Garden Finance disabled its application after security firm Blockaid detected a $450,000 exploit targeting the protocol's infrastructure. The attack exploited a vulnerability in an independent solver's off-chain database, where an attacker inserted fraudulent swap records into the system.

Garden Finance emphasized that no user funds or smart contracts suffered direct compromise. The breach affected only the solver's external database, limiting the damage scope. The team moved quickly to contain the incident by taking the app offline, preventing further unauthorized transactions.

Solvers play a critical role in Garden Finance's architecture. These off-chain actors aggregate liquidity and route trades without directly controlling user assets. By compromising the solver's database, the attacker gained ability to fabricate transaction records and potentially redirect value flows through fraudulent swap orders.

Blockaid, a security monitoring platform for blockchain transactions, identified the breach and alerted Garden Finance. The firm specializes in detecting wallet drains and contract exploits before they execute at scale. Its early detection likely prevented larger losses.

The $450,000 figure represents the value extracted through the fraudulent swap records before the protocol shut down operations. The actual technical vector remains under investigation, but the attack pattern suggests the solver lacked sufficient database encryption or access controls to prevent unauthorized record insertion.

This incident highlights a growing vulnerability class in decentralized finance: off-chain infrastructure dependencies. Many protocols farm critical functions to external solvers, aggregators, and relayers to improve efficiency. When these third parties lack robust security practices, they become attack vectors that bypass smart contract audits and on-chain safeguards.

Garden Finance's response prioritized transparency by immediately disclosing the incident and clarifying that user funds remained safe. Protocols that control damage quickly and communicate clearly tend to recover user confidence faster than those that delay disclosure. The team now faces rebuilding trust while auditing their solver ecosystem for similar vulnerabilities.

This exploit serves