Home/News/Garden Finance Disables App After $450,000 Exploit
CoinTelegraph3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Garden Finance Disables App After $450,000 Exploit

Garden Finance Disables App After $450,000 Exploit

Decentralized finance platform Garden Finance disabled its application on March 12, 2024, after a security exploit resulted in the loss of approximately $450,000 in Tether (USDT). The exploit targeted Garden Finance's Hash Time Locked Contracts (HTLCs) across multiple blockchain networks, including Ethereum, Base, Arbitrum, and BNB Smart Chain. Security firm Blockaid reported the incident, detailing how an attacker was able to drain the funds through vulnerabilities within these contracts. The HTLC mechanism is designed to facilitate trustless cross-chain transactions by requiring both parties to lock assets and providing a time limit for the transaction to be completed. If the transaction is not completed within the specified time, the assets are returned to their original owners. However, flaws in the implementation or the underlying smart contract logic can create opportunities for attackers to exploit these systems.

Blockaid's analysis indicated that the attacker specifically targeted the HTLC contracts, which are crucial for Garden Finance's cross-chain functionality. The exploit allowed the attacker to bypass the intended security measures and withdraw a significant amount of USDT. The exact technical details of the vulnerability have not been fully disclosed by Blockaid or Garden Finance, but the firm confirmed that the funds were successfully drained from the affected contracts. The incident highlights the ongoing security challenges faced by decentralized finance (DeFi) protocols, which often manage substantial amounts of user assets and are prime targets for malicious actors. The rapid growth of the DeFi sector has been accompanied by a rise in sophisticated exploits, leading to substantial financial losses for users and projects.

In response to the exploit, Garden Finance took immediate action to disable its application, preventing further potential losses and allowing time for an investigation. The company has not yet released a detailed statement regarding the incident or its plans for remediation and user compensation. The loss of $450,000 represents a significant blow to the platform and its users, underscoring the critical need for robust security audits and continuous monitoring of smart contract code. The multi-chain nature of the exploit means that users holding assets on Ethereum, Base, Arbitrum, and BNB Smart Chain who interacted with Garden Finance's HTLC contracts were potentially at risk. The incident serves as a stark reminder of the inherent risks associated with interacting with DeFi protocols, even those designed with advanced cryptographic mechanisms like HTLCs. The blockchain ecosystem continues to grapple with balancing innovation and security, with exploits like this prompting further scrutiny of development practices and auditing standards within the industry.

Original source — read the full reporting at the publisher:

Read on CoinTelegraph

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next