Garden Finance 2025 solver infrastructure compromise
An attacker gained unauthorized access to an independent Garden solver’s operating environment and drained approximately $11.4 million in crypto assets belonging to the solver across multiple chains. Garden’s later forensic report states that protocol contracts were not compromised and no user funds were at risk.
Incident facts
- Incident title
- Garden Finance 2025 solver infrastructure compromise
- Bridge
- Garden Finance
- Incident date
- 2025-10-30
- Incident type
- Hack
- Major incident
- Yes
- Affected chains
- Ethereum, Arbitrum, Unknown
- Affected assets
- WBTC, USDC, USDT, ETH, Unknown
- Attack category
- Operator Or Governance Issue
- Reported loss
- about $11.4 million
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- None
- Reimbursement
- Not Applicable
- Restart
- Unknown
- Current outcome
- Active After Incident
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-09-01
- Last verified
- 2026-09-01
Amount and valuation
Garden reports approximately $11.4 million in crypto assets belonging to the independent solver were drained across multiple chains.
This is a solver-owned asset loss, not a user-fund loss or Garden protocol-contract loss.
solver-owned crypto assets drained across multiple chainsapproximately $11.4 million
Garden first-party incident report.
Why this remains unresolved
- Garden states that recovery efforts continued, but completed recovery of the drained solver-owned assets is not established.
Timeline events
Garden solver operating environment compromised2025-10-30
Unauthorized access to an independent solver operating environment led to approximately $11.4 million in solver-owned crypto assets being drained across multiple chains.
Garden states protocol contracts and user funds were unaffected.
Garden pauses user-facing services during 2025 response2025-10-30
Garden activated incident response and paused user-facing services as a precaution while isolating and investigating the solver compromise.
The pause is precautionary response evidence and does not imply protocol-contract compromise.
Evidence records
- Garden Incident Report — October 30, 2025Garden Finance · Tier 1 · High reliability · primary · 2026-01-28Claim scope: Incident Case
First-party incident report establishing October 30, 2025 solver-environment compromise, approximately $11.4M solver-owned loss, protocol/user-fund exclusion, response pause and continuing recovery efforts.
- Garden Finance shares forensic findings: Security breach limited to solver layerThe Block · Tier 2 · High reliability · secondary · 2026-01-29Claim scope: Incident Case
Corroborates the approximately $11.4M solver-owned loss and reports Garden/EY forensic findings that the breach was limited to solver infrastructure.
- Garden Incident Report — October 30, 2025Garden Finance · Tier 1 · High reliability · primary · 2026-01-28Claim scope: Incident Case
First-party Garden postmortem linked directly to the exploit/pause event; the existing primary record remains linked to the later investigation/recovery event.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact initial compromise method remains not fully established by the admitted first-party source.
- Attribution indicators are not treated as a legal attribution finding.
- A dated post-incident service reopening is not established in this bounded evidence package.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.