Fact-check findings
What an automated fact-checker found when it re-read Garden Finance Cross-Chain Bridge — July 2026 Solver Database Exploit against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #16[unverifiable][awaiting moderator]in section: Alleged Facilitation of Illicit Fund Flows
“These allegations have not resulted in any publicly disclosed regulatory action as of the time of reporting.”
reviewerThe illicit-flows allegations have not resulted in any publicly disclosed regulatory action as of the time of reportingNo contradicting evidence found, but this is a negative claim that cannot be fully verified either way.
link rot
2 claimsA cited source no longer resolves or no longer says what the page attributes to it.
- #2[link rot][awaiting moderator]in section: Protocol Overview
“https://web3.bitget.com/crypto-news/garden-finance-unlocks-bitcoin-liquidity-with-new-cross-chain-staking-solutions”
reviewerThe Bitget Wallet article cited as a source for Garden Finance's background is a live, working citationURL is dead with no archived version found. The underlying facts it was cited for (Dec 2023 launch, RenBTC lineage) remain supported by other live sources, but this specific citation should be removed since no live replacement carrying the same content was located. - #3[link rot][awaiting moderator]in the timeline
“https://web3.bitget.com/crypto-news/garden-finance-unlocks-bitcoin-liquidity-with-new-cross-chain-staking-solutions”
reviewerSame dead Bitget Wallet URL is used as the source for the timeline's launch entrySame underlying dead URL as the Protocol Overview section citation; grouped under the same defect_group.
partially supported
1 claimThe cited evidence supports part of the claim but not all of it.
- #14[partially supported][awaiting moderator]in section: Alleged Facilitation of Illicit Fund Flows
“ZachXBT further alleged that approximately 25% of the protocol's total bridged volume consisted of stolen funds, including proceeds from the Swissborg hack.”
reviewerZachXBT further alleged approximately 25% of Garden Finance's total bridged volume consisted of stolen funds, including proceeds from the Swissborg hackThe 25% figure the page uses matches the article's headline/lead framing, but the source itself contains an internally inconsistent higher figure (75%) elsewhere in the same piece that the page does not acknowledge.
confirmed
15 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Protocol Overview
“The protocol was launched in December 2023 and was developed by former members of the RenBTC core team, with co-founder Jaz Gulati among its publicly named leadership.”
reviewerGarden Finance launched in December 2023, developed by former RenBTC core team members including co-founder Jaz GulatiFact independently corroborated by multiple live sources, but the specific source cited on the page (Bitget Wallet article) is dead — see separate link_rot finding. - #4[confirmed][no action needed]in section: July 2026 Solver Database Exploit
“On July 26, 2026, at approximately 9:30 PM UTC, Web3 security firm Blockaid published an alert on X describing an active, ongoing exploit targeting Garden Finance's HTLC contracts across four blockchain networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.”
reviewerOn July 26, 2026 at approximately 9:30 PM UTC, Blockaid published an alert on X about an active exploit on Garden Finance's HTLC contracts across Ethereum, Base, Arbitrum and BNB Smart ChainTime, date and affected chains match cited reporting exactly. - #5[confirmed][no action needed]in section: July 2026 Solver Database Exploit
“Blockaid flagged the exploiter's wallet address (0x25b…6999), which Etherscan tagged with an exploit warning. The wallet held approximately $424,707.21 across the four chains, with 20 transactions logged at the time of reporting.”
reviewerThe exploiter wallet (0x25b...6999) held approximately $424,707.21 across four chains with 20 transactions logged, and was tagged by Etherscan with an exploit warningPrecise figures match the cited article word-for-word. - #6[confirmed][no action needed]in section: July 2026 Solver Database Exploit
“Garden confirmed total losses of approximately $450,000 in USDT. The protocol's core HTLC smart contracts were not modified or directly exploited.”
reviewerGarden confirmed total losses of approximately $450,000 in USDT and that HTLC smart contracts were not modified or exploitedConfirmed by primary reporting. - #7[confirmed][no action needed]in section: Technical Mechanism and Attack Vector
“Security firm zeroShadow noted in forensic findings from the 2025 incident that 'the incident originated from a leaked private key on a compromised device,' though the specific entry vector for the July 2026 database breach had not been publicly confirmed at time of reporting.”
reviewerzeroShadow's forensic findings on the October 2025 incident concluded 'the incident originated from a leaked private key on a compromised device'Direct quote and attribution to zeroShadow (as opposed to EY, which handled the SSH/IP forensics) is accurate. - #8[confirmed][no action needed]in section: Incident Response
“The protocol cited its SOC 2 Type II attestation controls in communications surrounding the incident.”
reviewerGarden engaged Blockaid, zeroShadow and Quantstamp, and cited its SOC 2 Type II attestation in communications about the July 2026 incidentConfirmed. - #9[confirmed][no action needed]in section: Prior Security Incident: October 2025 $11 Million Solver Breach
“Ernst & Young (EY), engaged by Garden for an independent forensic investigation, confirmed unauthorized access to the solver's infrastructure and identified suspicious SSH access from IP addresses with indicative locations in Japan and China.”
reviewerEY, engaged by Garden, confirmed unauthorized access and identified suspicious SSH access from IPs with indicative locations in Japan and China for the October 2025 breachConfirmed by the Decrypt forensic-findings writeup. - #10[confirmed][no action needed]in section: Prior Security Incident: October 2025 $11 Million Solver Breach
“Following the incident, Garden Finance implemented additional security controls including solver infrastructure isolation, expanded solver operators, formal security standards, and appointment of a dedicated CISO.”
reviewerFollowing the October 2025 breach, Garden implemented solver infrastructure isolation, expanded solver operators, formal security standards, and appointed a dedicated CISOConfirmed. - #11[confirmed][no action needed]in section: Prior Security Incident: October 2025 $11 Million Solver Breach
“ZachXBT alleged at the time that the compromised solver may have been operated by a Garden team member rather than a fully independent party, pointing to an on-chain message from a Garden deployer address stating 'our systems have been compromised.' Garden disputed this characterization.”
reviewerZachXBT alleged the compromised October 2025 solver may have been operated by a Garden team member, citing an on-chain message from a Garden deployer address stating 'our systems have been compromised', which Garden disputedThe page's short quote is a verbatim substring of the full on-chain message; attribution and the dispute are both accurate. - #12[confirmed][no action needed]in section: Alleged Facilitation of Illicit Fund Flows
“ZachXBT alleged in a June 2026 post on X that over 80% of the fees Garden Finance collected in a 12-day window ending June 2, 2026 — totaling 38.86 BTC and approximately $300,000 in revenue — came from laundering efforts involving assets stolen in the February 2025 Bybit hack, which was attributed to the Lazarus Group (a North Korea state-sponsored cybercriminal organization).”
reviewerZachXBT alleged in June 2026 that over 80% of fees Garden collected in a 12-day window ending June 2, 2026 (38.86 BTC, ~$300,000) came from laundering Bybit-hack proceedsFigures match the cited article precisely. - #13[confirmed][no action needed]in section: Alleged Facilitation of Illicit Fund Flows
“Co-founder Jaz Gulati disputed the ZachXBT claims, stating that 30 BTC in fees were collected before the Bybit incident, arguing that much of the revenue predated the alleged laundering activity.”
reviewerJaz Gulati disputed ZachXBT's claim, stating 30 BTC in fees were collected before the Bybit incidentConfirmed verbatim. - #15[confirmed][no action needed]in section: Alleged Facilitation of Illicit Fund Flows
“Security researcher Taylor Monahan, of MetaMask, separately alleged that a sizable portion of Garden Finance's bridging activity was carried out by North Korean cybercriminals.”
reviewerTaylor Monahan of MetaMask separately alleged a sizable portion of Garden Finance's bridging activity was carried out by North Korean cybercriminalsTaylor Monahan and 'Tayvano' are the same person; her MetaMask affiliation and independent allegation are accurately represented. - #17[confirmed][no action needed]in section: Systemic Risk: Solver Architecture and Off-Chain Trust Dependencies
“Crypto Briefing noted that despite audits by Trail of Bits, OtterSec, and Zellic, the protocol experienced 'fundamentally different types of attacks,' underscoring that traditional smart contract audits do not cover off-chain infrastructure vulnerabilities.”
reviewerCrypto Briefing noted that despite audits by Trail of Bits, OtterSec, and Zellic, the protocol experienced 'fundamentally different types of attacks'Direct quote confirmed against source. - #18[confirmed][no action needed]in section: Prior Security Incident: October 2025 $11 Million Solver Breach
“On October 30, 2025, an attacker drained approximately $11.4 million from one of Garden's largest independent solver operators. The breach was attributed by blockchain investigator ZachXBT and security firm zeroShadow to the North Korea-affiliated threat actor group tracked as 'DangerousPassword.'”
reviewerOn October 30, 2025, an attacker drained approximately $11.4 million from a Garden solver, attributed by ZachXBT and zeroShadow to the DPRK-affiliated 'DangerousPassword' groupThe $11.4M figure reflects later, more precise reporting than the initial ~$11M headline figure; both are consistent, not contradictory. - #19[confirmed][no action needed]in section: Prior Security Incident: October 2025 $11 Million Solver Breach
“Garden offered the attacker a 10% bounty for return of funds.”
reviewerGarden offered the attacker a 10% bounty for return of fundsConfirmed.