skip to content
ai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILURE
BAD/GATEWAY*

POLYMARKET CONFIRMS HACK! $3MN IN CRYPTO STOLEN FROM USERS

A third-party vendor compromise let hackers inject malicious code onto the site and drain accounts from an unspecified number of users.

by editor4 min readcomments soon

polymarket confirms hack, $3 million in crypto stolen from users
· Image credit: Reuters

Polymarket confirmed that on Thursday hackers stole funds from an unspecified number of users after a third-party breach. The company said a compromise at a vendor allowed attackers to inject malicious code into the website "for some users". Blockchain monitoring firm PeckShield estimated the theft at roughly $3 million of cryptocurrency, and a blockchain analyst reported that funds were taken from more than 11 victims.

Polymarket spokesperson Connor Brandi confirmed the breach but declined to provide further details. The company said it has "contained" the incident and is now contacting affected users and "refunding them in full".

THE ATTACK VECTORS

Polymarket did not lose its own private keys or suffer a direct compromise of its smart contracts. Instead, a third-party vendor that the platform relied on was breached first. The attackers used that access to inject malicious code into Polymarket’s front-end for a subset of visitors. Users who interacted with the site during the window unknowingly authorised transactions that drained their wallets.

This is the classic supply-chain web attack, the same technique used against Ledger’s connector library in 2021 and dozens of DeFi front-ends since. It bypasses the platform’s core security because the injection happens at the presentation layer, before the user’s transaction reaches the blockchain. From the user’s perspective, the site looked normal, and the MetaMask or WalletConnect prompt looked legitimate.

The full scope is still unclear. Polymarket has not disclosed how many users were affected, how long the malicious code was live, or which third-party vendor was compromised. As of Thursday afternoon, the company had not published a post-mortem. The two people who publicly claimed their funds were stolen on social media are likely a fraction of the total.

IT'S BEEN A VERY BAD WEEK

Sunday’s revelation has already done damage to the platform’s reputation. An investigation found that Polymarket paid online creators to post videos showing they had won lucrative bets, but the wins were staged. The company said it would audit its promotional content, but the damage was done. Users and critics alike questioned the integrity of a platform that needed to manufacture success stories.

Now a real security breach has struck. A platform whose entire value proposition hinges on trust (that the oracle data is accurate, that the settlement is fair, that your funds are safe) has suffered two credibility blows in the same week. The first was a reputational blemish. The second is a direct financial hit to users.

THE NUMBERS

PeckShield’s estimate of $3 million in stolen crypto is a notable sum but not catastrophic for Polymarket, which processed billions in volume during the 2024 election cycle. What matters more is the number of victims, more than 11 by one analyst’s count, and how the company handles them. Polymarket says it is refunding victims in full, which is the correct move for retaining what goodwill remains. But refunding victims does not undo the breach, and it does not address the systemic question of why a third-party vendor had that level of access to the platform.

THE PLATFORM IS STILL UP THOUGH.

The company has not explained which third-party vendor was compromised, or how it plans to prevent a repeat. Until it publishes a thorough root-cause analysis, users have no way to evaluate whether their funds are safe on the platform. The promise of full refunds is only as good as the company’s willingness and ability to pay, and any delay in recovery or further revelations could trigger a run on withdrawals.

Meanwhile, the platform remains live. Users who want to withdraw their funds will have to weigh the risk of interacting with a site that was just compromised. The irony is that the injection was apparently limited in scope, but the uncertainty about the vendor and the attack window means every user has to wonder if they were exposed.

The two incidents this week, one about deception and one about theft, add up to a crisis of confidence. Surviving its own security and marketing decisions may prove harder.


what did you make of it?

share

more from cybersecurity