Polymarket Hackers Steal User Funds in Third-Party Breach

Polymarket confirms user funds stolen after a third-party vendor compromise, with blockchain monitors estimating $3 million in losses.

By Central
Polymarket security breach leads to theft of cryptocurrency, highlighting supply-chain risks for prediction market users.
Highlights
  • The attack originated from a compromised third-party vendor that injected malicious code into the Polymarket website.
  • Blockchain security firm PeckShield reported approximately $3 million in cryptocurrency stolen from over eleven victims.
  • Polymarket is contacting affected victims to provide full refunds after containing the incident.

Polymarket, the leading prediction market platform, has confirmed that hackers successfully stole user funds following a compromise of a third-party vendor, marking a significant security incident in the crypto-gambling space. The breach, disclosed via an official post on X on Thursday, underscores the persistent risks posed by supply-chain attacks and the vulnerability of cryptocurrency wallets to targeted phishing campaigns.

Third-Party Vendor Compromise Led to Malicious Code Injection

According to Polymarket’s statement, the attack originated from a compromise at an external third-party vendor, which allowed unknown threat actors to inject malicious code into the Polymarket website for a subset of users. The company stated that it has now contained the incident and is actively contacting affected victims to provide full refunds. A Polymarket spokesperson confirmed to TechCrunch that the breach directly resulted in the theft of user funds but declined to provide further technical details or specifics regarding the number of victims.

The precise attack vector remains unclear, and Polymarket has not disclosed whether the injected code was designed to intercept wallet credentials, manipulate transaction data, or deploy a fake deposit interface. Security analysts note that third-party vendor compromises are particularly dangerous because they bypass the platform’s own security controls, often remaining undetected until users report suspicious activity.

Blockchain Monitors Report Approximately $3 Million in Cryptocurrency Stolen

Shortly after Polymarket’s disclosure, blockchain security firm PeckShield reported on X that an active phishing campaign was targeting Polymarket users, estimating losses of around $3 million worth of cryptocurrency. A separate blockchain analyst also reported similar loss figures, claiming that funds were stolen from more than eleven victims. These third-party estimates have not been independently verified, and Polymarket has not confirmed the total amount stolen. The incident follows two separate social media claims in recent days from users who alleged their Polymarket funds had been drained.

Breach Compounds Reputational Challenges for Polymarket

The hack arrives during a particularly turbulent week for Polymarket. On Sunday, an investigative report revealed that the company had paid online creators to post deceptive videos showing fabricated winning bets, misleading viewers about the真实性 of their winnings. Polymarket responded by stating it would audit its promotional content. This security breach now adds a significant trust and safety concern on top of the existing questions about the platform’s business practices. For a platform that offers users the ability to be paid in cryptocurrency, the integrity of its deposit and withdrawal systems is paramount.

What Affected Polymarket Users Should Do Now

If you have used Polymarket, particularly in the period surrounding the disclosed incident, take immediate protective steps. Assume the worst-case scenario regarding the potential exposure of account activity. The most critical action is to avoid interacting with any links or emails claiming to be from Polymarket, as threat actors often follow a breach with targeted phishing attempts. Change your Polymarket account password and any password that you reused across other services. Enable two-factor authentication using a hardware security key or an authenticator app, not SMS-based verification, on all associated email and exchange accounts. Scrutinize your transaction history on the blockchain for any unauthorized outgoing transfers. For future protection on any crypto-trading platform, store the majority of your assets in a hardware wallet (cold storage) rather than a connected exchange wallet. Treat any unsolicited communication about a refund or account freeze as a potential phishing attack until verified through official channels. Consider using a reputable VPN service with a verified no-logs policy when accessing any financial or cryptocurrency platform over public Wi-Fi to reduce exposure to network-level attacks. While no platform can guarantee absolute security, combining cold storage with strong, unique credentials and robust network hygiene significantly reduces your personal attack surface.

Share This Article