USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

$450,000 USDT Flows Out of Garden Finance Bridge: Shutdown, HTLC, and Contagion Risk for U-Card Top-Up Paths

2026-07-28

Cross-chain bridge protocol Garden Finance fully suspended its app service on July 26, local time, after receiving a security alert. Blockchain security firm Blockaid disclosed the same day that roughly $450,000 in USDT-equivalent value had been drained from Garden Finance’s hash time-locked contracts (HTLC), affecting four networks — Ethereum, Base, Arbitrum, and BNB Smart Chain. Blockaid published the attacker’s address and the affected contract addresses while the attack was still in progress. Garden Finance said the shutdown was a precautionary step to “isolate and inspect the compromised infrastructure.” Korean outlet Tokenpost, citing Cointelegraph, reported that the issue traced to a breach in the ledger layer of its solvers (matching agents) — see the original Tokenpost report.

Editorial take: it’s not your card balance that’s affected — it’s your top-up path

Let’s draw the boundary clearly first: this is not an incident involving any card issuer, nor a problem with USDT itself. Tether’s reserves, redemption process, and its Omni/TRC20/ERC20 contracts across networks are all unchanged. At $450,000, the absolute scale is small by the standards of bridge incidents and isn’t large enough to produce any observable effect on USDT’s secondary-market price.

What actually concerns U-card users is the on-chain provenance of funds. The top-up flow for most USDT virtual cards runs: exchange or wallet → on-chain transfer → issuer’s custodial address. If you’re in the habit of using a cross-chain bridge to move assets from Base/Arbitrum to whichever network your issuer supports for top-ups (usually TRC20 or ERC20), then funds that passed through Garden Finance around July 26 have, in theory, a very small probability of an indirect hop-based association with a flagged address. Card issuers and their acquiring partners generally run screening through providers like Chainalysis, Elliptic, or TRM. A deposit flagged as being “N hops from a tagged address” is most commonly handled not by freezing the card, but by holding the deposit and requesting supplementary source-of-funds documentation.

Reasonable expectations for the timeline ahead:

As for specific cards: users on Asia-Pacific routing who top up mainly through the in-app MPChat wallet — the MPCard (Asia Elite variant) — and who have always followed the “exchange withdrawal → direct top-up” path have no exposure and don’t need to do anything. Users who spread assets across multiple L2s and habitually consolidate through bridges before topping up — whether holding a Bybit Card or an OKX Card — should switch to internal exchange transfers this week (no on-chain hop, no screening hop) rather than a third-party bridge. Readers unsure why a top-up path would ever affect card approval can start with the section on custodial addresses and deposit screening in What Is a U-Card.

Historical comparison: small, fast, attributable — this is not the 2022-style bridge disaster

Placed on the spectrum of bridge incidents, the 2022 cases — Ronin ($625 million), Wormhole ($325 million), and Nomad (~$190 million) — involved entire validator sets or message-verification logic being bypassed wholesale, with amounts large enough to trigger ecosystem-level liquidity events. The 2023 Multichain incident was different in kind: loss of operator control over private keys, which caused large volumes of bridged assets (including bridged USDT/USDC) to lose their underlying redeemability, leaving many users holding mapped tokens that could no longer be redeemed. That is the scenario that would genuinely propagate into card top-up assets.

This incident differs in three ways:

  1. Scale is small — $450,000 doesn’t raise any question of protocol solvency.
  2. The attack hit the HTLC + solver ledger layer, a bookkeeping trust surface specific to intent/solver architecture — not a loss of custodial private keys. Users aren’t left holding “unbacked mapped USDT.”
  3. Response was fast — a third-party monitor published addresses while the attack was still underway, and the project shut down operations the same day.

What hasn’t changed: bridges remain the weakest link in stablecoin cross-chain transfers. Three years on, the attack surface has shifted from multisigs and message verification to solvers and matching ledgers, but the conclusion is the same — every time USDT crosses a bridge, it accumulates one more layer of traceable, potentially flaggable history.

Compliance view: where the gray zone sits

On the regulatory side, this incident doesn’t introduce any new rule, but it reinforces an existing trend: VASP requirements for tracing the source of incoming funds are expanding from “direct counterparty” to “multi-hop association.” For source-of-funds tracing requirements under Hong Kong’s VASP regime and travel-rule provisions, see our Hong Kong compliance guide; for the comparable approach under Singapore’s MAS framework for DPT service providers, see our Singapore compliance guide.

One boundary is worth stating clearly: using a cross-chain bridge is not, in itself, prohibited in either jurisdiction — that is clearly legal territory. The gray zone arises when a deposit’s on-chain history shows an association with a publicly flagged attacker address; the card issuer has both the right and the obligation to request further explanation, and may freeze that deposit if no adequate explanation is provided. That’s not the same as “banning” a card, but it does mean the 200 ₮ you meant to use for a subscription renewal could get stuck for a few days. The one clearly prohibited act is transferring or exchanging funds while knowing they originated from stolen assets.

Milestones worth watching

Editorial recommendations

MPCard holders who have always topped up via direct exchange withdrawal: no action needed.

Users who bridged through Garden Finance in the past 7 days and topped up that USDT into any virtual card: there’s no need to panic or proactively self-report, but keep complete records of that fund’s origin — exchange withdrawal records, bridge transaction hashes, timestamps. Users who can supply a complete chain-of-custody trail in a single response, if questioned, almost always get the hold lifted within a few business days.

Users planning a USDT cross-chain top-up this week: change the route. Prefer internal exchange transfers across networks, or withdraw directly from an exchange onto whichever network your card issuer supports. Save third-party bridges for long-tail assets with no CEX alternative. This is especially true for readers who pay fixed subscriptions with a U-card — saving a few dollars in bridge fees isn’t worth having your ChatGPT Plus renewal (officially $20/month) get stuck on billing day.

What not to do: don’t send any new transactions to Garden Finance’s contracts before a recovery announcement is out; don’t respond to any direct message claiming to “help recover your assets from the bridge” — after every past bridge incident, phishing sites have shown up faster than the official post-mortem.