Polymarket Suffers $3M Hack via Compromised Third-Party Vendor
Polymarket, a prediction market platform, suffered a security breach on Thursday when hackers compromised a third-party vendor to inject malicious code into its front-end. The exploit resulted in the theft of approximately $3 million in customer funds, primarily in pUSD (a Polymarket-specific stablecoin backed by USDC), which was then converted to ETH and stored in a single Ethereum wallet. On-chain analysts at Bubblemaps confirmed that fewer than 15 user accounts were affected. Polymarket stated that the issue has been fixed and affected users will be fully reimbursed, but did not disclose which vendor was compromised. This is Polymarket's second security incident in two months, following a $700,000 loss from a private key compromise in May. Both incidents highlight vulnerabilities in third-party dependencies, even as core protocols remain secure.
Key facts
- Hackers compromised a third-party vendor to inject malicious code into Polymarket's front-end.
- Approximately $3 million in customer funds were stolen, mostly in pUSD stablecoin.
- Fewer than 15 user accounts were affected, according to Bubblemaps.
- Polymarket says affected users will be fully reimbursed and the issue is fixed.
- This is Polymarket's second security incident in two months, following a $700K private key hack.
KeyAudit data perspective
🔧 Check your seed against KeyAudit leak DB