K

KeyAudit

· ·phishing·defi-exploit

Polymarket Users Lose $3.1M in Phishing Attack, Platform Pledges Refunds

Polymarket, a leading prediction market platform, suffered a phishing attack that resulted in the theft of approximately $3.1 million worth of its native token, PUSD, from 11 user wallets. The attack, first reported by blockchain intelligence firm AMLBot, involved the funds being stolen from Polygon and immediately bridged to Ethereum. Polymarket stated that a compromised third-party vendor had injected a malicious script into its frontend, which has since been removed. The platform has pledged full refunds to affected users. This incident follows a series of recent security issues at Polymarket, including a suspected breach in March 2025 where over $520,000 was drained from smart contracts, and a Discord security incident in December 2024. Additionally, the platform is reportedly under federal investigation for allegedly deceptive social media promotions, as highlighted by a Wall Street Journal article. The phishing attack underscores ongoing security challenges in the crypto space, particularly for platforms handling user funds.

Key facts

  • Hackers stole $3.1M in PUSD tokens from 11 Polymarket users.
  • Attack involved a compromised third-party vendor injecting malicious script.
  • Polymarket removed the dependency and pledged full refunds to victims.
  • Platform faces separate federal investigation over deceptive promotions.
  • Polymarket suffered previous security incidents in March and December 2024.

KeyAudit data perspective

📊 KeyAudit data: Ethereum historical leak records: 1869493

← Back to list