Crypto Prices

Garden Finance Suspends Services After Independent Solver Database Breach

50 minutes ago
1 min read
2 views

Garden Finance Security Incident

Garden Finance recently suspended access to its application following a significant security incident involving the off-chain database of one of its independent solvers. This breach led to the unauthorized withdrawal of approximately $450,000 in USDT from Garden Finance’s hash time-locked contracts (HTLCs) operating on various blockchains including Ethereum, Base, Arbitrum, and the BNB Smart Chain.

Details of the Breach

The blockchain security experts at Blockaid first alerted the community to the ongoing exploit, affirming that while the HTLCs had been compromised, the core protocol itself and user funds remained secure. Specifically, Blockaid reported that fraudulent transaction entries were manipulated, allowing the solver to release funds for swaps that had not actually been funded.

Response from Garden Finance

In response to this alarming incident, Garden Finance proactively took its application offline to facilitate further investigation and secure its operational framework. The company clarified that no user assets were at risk and that only those belonging to the compromised solver were affected. Furthermore, they are still assessing the total loss and determining which blockchain networks were involved.

Functionality of HTLC Contracts

Garden Finance explained that its HTLC contracts serve a crucial role as escrow solutions allowing for atomic swaps between Bitcoin and other blockchain assets. These contracts are designed to lock funds until specific conditions are satisfied; during this incident, the contracts themselves remained intact and operated correctly.

Security Measures and Future Steps

The company reassured its users that this situation was confined to the infrastructure of one independent solver and did not impact the wider network or threaten user investments. While the HTLCs were not exploited, it was the manipulated records in the compromised off-chain database that caused undue fund releases without proper counterparty actions.

To enhance security measures moving forward, Garden Finance has enlisted the expertise of cybersecurity firms including zeroShadow, Quantstamp, and Blockaid to aid in the recovery of the stolen assets. Additionally, the organization is working on restoring its services as soon as it completes the necessary security evaluations.

Industry Context

The incident with Garden Finance draws parallels with a recent breach experienced by Triple-A, a Singapore-based stablecoin payment firm, which also reported unauthorized access to treasury wallets causing losses to corporate assets while ensuring customer funds were protected.

This breach is just one of several security concerns emerging in the cryptocurrency sector, which has seen increased scrutiny and incidents of hacking. Earlier this year, Lien Finance disclosed losses due to vulnerabilities in its system that exploited loopholes in bond validation processes. The cryptocurrency landscape continues to confront these ongoing challenges, requiring vigilance and enhanced security measures to protect against future attacks.

Popular