A Hair Dryer Blows Away $34,000 from Polymarket

marsbitPublicado a 2026-04-23Actualizado a 2026-04-23

Resumen

A hairdryer was used to manipulate a temperature sensor at Paris Charles de Gaulle Airport (LFPG) on April 6 and 15, 2026, causing short-lived artificial temperature spikes. These false readings were used to exploit a prediction market on Polymarket, where users bet on Paris’s daily maximum temperature. The attacker targeted low-probability high-temperature outcomes, which settled as "Yes" based on the corrupted data, netting a total of $34,000 in profit. The attacker’s a newly created anonymous account funded just two days before the first incident. After the successful manipulations, the funds were quickly moved through mixers and decentralized exchanges to avoid tracing. French meteorological experts and authorities confirmed the anomalies were inconsistent with actual weather conditions and nearby station data, pointing to physical intervention. Legal action was initiated for "disrupting automated data processing systems," which carries severe penalties under French law. Polymarket’s market rules relied solely on a single, publicly accessible sensor and did not account for subsequent data revisions, making the system vulnerable to such physical oracle attacks. In response, Polymarket silently switched its data source to Paris-Le Bourget Airport (LFPB) without public explanation or refunding the exploited funds. The incident highlights the risks of single-point data dependencies in prediction markets and the low-cost, high-reward potential of real-world manipulation.

Author: 0x2333, The BlockBeats

A hair dryer, an unattended weather sensor, and two meticulously calculated operations.

On April 6 and April 15, 2026, a weather probe at the Météo-France station at Paris Charles de Gaulle Airport was heated with a portable heating device, causing the temperature readings to spike abnormally within a short period. The actual temperature at Charles de Gaulle Airport did not experience such fluctuations, but the prediction market betting on "Paris Daily Maximum Temperature" on Polymarket settled as usual. In two operations, a total of $34,000 in rewards was transferred from the platform to an anonymous account opened just two days before the incident.

This was not a typical crypto attack. It did not exploit any smart contract vulnerabilities, nor did it target any decentralized governance processes. The entire attack tool was just a hair dryer.

Temperature Spikes 4°C in 12 Minutes, How Did a Single Probe Deceive the Global Prediction Market?

Between 6:30 PM and 6:42 PM on April 6, the temperature reading at the Charles de Gaulle Airport weather station climbed 4°C in 12 minutes, peaking at 22.5°C, before rapidly dropping back within 5 minutes. The actual temperature in Paris that day did not show such drastic fluctuations, and no similar anomalies were recorded at other nearby weather stations.

This weather station (code: LFPG) is located at the edge of the Charles de Gaulle Airport runway, near a public area adjacent to a road. Its relatively open physical location made it possible for the suspect to approach the sensor and perform physical intervention.

This brief period of "high temperature"恰好 hit the "21°C" option on Polymarket, a previously almost ignored outcome. After the abnormal data was accepted by the platform as the day's maximum temperature, it settled to Yes. An account behind it took away approximately $14,000.

Nine days later, around 9:30 PM on April 15, almost the exact same script played out again. On a cloudy, windless night, the temperature reading at Charles de Gaulle Airport bizarrely climbed to 22°C. The probability of the "22°C" option on Polymarket soared from 0.1% to 95% in just 30 minutes. A second prize of over $20,000 flowed into the same account.

Paul Marquis, founder of French E-Meteo Service and a meteorologist, provided a technically almost irrefutable judgment: "There was no change in wind direction or relative humidity at the time, and no anomalies were recorded at other surrounding weather stations. Physical intervention is the most reasonable explanation, such as placing a heating device near the sensor probe."

Météo-France subsequently conducted a physical inspection of the sensor, found evidence of tampering, and formally filed a criminal complaint with the Roissy Air Transport Gendarmerie. The charge is "disrupting the operation of an automated data processing system." Under French law, this offense carries a maximum penalty of 7 years imprisonment and a fine of 300,000 euros.

The profile of the involved account is also questionable. It was created on April 4, 2026, just 48 hours before the first operation. The initial funds were only a few dozen dollars, transferred via a cryptocurrency exchange. It almost exclusively participated in the "Paris weather" market, specifically buying extremely low-probability "high temperature" options. After two successful attempts, the funds were quickly transferred through mixers and decentralized exchanges, making on-chain tracking significantly more difficult.

On one side is a common household hair dryer, retailing for less than 30 euros. On the other side is a global climate prediction market with a daily trading volume exceeding $2 million. The extreme asymmetry between the cost of the attack and the potential gain.

The abnormal data was first discovered by local French weather enthusiasts on the Infoclimat forum. The event was subsequently spread to the English-speaking crypto community, followed by reports from French media such as Le Monde, Le Figaro, and BFMTV. Polymarket officials have not issued any public statement on the matter, nor have they revoked the already paid $34,000 reward.

Rule Vulnerability, How Does a Single Sensor Reading Decide Six-Figure Prizes?

The true protagonist of this incident is not the hair dryer, but rather the settlement rules of Polymarket's weather market.

Polymarket's weather markets have grown rapidly in recent years, with the number of active markets now reaching 173, covering temperature, precipitation, hurricanes, tornadoes, earthquakes, volcanoes, and even pandemics. Among them, the "Paris Daily Maximum Temperature" market uses an extremely simple settlement mechanism, locking the data source to the readings from one specific weather station hosted on the Wunderground website.

Before this incident, this station was the Charles de Gaulle Airport weather station (code LFPG), with temperature rounded to the nearest whole degree Celsius. Most crucially, the market settles immediately after the data is finalized, and "does not consider any subsequent data revisions."

This last point means that even if Météo-France later discovers data anomalies and revises the historical records, Polymarket will still pay out rewards based on the contaminated original reading. The rules are written clearly and executed without ambiguity.

The vulnerability thus clearly presents itself in three points:

First, a single point of failure. The settlement of the entire six-figure prize pool relies entirely on the reading from one sensor. Polymarket did not design mechanisms for multi-station weighting, redundant comparison, or anomaly熔断. The so-called "data source" is that single metal probe by the runway at Charles de Gaulle Airport.

Second, physical accessibility. The Charles de Gaulle Airport weather station is located near the edge of the runway, adjacent to a public area next to a road, allowing any ordinary person to approach within meters of the probe. This geographical detail lowers the barrier to "physical intervention" from theoretical possibility to an almost zero-cost practical operation.

Third, the rigidity of the settlement mechanism. The invalidity of post-hoc revisions means that once an attack is successful, there is no possibility of "reversal." The rules ensure the certainty of settlement on one hand, but also guarantee that manipulation, once successful, is irreversible.

Fibo Crypto analyst Victor gave this technique a technically elegant name: "Physical Oracle Attack." Unlike previous "Digital Oracle Attacks" that targeted UMA governance votes and relied on large-scale token voting to manipulate oracle results, physical oracle attacks bypass the entire on-chain logic, acting directly on the first mile of the data pipeline—the metal probe in the real world.

On April 17, two days after the incident was exposed, Polymarket quietly completed a rule change, switching the settlement data source for the Paris weather market from Charles de Gaulle Airport (LFPG) to Paris-Le Bourget Airport (LFPB). The switch was not accompanied by any official announcement, public technical explanation, or any response to the two manipulations that had already occurred.

Changing a probe is much easier than publicly admitting a vulnerability. Polymarket's weather market was initially designed as a mirror, reflecting the market's collective judgment about the future. But when the image in the mirror is valuable enough, the odds steep enough, and the probe accessible enough, someone will always walk over with a 30-euro hair dryer and blow their desired result into it.

Preguntas relacionadas

QWhat was the method used to manipulate the temperature readings at Charles de Gaulle Airport?

AA portable heating device, such as a hairdryer, was used to artificially heat the meteorological sensor, causing a temporary spike in temperature readings.

QHow much money was stolen from Polymarket through this manipulation attacks?

AA total of $34,000 was stolen from the platform across two separate attacks.

QWhat specific vulnerability in Polymarket's system did this attack exploit?

AThe attack exploited a single point of failure in the settlement mechanism, which relied solely on the temperature reading from one specific, physically accessible weather station (LFPG) without any redundancy checks or mechanisms to account for data revisions.

QWhat action did Polymarket take after the attacks were discovered?

APolymarket quietly changed the data source for its Paris weather market from the Charles de Gaulle Airport station (LFPG) to the Paris-Le Bourget Airport station (LFPB) without making any public announcement or addressing the prior manipulations.

QWhat is the term used to describe this type of attack that targets the physical data source?

AThis type of attack is called a 'physical oracle attack,' which manipulates the real-world data source feeding into the prediction market, rather than exploiting a smart contract or governance vulnerability.

Lecturas Relacionadas

AI Trading Cools, South Korean Stocks Plunge 1.8%, Spot Gold Rises 1%, Bitcoin Dives

A sell-off in AI-related stocks, triggered by Broadcom's disappointing earnings forecast, sent shockwaves through global markets. South Korea's KOSPI led Asia's decline, plunging 1.8% as the risks from concentrated chip stock gains and surging leveraged investments came to the fore. The tech-heavy Nasdaq 100 futures fell 0.5% following Broadcom's 14% after-hours plunge, which signaled a slower-than-expected transition to AI clients. This pullback extended Wall Street's weakness, halting the S&P 500's nine-day rally amid hawkish Fed signals and renewed Middle East tensions. South Korean authorities convened an emergency meeting, pledging "immediate measures" against market volatility and warning of record-high stock margin debt. The adjustment rippled across assets: Bitcoin fell to around $64,000, its lowest since February, while safe-haven gold rose 1% on bargain hunting. Oil prices dipped on Middle East ceasefire news. Market analysts noted the sell-off was driven by profit-taking after massive gains, particularly in chip stocks like Samsung and SK Hynix, which now dominate the KOSPI. Wall Street banks are divided on Korea's outlook, with Goldman Sachs raising its target while Citigroup and others warn of overvaluation and a potential bubble. Bridgewater's Ray Dalio noted that great technological shifts often create bubbles. Meanwhile, Fed officials' hints at potential future rate hikes added to the cautious mood ahead of key U.S. jobs data.

华尔街日报Hace 8 min(s)

AI Trading Cools, South Korean Stocks Plunge 1.8%, Spot Gold Rises 1%, Bitcoin Dives

华尔街日报Hace 8 min(s)

Seeking Alpha's Hot Article: Why Might the U.S. Stock Market Crash in June?

In a recent Seeking Alpha article, financial professor and analyst Damir Tokic argues that the US stock market may be poised for a significant crash in June 2026. The core thesis centers on a "mega-bubble" in equities, particularly within the technology sector, which has driven the S&P 500 to near-record valuations, with a Shiller P/E ratio exceeding 40—a level comparable to the 2000 dot-com bubble. Tokic identifies two primary catalysts for a potential collapse. First, he points to unsustainable market exuberance fueled by what he terms the "Trump Stimulus"—massive AI capital expenditure by tech giants, which he believes is politically driven and cannot last. Second, and more urgently, he highlights the escalating Iran war as a critical threat. The ongoing closure of the Strait of Hormuz has created a severe global energy supply crunch. Strategic petroleum reserves are projected to hit critically low operational levels by June, potentially causing oil prices to spike above $200 per barrel and triggering a severe, supply-driven inflationary shock. This scenario, Tokic warns, would force the Federal Reserve's hand. Despite currently maintaining a dovish bias, the Fed would likely be compelled to officially pivot to a hawkish stance at its June FOMC meeting to combat soaring inflation and bond yields. He contends that such a shift—or even a failure to act, which would destroy Fed credibility—could be the trigger that punctures the market bubble. The resulting downturn, he concludes, could rival the bear markets of 2000 and 2008, advising investors to prepare for a major correction.

marsbitHace 30 min(s)

Seeking Alpha's Hot Article: Why Might the U.S. Stock Market Crash in June?

marsbitHace 30 min(s)

AI PC Battle: Bet on the Toll Booth, Not the Camp

**Title:** The AI PC Battle: Don't Bet on Sides, Bet on the Tollbooth **Summary:** The AI PC competition is moving beyond simple "x86 vs. Arm" narratives. The core investment thesis should focus on identifying which players can sustain margins, cash flow, and pricing power throughout the upgrade cycle, rather than backing a particular architecture. The opportunity is analyzed in three layers: 1. **The Advanced Foundry Tollbooth:** TSMC is positioned to collect "tolls" regardless of which chip designer wins, due to its dominant ~70% share in advanced semiconductor manufacturing, which is essential for high-end AI PC chips. 2. **Compute & Platform Spillover:** AMD represents an offensive in the x86 CPU+GPU space, while NVIDIA leverages its GPU and CUDA software stack dominance. Both benefit from the demand for increased local AI compute. 3. **Architecture Diffusion & Turnaround Plays:** ARM and Intel offer potential for significant upside (elasticity), but investments here require stricter discipline due to higher execution risks and competitive challenges. The industry is transitioning from concept to shipment validation. While short-term forecasts for AI PC adoption have been revised down slightly due to tariffs and procurement delays, the long-term trend towards AI becoming a standard PC feature remains intact. The key driver for upgrade cycles will be whether compelling enterprise applications (e.g., privacy-sensitive computing, low-latency inference) emerge beyond consumer-focused features like meeting summarization. Investment strategy should prioritize companies with platform-level advantages and recurring revenue streams. TSMC offers high certainty as the foundational tollbooth. AMD presents a strong offensive play within the established ecosystem. ARM and Intel are higher-risk, higher-potential-reward turnaround bets. The report cautions against chasing short-term hype and emphasizes a disciplined, long-term approach focused on buying ecosystem strength and cash-flow certainty after market enthusiasm subsides. **Key Risks:** Underwhelming AI PC applications slowing upgrade cycles; slow improvement in Windows on Arm compatibility; macro/tariff impacts on PC demand; potential advanced node supply-demand mismatches affecting TSMC; high overall AI sector valuations making stocks vulnerable to a risk-off shift in markets.

marsbitHace 44 min(s)

AI PC Battle: Bet on the Toll Booth, Not the Camp

marsbitHace 44 min(s)

Ten-Thousand-Word Analysis: From $10 to $290, MRVL Wins the Entire AI Era by 'Not Making GPUs'

Marvell Technology's stock price surged from under $10 in 2016 to a record $290 in June 2026, fueled not by making GPUs, but by dominating AI infrastructure connectivity. This analysis argues the market misvalues MRVL as merely a smaller Broadcom in custom AI chips, overlooking its true, unique position. Marvell's core strength lies in enabling high-speed data flow for AI clusters through three interconnected businesses. First, it holds a commanding ~70% market share in high-speed optical DSPs (essential for data center light modules), a deep-moat business with accelerating growth. Second, its custom AI chip design business serves hyperscalers like AWS, Microsoft, and Google, with a significant revenue pipeline despite lower margins. Third, stable cash flows come from Ethernet switch chips and enterprise storage controllers. Together, they form a full-stack "AI data movement" platform. CEO Matt Murphy's transformative leadership since 2016, involving strategic divestments, key acquisitions (like Inphi for optical DSPs), and securing long-term agreements with major cloud providers, repositioned the company. A pivotal $2 billion strategic investment from NVIDIA in 2026 underscored Marvell's critical role in the AI ecosystem, particularly through collaborations like NVLink Fusion. While Marvell faces risks—including client concentration (losing the Amazon Trainium3 design), lower-margin business mix, competitive threats, insider selling, and complex supply chains—its fundamentals remain strong. The optical interconnect moat is widening with the acquisition of Celestial AI (photonics fabric), and financial metrics show accelerating revenue growth and operating leverage. With a PEG ratio suggesting undervaluation relative to its growth, the thesis is that the market undervalues Marvell's monopolistic position in AI "plumbing" while overemphasizing its competitive custom chip segment. The story transcends investing, symbolizing how in any complex system—from the internet to AI—the value of "connection" ultimately surpasses that of individual "nodes."

marsbitHace 1 hora(s)

Ten-Thousand-Word Analysis: From $10 to $290, MRVL Wins the Entire AI Era by 'Not Making GPUs'

marsbitHace 1 hora(s)

Trading

Spot
Futuros

Artículos destacados

Cómo comprar T

¡Bienvenido a HTX.com! Hemos hecho que comprar Threshold Network Token (T) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Threshold Network Token (T) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Threshold Network Token (T)Después de comprar tu Threshold Network Token (T), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Threshold Network Token (T)Tradear fácilmente con Threshold Network Token (T) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

599 Vistas totalesPublicado en 2024.12.10Actualizado en 2026.06.02

Cómo comprar T

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de T (T).

活动图片