Polymarket Confirms Hackers Drained $3 Million From Users After Third-Party Breach
Prediction-market platform Polymarket confirmed that hackers stole roughly $3 million from users following a compromise at a third-party vendor. The attackers injected malicious code into the platform’s frontend, enabling a phishing campaign that tricked victims into signing fraudulent transactions, which then drained funds from their connected wallets.
Polymarket stated that the incident has been fully contained, the affected dependency removed, and refunds are being initiated for affected users. The company emphasized that its core infrastructure and onchain markets were not breached—the vulnerability stemmed from a third-party supplier’s code served through Polymarket’s website.
Blockchain security firm Peckshield estimated the losses at approximately $3 million, affecting more than 11 victims. The attack is a classic supply-chain compromise, where attackers target a trusted vendor rather than directly attacking the platform itself. Because the malicious code resided in the website’s frontend, users who loaded the compromised page were prompted to approve transactions that appeared legitimate but instead handed control of their assets to the attackers.
Polymarket is now contacting victims individually and processing refunds rapidly, absorbing the cost to maintain user trust. The breach comes amid a surge in prediction market activity: Polymarket and rival Kalshi together drove a record month in April, with Polymarket processing over 100 million trades to date. The platform recently deployed Chainalysis surveillance tools to monitor market integrity, while U.S. lawmakers have probed prediction markets over insider-trading safeguards.
Source: https://news.bitcoin.com/polymarket-3-million-third-party-breach/