Polymarket Hackers Drain $3.1M in PUSD and Park 1,891 ETH Across 3 Wallets

 

By Onkar Singh // June 29, 2026 @ 09:28 AM Make AlphaWire Logo preferred on Google News
Polymarket Hackers Drain $3.1M in PUSD and Park 1,891 ETH Across Three Wallets

Share

Points of Focus

  • Hackers stole $3.1 million after malicious code hit Polymarket’s frontend; refunds are promised.
  • Funds were swapped into 1,893 ETH and remain in attacker-controlled wallets.
  • It’s Polymarket’s third security incident in seven months.

 

A supply-chain attack hit Polymarket on June 25, 2026, draining close to $3 million from user wallets after attackers compromised a third-party vendor and injected malicious code into the platform’s frontend. The script targeted PUSD, Polymarket’s native collateral token on Polygon. At least 11 wallets lost funds before the platform contained the breach.

Onchain investigator Specter was the first to flag the activity publicly, identifying losses of $2.94 million across more than 11 victim wallets and naming the primary consolidation address as “0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD.” Polymarket confirmed the breach approximately 15 minutes after Specter’s report.

 

 

Blockchain intelligence company AMLBot updated the total to $3.1 million on June 27, 2026. The stolen assets were bridged from Polygon to Ethereum and converted into approximately 1,893 Ether (ETH). At the time of publication, the funds remain in the identified attacker wallets.

The attack was a supply-chain compromise, not a protocol exploit. The smart contracts were never touched — the site was. When affected users connected their wallets, the injected script prompted them to sign or approve transactions without raising obvious suspicion, handing over control of their PUSD holdings to the attacker.

Despite the volume of stolen PUSD, the token held its peg throughout, trading at $0.9998 on Polygon after the incident. The theft hit individual wallets rather than the underlying token backing.

 

Three incidents in seven months

This is Polymarket’s second security breach in the past two months. In May, the platform reported a $700,000 internal operations wallet hack caused by a six-year-old private key compromise. That incident did not affect user funds but exposed internal infrastructure vulnerabilities.

 

Register and unlock all content immediately

Create a free account to get full access to all our content.

 

In March, blockchain investigator ZachXBT highlighted a suspected security breach in which over $520,000 was reportedly drained from two smart contracts on Polygon.

Polymarket said at the time that funds were safe. In December 2025, the platform confirmed a security incident on its Discord channel after users reported missing funds and suspicious login attempts, blaming an unidentified third-party login provider.

The pattern is consistent across all three incidents. What is being breached is not the blockchain code itself but operational security: poorly managed private keys and unaudited external dependencies. The web layer remains a massive attack surface even inside Web3.

Polymarket has not disclosed the identity of the compromised vendor in the June 25 attack, how long the malicious code was active, or the exact number of users affected.

 

The worst week in Polymarket’s history

The hack caps what has been a catastrophic seven-day period for the platform. On Sunday, June 22, a Wall Street Journal investigation revealed that the company had paid online creators to post deceptive videos showing fabricated bets and fake winnings across more than 1,100 videos, prompting Polymarket to say it would audit its promotional content.

The news of the phishing attack follows reports that Polymarket is under federal investigation following the WSJ article into deceptive social media promotion. Spain blocked the platform in May over missing gambling licenses, joining France, Belgium, Poland, Italy, and India in restricting access.

The June 25 attack was the 89th security incident recorded in the second quarter of 2026, the highest quarterly count ever reported. Losses from exploits in June reached $74.9 million, up from $60.5 million in May, per DefiLlama data.

 

Polymarket’s position and what comes next

Polymarket remains the largest prediction market platform with total value locked exceeding $450 million, up 301% from $112 million a year ago. Full refunds to affected users are confirmed. The underlying platform continues to operate.

The World Cup is generating record volume. None of that changes the central question the incident forces: whether operational security at Polymarket is scaling at the same pace as its commercial ambitions, its regulatory exposure, and the value it is now responsible for protecting.

Two security incidents within two months, both originating from third-party infrastructure rather than core code and both requiring Polymarket to fund the losses from its own balance sheet, are a pattern that the company’s regulators, its institutional partners, and its users are all watching closely.

Share

Default avatar

Onkar Singh

Onkar is a seasoned digital finance (DeFi) content creator with half a decade of experience in the blockchain and cryptocurrency industry. He has contributed to leading crypto media platforms, and collaborated with numerous DeFi projects worldwide. He blends his passion for technology and storytelling to deliver insightful content that bridges the gap between complex blockchain concepts and mainstream understanding.

Table of content

Ad

Related Articles