![]()
[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]
Backyard Finance mentioned an impartial solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to quickly take its app offline.
On Sunday, Blockaid mentioned an attacker drained about $450,000 in USDT from Backyard’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Good Chain. HTLCs are time-bound escrow contracts that Backyard makes use of to facilitate atomic swaps between Bitcoin and belongings on different networks. Blockaid described the exploit as ongoing and printed addresses linked to the attacker and affected contracts.
Nevertheless, a Backyard Finance spokesperson informed Cointelegraph that neither the protocol nor its HTLC sensible contracts had been compromised. The corporate mentioned the attacker breached the off-chain database of an impartial solver and inserted fraudulent transaction information, inflicting the solver to launch funds for swaps that had not been funded by the counterparty.
Backyard mentioned no consumer funds had been misplaced or positioned in danger and that the incident affected solely solver-owned belongings. The corporate continues to be confirming the entire quantity, belongings and networks concerned. It mentioned companies had been paused as a precaution whereas the affected infrastructure was remoted and reviewed.
Blockaid acknowledged Cointelegraph’s request for feedback.
Backyard works with safety corporations to hint funds
Backyard mentioned it’s working with zeroShadow, Quantstamp and Blockaid to hint and recuperate the funds. The protocol expects to revive companies shortly, topic to finishing safety checks, however didn’t give a selected timeline.
“Backyard’s protocol and HTLC sensible contracts weren’t compromised, and no consumer funds had been misplaced or in danger,” the corporate informed Cointelegraph, including that the incident was remoted to the off-chain infrastructure of 1 solver in its community of impartial solvers.
The corporate additionally pointed to its current SOC 2 Kind II attestation as proof of its funding in safety and operational controls. Backyard informed Cointelegraph that its quick priorities are securing the affected methods, tracing the solver’s funds and making certain companies resume solely after the related opinions are accomplished.
Associated: WEMIX says attacker moved about $724,000 after contract breach
The incident follows an October 2025 breach by which an attacker stole about $11.4 million after compromising the working setting of considered one of Backyard’s solvers. Backyard mentioned that incident additionally didn’t have an effect on its protocol contracts or put consumer funds in danger.
Journal: Contained in the ‘pretend police raid’ that compelled a $1M Bitcoin switch

