Garden hack — October 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 30, 2025 |
| Target type | Cross-chain bridge |
| Loss | $11,400,000Published estimates range $10,800,000 to $11,400,000Price at time of incident |
| Method | Private key compromiseAn attacker obtained the SSH key of an independent solver operator running infrastructure for Garden's cross-chain swap protocol, gained root access to the server, and located the solver's hot-wallet private key stored in an environment variable. The key was then used to sweep the solver's balances across several chains, with proceeds bridged out via Mayan. No Garden protocol contract was compromised. |
| Chains | Multiple chains |
| Attributed to | DangerousPassword (also tracked as CryptoCore, Sapphire Sleet, UNC1069), a North Korea-affiliated threat actorSuspected |
| Outcome | Unresolved |
What happened
Garden, a cross-chain swap protocol, lost roughly $11 million on 30 October 2025 when the server of one of its independent solvers was taken over. Garden's own incident report puts the window between 10:47 and 11:06 CET and the amount drained at approximately $11.4 million. Investigator ZachXBT, who flagged the outflows publicly, and CertiK, which tracked the funds afterwards, described the loss as about $10.8 million.
According to Garden's report the attacker obtained the solver operator's SSH key, gained root access to the machine, and found the solver's private key stored in an environment variable. That key was then used to drain balances across multiple chains, with assets bridged out via Mayan. Solvers in Garden's design hold their own inventory to fill user swaps, so what was taken was the solver's working capital; Garden says no protocol contract was compromised and no user funds were at risk.
That framing was disputed at the time. ZachXBT argued the team was downplaying the incident, and pointed to an on-chain message sent to the attacker from a Garden deployer address stating that the project's systems had been compromised across multiple blockchains. A 10% white-hat bounty went unanswered and the attacker moved 501 BNB and 1,910 ETH, about $6.65 million, through Tornado Cash.
Garden published forensic findings on 29 January 2026. Ernst & Young reported that SSH authentication logs on the solver server showed suspicious access from four IP addresses geolocating to Japan and China on the day of the incident, and zeroShadow assessed that the indicators and laundering patterns were consistent with attacks attributed to the North Korea-affiliated actor it tracks as DangerousPassword. No funds have been recovered.
Sources
- GardenPrimary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- AMBCrypto (reporting CertiK tracking and ZachXBT findings)Secondary · retrieved 2026-08-01
- The Coin RepublicSecondary · retrieved 2026-08-01
Official post-mortem: https://garden.finance/blog/garden-incident-report-october-30-2025
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Garden hack — October 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/garden-financehttps://itokenly.com/hacks/garden-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.