Incident case

Garden Finance 2025 solver infrastructure compromise

An attacker gained unauthorized access to an independent Garden solver’s operating environment and drained approximately $11.4 million in crypto assets belonging to the solver across multiple chains. Garden’s later forensic report states that protocol contracts were not compromised and no user funds were at risk.

reviewedcurrent

Incident facts

Incident title
Garden Finance 2025 solver infrastructure compromise
Bridge
Garden Finance
Incident date
2025-10-30
Incident type
Hack
Major incident
Yes
Affected chains
Ethereum, Arbitrum, Unknown
Affected assets
WBTC, USDC, USDT, ETH, Unknown
Attack category
Operator Or Governance Issue
Reported loss
about $11.4 million
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
None
Reimbursement
Not Applicable
Restart
Unknown
Current outcome
Active After Incident
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-09-01
Last verified
2026-09-01

Amount and valuation

Garden reports approximately $11.4 million in crypto assets belonging to the independent solver were drained across multiple chains.

This is a solver-owned asset loss, not a user-fund loss or Garden protocol-contract loss.

Why this remains unresolved

Timeline events

  • Garden solver operating environment compromised2025-10-30

    Unauthorized access to an independent solver operating environment led to approximately $11.4 million in solver-owned crypto assets being drained across multiple chains.

    Hack DisclosedHigh

    Garden states protocol contracts and user funds were unaffected.

  • Garden pauses user-facing services during 2025 response2025-10-30

    Garden activated incident response and paused user-facing services as a precaution while isolating and investigating the solver compromise.

    Bridge PausedHigh

    The pause is precautionary response evidence and does not imply protocol-contract compromise.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.