#What Is the Current Situation with Garden Finance?
Currently, Garden Finance is facing a significant security threat. The Web3 security firm Blockaid has identified an ongoing exploit targeting its smart contracts. This incident has already resulted in approximately $450,000 in USDT being drained across four different Ethereum Virtual Machine-compatible blockchains. The affected networks include Ethereum, Base, Arbitrum, and BNB Chain, indicating a multi-faceted attack that is still active as of detection.
This follows a previous breach where Garden Finance suffered an estimated loss of between $10.8 million and $11 million. Given these consecutive security incidents, it's reasonable to question whether these vulnerabilities reveal a troubling pattern rather than just unfortunate luck.
#How Did the Exploit Occur?
The recent exploit leverages Hash Time Locked Contracts, or HTLCs, which are essentially used for facilitating cross-chain atomic swaps. HTLCs function like digital escrow platforms where two parties lock assets on different blockchain networks, and the swap process is contingent upon both sides meeting predefined conditions within a specified timeframe.
Blockaid has concluded that the attacker was able to drain USDT from these HTLC contracts by exploiting weaknesses in the contract's logic across multiple networks. This indicates that the issue is rooted in how the smart contracts were designed or deployed, rather than being merely a localized bug within one specific blockchain environment.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#What Is The Security History of Garden Finance?
Garden Finance has a history of undergoing comprehensive security audits by reputable firms such as Trail of Bits, OtterSec, and Zellic. Despite these audits, the protocol has proven vulnerable to breaches, which raises questions about its security efficacy.
The protocol operates across a variety of blockchains including Ethereum, Solana, Base, Arbitrum, and BNB Chain, primarily focusing on enabling rapid cross-chain swaps. Notably, the earlier breach was linked to a compromised solver, thus marking a different attack vector compared to this recent exploit.
#What Should Investors Do?
For investors with funds allocated within Garden Finance, the prudent course of action is to withdraw those funds until the ongoing exploit is thoroughly investigated and resolved. The designation of this incident as an ongoing attack implies that the vulnerability may still be at risk of being exploited.
Garden Finance now finds itself grappling with two major security breaches in under a year, with significant financial implications. While the current loss of $450,000 is less severe than the prior incident, the underlying issues remain a cause for concern.