Polymarket hacked: $3 million in user funds stolen
Prediction market Polymarket reports that hackers injected malicious code into the website via a compromised external vendor. As a result, attackers managed to steal approximately $3 million in user funds. This is the second security incident at the platform in less than two months.
Ethereum is available at OKX and Bybit.
Malicious Code Injected into the Frontend
The attack took place after a third party with which Polymarket works was compromised. Through this vulnerability, the hackers succeeded in placing malicious code into the frontend of the website. Polymarket itself declined to confirm to Decrypt which vendor was the victim, but acknowledged that the attack occurred via this route.
Onchain analysis shows that fewer than fifteen accounts were affected. The stolen assets consist mainly of pUSD, the platform’s own stablecoin. The attackers subsequently swapped these funds for Ethereum, which currently stands at $1.550. a decline of 5.2% over the past 24 hours.
Polymarket Fully Compensates Affected Users
Polymarket said in a post on X that the vulnerability has now been fixed. The company promises that all affected users will be fully reimbursed for their stolen funds. The exact details of how and when the compensation will take place have not yet been shared by the platform.
This incident comes at a time when prediction markets are very much in the spotlight. For instance, CBOE recently launched CBOE Predicts, a new platform in this segment. The Polymarket hack shows that the security of the entire supply chain remains a point of focus, even for established players in the market.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.