POLYMARKET CONFIRMS HACK! $3MN IN CRYPTO STOLEN FROM USERS
A third-party vendor compromise let hackers inject malicious code onto the site and drain accounts from an unspecified number of users.
by editor4 min readcomments soon

Polymarket confirmed that on Thursday hackers stole funds from an unspecified number of users after a third-party breach. The company said a compromise at a vendor allowed attackers to inject malicious code into the website "for some users". Blockchain monitoring firm PeckShield estimated the theft at roughly $3 million of cryptocurrency, and a blockchain analyst reported that funds were taken from more than 11 victims.
Polymarket spokesperson Connor Brandi confirmed the breach but declined to provide further details. The company said it has "contained" the incident and is now contacting affected users and "refunding them in full".
THE ATTACK VECTORS
Polymarket did not lose its own private keys or suffer a direct compromise of its smart contracts. Instead, a third-party vendor that the platform relied on was breached first. The attackers used that access to inject malicious code into Polymarket’s front-end for a subset of visitors. Users who interacted with the site during the window unknowingly authorised transactions that drained their wallets.
This is the classic supply-chain web attack, the same technique used against Ledger’s connector library in 2021 and dozens of DeFi front-ends since. It bypasses the platform’s core security because the injection happens at the presentation layer, before the user’s transaction reaches the blockchain. From the user’s perspective, the site looked normal, and the MetaMask or WalletConnect prompt looked legitimate.
The full scope is still unclear. Polymarket has not disclosed how many users were affected, how long the malicious code was live, or which third-party vendor was compromised. As of Thursday afternoon, the company had not published a post-mortem. The two people who publicly claimed their funds were stolen on social media are likely a fraction of the total.
IT'S BEEN A VERY BAD WEEK
Sunday’s revelation has already done damage to the platform’s reputation. An investigation found that Polymarket paid online creators to post videos showing they had won lucrative bets, but the wins were staged. The company said it would audit its promotional content, but the damage was done. Users and critics alike questioned the integrity of a platform that needed to manufacture success stories.
Now a real security breach has struck. A platform whose entire value proposition hinges on trust (that the oracle data is accurate, that the settlement is fair, that your funds are safe) has suffered two credibility blows in the same week. The first was a reputational blemish. The second is a direct financial hit to users.
THE NUMBERS
PeckShield’s estimate of $3 million in stolen crypto is a notable sum but not catastrophic for Polymarket, which processed billions in volume during the 2024 election cycle. What matters more is the number of victims, more than 11 by one analyst’s count, and how the company handles them. Polymarket says it is refunding victims in full, which is the correct move for retaining what goodwill remains. But refunding victims does not undo the breach, and it does not address the systemic question of why a third-party vendor had that level of access to the platform.
THE PLATFORM IS STILL UP THOUGH.
The company has not explained which third-party vendor was compromised, or how it plans to prevent a repeat. Until it publishes a thorough root-cause analysis, users have no way to evaluate whether their funds are safe on the platform. The promise of full refunds is only as good as the company’s willingness and ability to pay, and any delay in recovery or further revelations could trigger a run on withdrawals.
Meanwhile, the platform remains live. Users who want to withdraw their funds will have to weigh the risk of interacting with a site that was just compromised. The irony is that the injection was apparently limited in scope, but the uncertainty about the vendor and the attack window means every user has to wonder if they were exposed.
The two incidents this week, one about deception and one about theft, add up to a crisis of confidence. Surviving its own security and marketing decisions may prove harder.
what did you make of it?
more from cybersecurity
cybersecurity
TWO SCATTERED SPIDER HACKERS JAILED FOR 5.5 YEARS OVER TFL ATTACK
The attack cost London’s transport authority an estimated £29 million and forced 27,000 employees to reset passwords in person.
cybersecurity
SF CITY ATTORNEY DEMANDS APPLE AND GOOGLE REMOVE 13+ NUDIFY APPS
David Chiu sent cease-and-desist letters accusing the platforms of “aiding and abetting” the spread of nonconsensual intimate images.
cybersecurity
ASSURANCEAMERICA DATA BREACH EXPOSES OVER 6.9MN DRIVER'S LICENSE NUMBERS
A targeted phishing attack on a single employee kicked off a breach that went undetected for months.
cybersecurity
OPERA DID WHAT CHROME AND EDGE STILL STRUGGLE WITH
Opera's paste protect screens every copied command before it runs. no other major browser does this natively.





