Backyard Finance Says Solver Breach Brought about $450K Drain

Backyard Finance Says Solver Breach Brought about 0K Drain



[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]

Backyard Finance stated an impartial solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to briefly take its app offline.

On Sunday, Blockaid said an attacker drained about $450,000 in USDT from Backyard’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Good Chain. HTLCs are time-bound escrow contracts that Backyard makes use of to facilitate atomic swaps between Bitcoin and belongings on different networks. Blockaid described the exploit as ongoing and revealed addresses linked to the attacker and affected contracts.

Nevertheless, a Backyard Finance spokesperson instructed Cointelegraph that neither the protocol nor its HTLC good contracts had been compromised. The corporate stated the attacker breached the off-chain database of an impartial solver and inserted fraudulent transaction data, inflicting the solver to launch funds for swaps that had not been funded by the counterparty.

Backyard stated no person funds had been misplaced or positioned in danger and that the incident affected solely solver-owned belongings. The corporate remains to be confirming the whole quantity, belongings and networks concerned. It stated providers had been paused as a precaution whereas the affected infrastructure was remoted and reviewed.

Blockaid acknowledged Cointelegraph’s request for feedback.

Backyard works with safety companies to hint funds

Backyard stated it’s working with zeroShadow, Quantstamp and Blockaid to hint and get better the funds. The protocol expects to revive services shortly, topic to finishing safety checks, however didn’t give a selected timeline.

“Backyard’s protocol and HTLC good contracts weren’t compromised, and no person funds had been misplaced or in danger,” the corporate instructed Cointelegraph, including that the incident was remoted to the off-chain infrastructure of 1 solver in its community of impartial solvers.

The corporate additionally pointed to its latest SOC 2 Kind II certification as proof of its funding in safety and operational controls. Backyard instructed Cointelegraph that its speedy priorities are securing the affected programs, tracing the solver’s funds and making certain providers resume solely after the related critiques are accomplished.

Associated: WEMIX says attacker moved about $724,000 after contract breach

The incident follows an October 2025 breach during which an attacker stole about $11.4 million after compromising the working surroundings of certainly one of Backyard’s solvers. Backyard stated that incident additionally didn’t have an effect on its protocol contracts or put person funds in danger.

Journal: Contained in the ‘faux police raid’ that pressured a $1M Bitcoin switch



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *