$3M Exploit Hits Polymarket: Users to Receive Full Refunds After Third-Party Breach

TheNewsCryptoPublished on 2026-06-26Last updated on 2026-06-26

Abstract

Polymarket will fully reimburse users affected by a front-end exploit that stole approximately $3 million in crypto assets. The company stated the incident was not a flaw in its core protocol but a supply chain attack. A compromised third-party vendor injected a malicious script into the platform's front-end for a limited number of users, allowing the attacker to drain funds from about 15 wallets while they interacted with the site. The stolen assets, primarily Polymarket's pUSD stablecoin, were bridged to Ethereum and converted to roughly 1,893 ETH. This marks the second security incident for Polymarket in under two months, following a separate $700,000 loss. The event highlights growing risks associated with third-party dependencies in the crypto industry.

The platform for predicting market users impacted by a website exploit that led to the theft of about $3 million in cryptocurrency assets will receive full reimbursement from Polymarket. The claim is that, instead of an issue with the underlying architecture of the platform, the incident was due to malware that was added to the front end of the platform by a compromised third-party vendor.

The malicious script was distributed to only a few selected individuals. It helped the attacker drain funds from the users’ wallets while interacting with the affected front-end. Then Polymarket declared that they were able to identify the cause of the issue, isolate the dependence and begin contacting the affected users.

“Our team discovered that a third-party vendor had been compromised, injecting a malicious script into our frontend for some users,” the company said in a statement. “We’ve contained it, removed the affected dependency, and are refunding impacted users in full.”

Around 15 Wallets Impacted as Stolen Funds Were Moved to Ethereum

An estimate that fewer than 15 user accounts were affected by the attack. Polymarket’s pUSD stablecoin, which the attacker bridged from Polygon to Ethereum before exchanging for about 1,893 ETH. It made up the majority of the stolen assets.

Instead of a direct violation of Polymarket’s smart contracts, security researchers characterised the event as a supply chain hack. This distinction shows that the platform’s core protocol was unaffected. Moreover, the attack used hacked third-party code on the website to target customers.

Even though the firm admits that the vulnerability has been patched, there is no information regarding which vendor has suffered due to the attack. Polymarket has not conducted a full technical analysis of the attack either.

Second Security Incident Raises New Concerns

Less than two months have passed since another security problem involving a wallet under company control that was used to give out user rewards. A compromised private key was allegedly the cause of the previous incident, which caused losses of about $700,000.

The current incident underscores the increasing hazards connected with third-party software dependencies. Even though Polymarket’s willingness to compensate impacted users may help restore confidence. Supply chain attacks are becoming a major security concern for the crypto sector. Also, it depends more and more on outside service providers.

Crypto Market Highlights

Cardano (ADA) Sends Mixed Signals: Is a Breakout Brewing or Another Drop Around the Corner?

TagsETHHackPolymarketprediction market

Related Questions

QWhat caused the $3M exploit on Polymarket and who will bear the financial loss?

AThe exploit was caused by a malicious script injected into the platform's front-end by a compromised third-party vendor. It was not a flaw in Polymarket's core protocol. Polymarket has stated it will provide full refunds to the impacted users, meaning the platform will bear the financial loss.

QHow did the attacker steal funds in the Polymarket exploit?

AThe attacker used a malicious script distributed to a limited number of users via the compromised front-end. This script drained funds from users' wallets as they interacted with the affected part of the website.

QApproximately how many users were affected by the Polymarket security breach, and what was the main asset stolen?

AIt is estimated that fewer than 15 user accounts (wallets) were affected. The majority of the stolen assets, worth about $3 million, consisted of Polymarket's pUSD stablecoin, which the attacker bridged to Ethereum and exchanged for approximately 1,893 ETH.

QHow did security researchers classify the Polymarket incident, and what does this mean for the platform's core protocol?

ASecurity researchers classified the incident as a supply chain hack. This means the attack originated from a compromised third-party dependency, not a direct breach of Polymarket's own smart contracts. Therefore, the platform's core protocol remained unaffected.

QWhat previous security incident had Polymarket experienced recently, and how does the current event highlight a broader industry risk?

ALess than two months prior, Polymarket experienced an incident where a compromised private key for a company-controlled wallet led to losses of about $700,000. The current event underscores the growing risk of supply chain attacks in the crypto industry, which is increasingly reliant on external service providers and third-party software.

Related Reads

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbit47m ago

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbit47m ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbit47m ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbit47m ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru6h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru6h ago

Trading

Spot
活动图片