Web3 security firm Blockaid flagged an active exploit targeting Garden Finance’s cross-chain smart contracts, with roughly $450,000 in USDT drained across four EVM chains: Ethereum, Base, Arbitrum, and BNB Chain. This marks the protocol’s second major security incident in under a year, following a previous breach in late 2025 that resulted in estimated losses between $10.8 million and $11 million. The attack exploits a vulnerability in HTLC contracts used for cross-chain atomic swaps, suggesting a flaw in contract logic rather than an isolated bug on a single deployment. The protocol has been audited by Trail of Bits, OtterSec, and Zellic, but has now experienced fundamentally different types of attacks on distinct infrastructure layers.
Source: Read the original article

