Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Polymarket updates hack loss to $3.1M, pledges full refunds to affected users

Polymarket updates hack loss to $3.1M, pledges full refunds to affected users

CryptobriefingCryptobriefing2026/06/27 17:39
By:Cryptobriefing

Polymarket, the decentralized prediction market that became a household name during the 2024 US election cycle, confirmed that a security breach on June 25 drained approximately $3.1 million in user funds. The platform has committed to making every affected user whole through full refunds.

The attack targeted Polymarket’s frontend through a compromised third-party vendor, meaning the platform’s core smart contracts were never actually breached. Between 11 and 15 wallets were impacted, with the stolen funds consisting primarily of pUSD, Polymarket’s USDC-backed stablecoin.

A supply-chain problem, not a protocol problem

Polymarket moved quickly to remove the affected dependency from its system and began contacting impacted users. On-chain analysts from PeckShield, SpecterAnalyst, and GoPlus Security tracked the stolen pUSD as it was swapped for ETH and consolidated into fewer wallets.

Advertisement
window.sevioads = window.sevioads || []; var sevioads_preferences = []; sevioads_preferences[0] = {}; sevioads_preferences[0].zone = "de1434f5-fa9e-44a6-93c3-4c2439763717"; sevioads_preferences[0].adType = "banner"; sevioads_preferences[0].inventoryId = "c5700508-581b-472c-8fdd-a931cdbfc8e1"; sevioads_preferences[0].accountId = "1e47efc1-ec2d-4fca-a8b9-354e249e5095"; sevioads.push(sevioads_preferences);

The company has emphasized that its underlying protocols remain secure.

Second breach in a month

This isn’t Polymarket’s first security incident this year. On May 22, a separate breach drained between $520,000 and $700,000 from an internal wallet on the Polygon network. That earlier attack was attributed to a suspected private key compromise, and Polymarket said at the time that user funds were not affected.

Two incidents in roughly five weeks paints a pattern that’s hard to ignore. The May breach hit internal funds. The June breach hit user funds. Different attack vectors, different targets, but the same platform finding itself on the wrong end of security failures at an uncomfortable frequency.

What this means for prediction market users and crypto investors

Supply-chain attacks are notoriously difficult to prevent because they exploit trust relationships with external vendors rather than flaws in a platform’s own code. Smart contract audits have become table stakes in the industry, with projects routinely commissioning multiple audit firms before launch. But frontend dependencies often receive far less scrutiny, despite being the layer that users actually interact with.

Regulatory implications also loom. Polymarket has already navigated complex regulatory waters, including a previous settlement with the CFTC. Repeated security breaches that result in user fund losses tend to attract the kind of regulatory attention that no crypto platform wants, particularly when the platform operates in a space that regulators are already watching closely.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!