's permissionless and trustless design — which does not require KYC — is relevant context for evaluating its exposure to illicit fund flows.","heading":"Alleged Facilitation of Illicit Fund Flows","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT: 80% of Garden Finance Fees from Stolen Bitcoin — BitDegree","type":"news_article","url":"https://www.bitdegree.org/crypto/news/zachxbt-claims-80-of-garden-finance-fees-tied-to-stolen-bitcoin"},{"credibility":2,"name":"25% of Garden Finance Funds Linked to Stolen Assets, ZachXBT Reveals — Yahoo Finance / CryptoNews","type":"news_article","url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html"},{"credibility":2,"name":"DeFi karma: Garden hacked for $11M after bridging Lazarus' loot — Protos","type":"news_article","url":"https://protos.com/defi-karma-garden-hacked-for-11m-after-bridging-lazarus-loot/"},{"credibility":1,"name":"Attackers dig up $11M in Garden Finance crypto exploit — The Register","type":"news_article","url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"}]},{"content":"Both the October 2025 and July 2026 incidents exploited the off-chain coordination layer of Garden Finance's solver infrastructure rather than its on-chain smart contracts. This pattern indicates that the protocol's attack surface extends significantly beyond its audited smart contract code. Solvers in Garden's architecture hold their own capital and process swap state via off-chain databases, creating centralized trust dependencies that contrast with the protocol's 'trustless' marketing. Crypto Briefing noted that despite audits by Trail of Bits, OtterSec, and Zellic, the protocol experienced 'fundamentally different types of attacks,' underscoring that traditional smart contract audits do not cover off-chain infrastructure vulnerabilities. The repeated exploitation of the solver layer — even after the October 2025 incident prompted Garden to implement new infrastructure isolation controls — raises questions about whether the architectural reliance on off-chain solver state can be adequately secured.","heading":"Systemic Risk: Solver Architecture and Off-Chain Trust Dependencies","severity":"high","sources":[{"credibility":2,"name":"Blockaid detects ongoing exploit draining $450K from Garden Finance across four chains — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/blockaid-garden-finance-exploit-450k/"},{"credibility":2,"name":"Garden Finance Shares Forensic Findings: Security Breach Limited to Solver Layer — Decrypt","type":"research","url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer"},{"credibility":3,"name":"Ongoing Security Exploit Looms Over Garden Finance — Value The Markets","type":"news_article","url":"https://www.valuethemarkets.com/cryptocurrency/news/ongoing-security-exploit-looms-over-garden-finance"}]}],"sources_used":[{"credibility":1,"name":"Garden Finance Says Solver Breach Caused $450K Drain — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/garden-finance-app-offline-450k-htlc-exploit"},{"credibility":1,"name":"Attackers dig up $11M in Garden Finance crypto exploit — The Register","type":"news_article","url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"},{"credibility":1,"name":"Garden Finance disables app as Blockaid reports $450,000 exploit — TradingView / CoinTelegraph","type":"news_article","url":"https://www.tradingview.com/news/cointelegraph:adffd80d9094b:0-garden-finance-disables-app-as-blockaid-reports-450-000-exploit/"},{"credibility":2,"name":"Garden Finance Halts App After $450K USDT Exploit Hits Four Blockchains — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/garden-finance-halts-app-after-450k-usdt-exploit-hits-four-blockchains/"},{"credibility":2,"name":"Blockaid detects ongoing exploit draining $450K from Garden Finance across four chains — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/blockaid-garden-finance-exploit-450k/"},{"credibility":2,"name":"Garden Finance takes app offline after independent solver database compromise — Crypto.news","type":"news_article","url":"https://crypto.news/garden-finance-takes-app-offline-after-independent-solver-database-compromise/"},{"credibility":2,"name":"Garden Finance Shares Forensic Findings: Security Breach Limited to Solver Layer — Decrypt","type":"research","url":"https://decrypt.co/356301/garden-finance-shares-forensic-findings-security-breach-limited-to-solver-layer"},{"credibility":2,"name":"Crypto bridge Garden Finance suffers $11M hack via compromised solver — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/garden-finance-bridge-11m-hack/"},{"credibility":2,"name":"DeFi karma: Garden hacked for $11M after bridging Lazarus' loot — Protos","type":"news_article","url":"https://protos.com/defi-karma-garden-hacked-for-11m-after-bridging-lazarus-loot/"},{"credibility":2,"name":"ZachXBT: 80% of Garden Finance Fees from Stolen Bitcoin — BitDegree","type":"news_article","url":"https://www.bitdegree.org/crypto/news/zachxbt-claims-80-of-garden-finance-fees-tied-to-stolen-bitcoin"},{"credibility":2,"name":"25% of Garden Finance Funds Linked to Stolen Assets, ZachXBT Reveals — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/25-garden-finance-funds-linked-175501426.html"},{"credibility":2,"name":"Garden Finance Halts Operations Following $450K Solver Database Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/garden-finance-halts-operations-following-450k-solver-database-exploit"},{"credibility":2,"name":"Garden Finance Disables App After Solver Breach — CoinInsider","type":"news_article","url":"https://www.coininsider.com/news/garden-finance-disables-app-after-solver-breach/"},{"credibility":2,"name":"Garden Finance Halts App After $450K Solver DB Breach — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/garden-finance-pauses-app-after-independent-solver-database-breach/"},{"credibility":3,"name":"Ongoing Security Exploit Looms Over Garden Finance — Value The Markets","type":"news_article","url":"https://www.valuethemarkets.com/cryptocurrency/news/ongoing-security-exploit-looms-over-garden-finance"}],"summary":"Garden Finance is a cross-chain atomic swap protocol that uses Hash Time-Locked Contracts (HTLCs) to facilitate trustless swaps between Bitcoin and EVM-chain assets. On July 26, 2026, an attacker compromised the off-chain database of an independent solver and inserted fraudulent transaction records, draining approximately $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Smart Chain. This was the protocol's second major security incident in under a year, following a substantially larger $11 million breach in October 2025 that involved a North Korea-affiliated threat actor group.","timeline":[{"date":"2023-12-01","event":"Garden Finance launched as a cross-chain atomic swap protocol, developed by former RenBTC team members including co-founder Jaz Gulati.","source":"Bitget Wallet","source_url":"https://web3.bitget.com/crypto-news/garden-finance-unlocks-bitcoin-liquidity-with-new-cross-chain-staking-solutions"},{"date":"2025-10-30","event":"An attacker gained unauthorized access to the operating environment of one of Garden Finance's largest independent solvers, draining approximately $11.4 million in crypto assets. EY forensic investigation later confirmed suspicious SSH access from IP addresses in Japan and China. ZachXBT attributed the attack to the DPRK-affiliated DangerousPassword group.","source":"The Register","source_url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"},{"date":"2025-10-31","event":"Garden Finance publicly disclosed the October 2025 breach, temporarily shut down its application, and offered a 10% bounty to the attacker for return of funds.","source":"The Register","source_url":"https://www.theregister.com/2025/10/31/attackers_dig_up_11m_in/"},{"date":"2026-06-02","event":"ZachXBT published analysis on X alleging that over 80% of Garden Finance's recent fee revenue — 38.86 BTC collected over 12 days — derived from laundering funds stolen in the February 2025 Bybit hack, attributed to the Lazarus Group. Co-founder Jaz Gulati disputed the claim.","source":"BitDegree","source_url":"https://www.bitdegree.org/crypto/news/zachxbt-claims-80-of-garden-finance-fees-tied-to-stolen-bitcoin"},{"date":"2026-07-26","event":"Blockaid detected an active, ongoing exploit on Garden Finance's HTLC contracts at approximately 9:30 PM UTC, flagging the attacker address (0x25b...6999) and approximately $450,000 in USDT drained across Ethereum, Base, Arbitrum, and BNB Smart Chain.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/garden-finance-app-offline-450k-htlc-exploit"},{"date":"2026-07-26","event":"Garden Finance took its application offline as a precaution and confirmed the exploit originated from the compromise of an independent solver's off-chain database. The team engaged zeroShadow, Quantstamp, and Blockaid to assist with asset tracing and recovery.","source":"Crypto.news","source_url":"https://crypto.news/garden-finance-takes-app-offline-after-independent-solver-database-compromise/"},{"date":"2026-07-27","event":"Garden Finance issued a public statement confirming the breach was limited to the solver layer, that HTLC smart contracts were not compromised, and that no user funds were at risk. The team stated it was still verifying the total amount lost and provided no timeline for service restoration.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/27/garden-finance-halts-app-after-450k-usdt-exploit-hits-four-blockchains/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision c4d32257-a7a6-4593-aa40-63bfecdf0925
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.