![]()
[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]
Backyard Finance stated an unbiased solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to quickly take its app offline.
On Sunday, Blockaid stated an attacker drained about $450,000 in USDT from Backyard’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Sensible Chain. HTLCs are time-bound escrow contracts that Backyard makes use of to facilitate atomic swaps between Bitcoin and property on different networks. Blockaid described the exploit as ongoing and printed addresses linked to the attacker and affected contracts.
Nevertheless, a Backyard Finance spokesperson advised Cointelegraph that neither the protocol nor its HTLC good contracts had been compromised. The corporate stated the attacker breached the off-chain database of an unbiased solver and inserted fraudulent transaction data, inflicting the solver to launch funds for swaps that had not been funded by the counterparty.
Backyard stated no consumer funds had been misplaced or positioned in danger and that the incident affected solely solver-owned property. The corporate continues to be confirming the overall quantity, property and networks concerned. It stated providers had been paused as a precaution whereas the affected infrastructure was remoted and reviewed.
Blockaid acknowledged Cointelegraph’s request for feedback.
Backyard works with safety corporations to hint funds
Backyard stated it’s working with zeroShadow, Quantstamp and Blockaid to hint and get well the funds. The protocol expects to revive providers shortly, topic to finishing safety checks, however didn’t give a particular timeline.
“Backyard’s protocol and HTLC good contracts weren’t compromised, and no consumer funds had been misplaced or in danger,” the corporate advised Cointelegraph, including that the incident was remoted to the off-chain infrastructure of 1 solver in its community of unbiased solvers.
The corporate additionally pointed to its latest SOC 2 Sort II attestation as proof of its funding in safety and operational controls. Backyard advised Cointelegraph that its speedy priorities are securing the affected programs, tracing the solver’s funds and making certain providers resume solely after the related evaluations are accomplished.
Associated: WEMIX says attacker moved about $724,000 after contract breach
The incident follows an October 2025 breach wherein an attacker stole about $11.4 million after compromising the working atmosphere of certainly one of Backyard’s solvers. Backyard stated that incident additionally didn’t have an effect on its protocol contracts or put consumer funds in danger.
Journal: Contained in the ‘faux police raid’ that compelled a $1M Bitcoin switch