A Hair Dryer Blows Away $34,000 from Polymarket

marsbitPubblicato 2026-04-23Pubblicato ultima volta 2026-04-23

Introduzione

A hairdryer was used to manipulate a temperature sensor at Paris Charles de Gaulle Airport (LFPG) on April 6 and 15, 2026, causing short-lived artificial temperature spikes. These false readings were used to exploit a prediction market on Polymarket, where users bet on Paris’s daily maximum temperature. The attacker targeted low-probability high-temperature outcomes, which settled as "Yes" based on the corrupted data, netting a total of $34,000 in profit. The attacker’s a newly created anonymous account funded just two days before the first incident. After the successful manipulations, the funds were quickly moved through mixers and decentralized exchanges to avoid tracing. French meteorological experts and authorities confirmed the anomalies were inconsistent with actual weather conditions and nearby station data, pointing to physical intervention. Legal action was initiated for "disrupting automated data processing systems," which carries severe penalties under French law. Polymarket’s market rules relied solely on a single, publicly accessible sensor and did not account for subsequent data revisions, making the system vulnerable to such physical oracle attacks. In response, Polymarket silently switched its data source to Paris-Le Bourget Airport (LFPB) without public explanation or refunding the exploited funds. The incident highlights the risks of single-point data dependencies in prediction markets and the low-cost, high-reward potential of real-world manipulation.

Author: 0x2333, The BlockBeats

A hair dryer, an unattended weather sensor, and two meticulously calculated operations.

On April 6 and April 15, 2026, a weather probe at the Météo-France station at Paris Charles de Gaulle Airport was heated with a portable heating device, causing the temperature readings to spike abnormally within a short period. The actual temperature at Charles de Gaulle Airport did not experience such fluctuations, but the prediction market betting on "Paris Daily Maximum Temperature" on Polymarket settled as usual. In two operations, a total of $34,000 in rewards was transferred from the platform to an anonymous account opened just two days before the incident.

This was not a typical crypto attack. It did not exploit any smart contract vulnerabilities, nor did it target any decentralized governance processes. The entire attack tool was just a hair dryer.

Temperature Spikes 4°C in 12 Minutes, How Did a Single Probe Deceive the Global Prediction Market?

Between 6:30 PM and 6:42 PM on April 6, the temperature reading at the Charles de Gaulle Airport weather station climbed 4°C in 12 minutes, peaking at 22.5°C, before rapidly dropping back within 5 minutes. The actual temperature in Paris that day did not show such drastic fluctuations, and no similar anomalies were recorded at other nearby weather stations.

This weather station (code: LFPG) is located at the edge of the Charles de Gaulle Airport runway, near a public area adjacent to a road. Its relatively open physical location made it possible for the suspect to approach the sensor and perform physical intervention.

This brief period of "high temperature"恰好 hit the "21°C" option on Polymarket, a previously almost ignored outcome. After the abnormal data was accepted by the platform as the day's maximum temperature, it settled to Yes. An account behind it took away approximately $14,000.

Nine days later, around 9:30 PM on April 15, almost the exact same script played out again. On a cloudy, windless night, the temperature reading at Charles de Gaulle Airport bizarrely climbed to 22°C. The probability of the "22°C" option on Polymarket soared from 0.1% to 95% in just 30 minutes. A second prize of over $20,000 flowed into the same account.

Paul Marquis, founder of French E-Meteo Service and a meteorologist, provided a technically almost irrefutable judgment: "There was no change in wind direction or relative humidity at the time, and no anomalies were recorded at other surrounding weather stations. Physical intervention is the most reasonable explanation, such as placing a heating device near the sensor probe."

Météo-France subsequently conducted a physical inspection of the sensor, found evidence of tampering, and formally filed a criminal complaint with the Roissy Air Transport Gendarmerie. The charge is "disrupting the operation of an automated data processing system." Under French law, this offense carries a maximum penalty of 7 years imprisonment and a fine of 300,000 euros.

The profile of the involved account is also questionable. It was created on April 4, 2026, just 48 hours before the first operation. The initial funds were only a few dozen dollars, transferred via a cryptocurrency exchange. It almost exclusively participated in the "Paris weather" market, specifically buying extremely low-probability "high temperature" options. After two successful attempts, the funds were quickly transferred through mixers and decentralized exchanges, making on-chain tracking significantly more difficult.

On one side is a common household hair dryer, retailing for less than 30 euros. On the other side is a global climate prediction market with a daily trading volume exceeding $2 million. The extreme asymmetry between the cost of the attack and the potential gain.

The abnormal data was first discovered by local French weather enthusiasts on the Infoclimat forum. The event was subsequently spread to the English-speaking crypto community, followed by reports from French media such as Le Monde, Le Figaro, and BFMTV. Polymarket officials have not issued any public statement on the matter, nor have they revoked the already paid $34,000 reward.

Rule Vulnerability, How Does a Single Sensor Reading Decide Six-Figure Prizes?

The true protagonist of this incident is not the hair dryer, but rather the settlement rules of Polymarket's weather market.

Polymarket's weather markets have grown rapidly in recent years, with the number of active markets now reaching 173, covering temperature, precipitation, hurricanes, tornadoes, earthquakes, volcanoes, and even pandemics. Among them, the "Paris Daily Maximum Temperature" market uses an extremely simple settlement mechanism, locking the data source to the readings from one specific weather station hosted on the Wunderground website.

Before this incident, this station was the Charles de Gaulle Airport weather station (code LFPG), with temperature rounded to the nearest whole degree Celsius. Most crucially, the market settles immediately after the data is finalized, and "does not consider any subsequent data revisions."

This last point means that even if Météo-France later discovers data anomalies and revises the historical records, Polymarket will still pay out rewards based on the contaminated original reading. The rules are written clearly and executed without ambiguity.

The vulnerability thus clearly presents itself in three points:

First, a single point of failure. The settlement of the entire six-figure prize pool relies entirely on the reading from one sensor. Polymarket did not design mechanisms for multi-station weighting, redundant comparison, or anomaly熔断. The so-called "data source" is that single metal probe by the runway at Charles de Gaulle Airport.

Second, physical accessibility. The Charles de Gaulle Airport weather station is located near the edge of the runway, adjacent to a public area next to a road, allowing any ordinary person to approach within meters of the probe. This geographical detail lowers the barrier to "physical intervention" from theoretical possibility to an almost zero-cost practical operation.

Third, the rigidity of the settlement mechanism. The invalidity of post-hoc revisions means that once an attack is successful, there is no possibility of "reversal." The rules ensure the certainty of settlement on one hand, but also guarantee that manipulation, once successful, is irreversible.

Fibo Crypto analyst Victor gave this technique a technically elegant name: "Physical Oracle Attack." Unlike previous "Digital Oracle Attacks" that targeted UMA governance votes and relied on large-scale token voting to manipulate oracle results, physical oracle attacks bypass the entire on-chain logic, acting directly on the first mile of the data pipeline—the metal probe in the real world.

On April 17, two days after the incident was exposed, Polymarket quietly completed a rule change, switching the settlement data source for the Paris weather market from Charles de Gaulle Airport (LFPG) to Paris-Le Bourget Airport (LFPB). The switch was not accompanied by any official announcement, public technical explanation, or any response to the two manipulations that had already occurred.

Changing a probe is much easier than publicly admitting a vulnerability. Polymarket's weather market was initially designed as a mirror, reflecting the market's collective judgment about the future. But when the image in the mirror is valuable enough, the odds steep enough, and the probe accessible enough, someone will always walk over with a 30-euro hair dryer and blow their desired result into it.

Crypto di tendenza

Domande pertinenti

QWhat was the method used to manipulate the temperature readings at Charles de Gaulle Airport?

AA portable heating device, such as a hairdryer, was used to artificially heat the meteorological sensor, causing a temporary spike in temperature readings.

QHow much money was stolen from Polymarket through this manipulation attacks?

AA total of $34,000 was stolen from the platform across two separate attacks.

QWhat specific vulnerability in Polymarket's system did this attack exploit?

AThe attack exploited a single point of failure in the settlement mechanism, which relied solely on the temperature reading from one specific, physically accessible weather station (LFPG) without any redundancy checks or mechanisms to account for data revisions.

QWhat action did Polymarket take after the attacks were discovered?

APolymarket quietly changed the data source for its Paris weather market from the Charles de Gaulle Airport station (LFPG) to the Paris-Le Bourget Airport station (LFPB) without making any public announcement or addressing the prior manipulations.

QWhat is the term used to describe this type of attack that targets the physical data source?

AThis type of attack is called a 'physical oracle attack,' which manipulates the real-world data source feeding into the prediction market, rather than exploiting a smart contract or governance vulnerability.

Letture associate

7 Months After the Collapse of Huiwang, Southeast Asia's Escrow Platforms Undergo a Major Reshuffle

Following the collapse of Huione Pay—dubbed the "Alipay of Southeast Asia"—seven months ago, the region's underground financial guarantee platform sector is undergoing a significant reshuffle. This power vacuum has been swiftly filled by emerging platforms such as XinBi, Tiger/Navigator, JinBei (renamed JinBo), Dali/Tiancheng, and FullyLight. These platforms, operating largely via Telegram and offering services like escrow for illicit transactions, have absorbed the vast user base and markets left behind by Huione. While positioning themselves as "trust intermediaries," their primary clientele consists of networks involved in online scams, money laundering, illegal gambling, and even human trafficking. For instance, the Tiger/Navigator platform explicitly provides "escrow" services for kidnapping-for-ransom operations ("强押车交易"). Data underscores the immense scale: Huione alone processed over $103 billion in cryptocurrency payments and facilitated over $31 billion through its escrow market before its downfall, linking it to Cambodia's notorious Prince Group. Since its collapse, competitors have seen explosive growth. For example, the XinBi platform has accumulated over $1.6 billion in total USDT revenue, while platforms like NewPay, OkPay (under Dali), and FullyLight Wallet collectively processed over $4.8 billion in USDT in a single year. This ecosystem thrives in regions like Cambodia and Myanmar, where regulatory gaps allow these platforms to act as critical financial infrastructure for sprawling cybercrime industries, from scam compounds to online casinos. The article concludes that the moniker "Southeast Asian Alipay" is a misnomer, obscuring the platforms' fundamental role in enabling serious criminal enterprises rather than representing legitimate financial innovation.

Odaily星球日报30 min fa

7 Months After the Collapse of Huiwang, Southeast Asia's Escrow Platforms Undergo a Major Reshuffle

Odaily星球日报30 min fa

The Changing Landscape: What Are Crypto VCs Experiencing?

Title: The Shifting Landscape of Crypto Venture Capital The era of dedicated crypto venture capital funds is undergoing a significant transformation. Once essential for navigating the sector's complexity and high risk, these specialized funds are now facing an identity crisis as the market matures. This shift mirrors historical patterns in other specialized investment classes like cleantech and SPACs, where initial information advantages dissipate as technologies become mainstream and integrated into existing industry frameworks. The article argues that crypto is reaching a critical inflection point, transitioning from a "building phase" to an "integration phase." Major players like Stripe, BlackRock, and Visa now engage with crypto not for its novel mechanics but as a foundational financial infrastructure. Their needs—regulatory compliance, banking partnerships, distribution channels—align with traditional fintech, a domain easily understood by large, generalist funds like Sequoia and Founders Fund. This evolution creates a "barbell effect" within the VC landscape. On one end are massive, diversified platforms that can incorporate crypto as one vertical among many. On the other are small, nimble funds focused on niche, experimental projects. The middle ground—medium-sized dedicated crypto funds—is being squeezed out. Their typical fund size makes it impossible to generate sufficient returns solely from early-stage crypto bets, yet they cannot compete with giants for later-stage deals. Consequently, leading crypto-native firms like Paradigm and Framework Ventures are expanding into AI, robotics, and other sectors, driven partly by LP pressure for better returns amid a broader VC DPI crisis. Others, like Dragonfly and a16z, have narrowed their crypto focus predominantly to financial infrastructure like stablecoins, reframing the sector's core narrative. For crypto entrepreneurs, this consolidation presents challenges. While generalist funds offer larger checks and broader resources, crypto projects now compete fiercely with AI for attention and capital within these firms. Furthermore, the long-term, non-commercial foundational work that built the ecosystem—funded by dedicated crypto VCs—is less likely to attract generalist capital focused on direct returns. The conclusion is that "crypto investor" as a standalone category is becoming obsolete, akin to "internet investor." Crypto is becoming a baseline infrastructure layer. The future will see a barbell structure: large-scale growth financing handled by generalist funds, while pioneering, speculative projects are funded by small, specialized vehicles. The dedicated crypto funds of the 2017-2021 boom, which incubated core infrastructure, are giving way to this new, bifurcated reality.

Foresight News47 min fa

The Changing Landscape: What Are Crypto VCs Experiencing?

Foresight News47 min fa

As Consensus Accelerates, What Are Young Investors Betting On?

Title: As Consensus Forms Faster, What Are Young Investors Betting On? In the rapid evolution of tech investment, a new generation of young investors is navigating a landscape where AI, robotics, commercial aerospace, and quantum computing are advancing simultaneously. Traditional investment logic based on financial models is giving way to a need for deep technical understanding and the ability to act before industry consensus forms. An analysis of trends from the "WAIC FUTURE TECH" list of young investment leaders reveals key shifts in focus. The first major trend is the movement of AI from the digital screen into the physical world. Investment is shifting from large language models and chatbots towards embodied AI, robotics, AI hardware, and edge computing. While demonstrations generate excitement, the real challenge lies in achieving scalable, reliable, and cost-effective delivery in complex real-world environments like factories and logistics. Success depends not just on algorithms but on the integration of sensors, actuators, and control systems. Second, the competitive focus for large models is moving beyond raw capability toward building an "intelligence flywheel." The goal is to create self-reinforcing systems where user interaction generates data, improving the model, which in turn enhances the user experience and attracts more engagement. Companies that successfully embed AI into workflows to create these closed-loop systems can build lasting value that isn't easily erased by the next model upgrade. Third, facing a potential bottleneck in high-quality human-generated data, investors are looking at new underlying technologies. Reinforcement learning and self-play, as demonstrated by AlphaGo Zero, offer paths for AI to generate its own experience. Scientific foundation models, which aim to build general AI capabilities for fields like life sciences and materials discovery, represent a non-consensus direction that could unlock new frontiers of knowledge and data. Finally, in deep-tech areas like quantum computing, commercial aerospace, and space-based infrastructure, patient capital is essential. These fields have long, uncertain development and validation cycles involving complex engineering, supply chains, and regulations. Investment here requires a long-term view, focusing on foundational team capabilities and the eventual emergence of market demand, even if commercial returns are distant. Collectively, these trends illustrate how young investors are adapting to a new era. They are learning to make earlier, technically-informed judgments, balance hype with real-world viability, and provide the patient capital needed to build the deep-tech foundations of the future.

marsbit1 h fa

As Consensus Accelerates, What Are Young Investors Betting On?

marsbit1 h fa

Trading

Spot

Articoli Popolari

Come comprare T

Benvenuto in HTX.com! Abbiamo reso l'acquisto di Threshold Network Token (T) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente Threshold Network TokenT.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva Threshold Network Token (T)Dopo aver acquistato Threshold Network Token (T), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia Threshold Network Token (T)Scambia facilmente Threshold Network Token (T) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

448 Totale visualizzazioniPubblicato il 2024.12.10Aggiornato il 2026.06.02

Come comprare T

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di T T sono presentate come di seguito.

活动图片