Share
Subscribe to the AlphaWire Newsletter
A supply-chain attack hit Polymarket on June 25, 2026, draining close to $3 million from user wallets after attackers compromised a third-party vendor and injected malicious code into the platform’s frontend. The script targeted PUSD, Polymarket’s native collateral token on Polygon. At least 11 wallets lost funds before the platform contained the breach.
Onchain investigator Specter was the first to flag the activity publicly, identifying losses of $2.94 million across more than 11 victim wallets and naming the primary consolidation address as “0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD.” Polymarket confirmed the breach approximately 15 minutes after Specter’s report.
Polymarket Under Attack
Polymarket users were drained of ~$3.1M in PUSD on Polygon via phishing / malicious EIP-7702 delegated execution.
Funds were converted to USDC.e via Relay, bridged to Ethereum, swapped to ETH, and consolidated at… pic.twitter.com/bG3GYZZ1D9
— AMLBot (@AMLBotHQ) June 27, 2026
Blockchain intelligence company AMLBot updated the total to $3.1 million on June 27, 2026. The stolen assets were bridged from Polygon to Ethereum and converted into approximately 1,893 Ether (ETH). At the time of publication, the funds remain in the identified attacker wallets.
The attack was a supply-chain compromise, not a protocol exploit. The smart contracts were never touched — the site was. When affected users connected their wallets, the injected script prompted them to sign or approve transactions without raising obvious suspicion, handing over control of their PUSD holdings to the attacker.
Despite the volume of stolen PUSD, the token held its peg throughout, trading at $0.9998 on Polygon after the incident. The theft hit individual wallets rather than the underlying token backing.
This is Polymarket’s second security breach in the past two months. In May, the platform reported a $700,000 internal operations wallet hack caused by a six-year-old private key compromise. That incident did not affect user funds but exposed internal infrastructure vulnerabilities.
Create a free account to get full access to all our content.
This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. We've contained it & removed the affected dependency. We're contacting impacted users & refunding them in full.
— Polymarket Traders (@PolymarketTrade) June 25, 2026
In March, blockchain investigator ZachXBT highlighted a suspected security breach in which over $520,000 was reportedly drained from two smart contracts on Polygon.
Polymarket said at the time that funds were safe. In December 2025, the platform confirmed a security incident on its Discord channel after users reported missing funds and suspicious login attempts, blaming an unidentified third-party login provider.
The pattern is consistent across all three incidents. What is being breached is not the blockchain code itself but operational security: poorly managed private keys and unaudited external dependencies. The web layer remains a massive attack surface even inside Web3.
Polymarket has not disclosed the identity of the compromised vendor in the June 25 attack, how long the malicious code was active, or the exact number of users affected.
The hack caps what has been a catastrophic seven-day period for the platform. On Sunday, June 22, a Wall Street Journal investigation revealed that the company had paid online creators to post deceptive videos showing fabricated bets and fake winnings across more than 1,100 videos, prompting Polymarket to say it would audit its promotional content.
The news of the phishing attack follows reports that Polymarket is under federal investigation following the WSJ article into deceptive social media promotion. Spain blocked the platform in May over missing gambling licenses, joining France, Belgium, Poland, Italy, and India in restricting access.
The June 25 attack was the 89th security incident recorded in the second quarter of 2026, the highest quarterly count ever reported. Losses from exploits in June reached $74.9 million, up from $60.5 million in May, per DefiLlama data.
Polymarket remains the largest prediction market platform with total value locked exceeding $450 million, up 301% from $112 million a year ago. Full refunds to affected users are confirmed. The underlying platform continues to operate.
The World Cup is generating record volume. None of that changes the central question the incident forces: whether operational security at Polymarket is scaling at the same pace as its commercial ambitions, its regulatory exposure, and the value it is now responsible for protecting.
Two security incidents within two months, both originating from third-party infrastructure rather than core code and both requiring Polymarket to fund the losses from its own balance sheet, are a pattern that the company’s regulators, its institutional partners, and its users are all watching closely.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share