Polymarket to Reimburse Users After $3M Frontend Hack Linked to Supply Chain Attack

Polymarket has confirmed it will fully reimburse users after attackers exploited a compromised third party vendor to inject malicious code into its frontend, resulting in approximately $3 million in losses.

Security researchers say the incident was not caused by a vulnerability in Polymarket’s core smart contracts, but instead classified it as a supply chain attack affecting the platform’s user interface layer.

Incident Details

The attack was first identified by on chain investigator Specter, who reported that a phishing style campaign had drained funds from more than 11 wallets holding Polymarket’s PUSD stablecoin. Initial estimates placed losses at around $2.94 million.

Security firm PeckShield later confirmed the figure and noted that the attacker bridged stolen assets from Polygon to Ethereum, where they were converted into approximately 1,893 ETH.

Polymarket acknowledged the breach through its official communications, stating that a third party vendor had been compromised and that malicious scripts were injected into the frontend affecting a limited number of users.

The platform said it quickly contained the issue, removed the affected dependency, and began contacting impacted users while committing to full reimbursement.

A representative closely associated with the project also confirmed that all affected users would be made whole.

Additional blockchain security analysts, including GoPlus Security, described the incident as a supply chain compromise impacting around 15 accounts in total. Other firms such as Bubblemaps also verified the scope of losses and praised the platform’s response once the attack was contained.

Repeat Security Concerns

This is not the first security incident involving Polymarket.

In a previous breach last month, an administrative wallet used for internal reward distributions was drained of roughly $700,000, likely due to a compromised private key. Initial estimates by investigator ZachXBT placed losses at about $520,000, though later tracking by Bubblemaps revised the total higher after following fund movements across multiple addresses.

At the time, developer Josh Stevens confirmed that an old private key had been exposed through an internal configuration issue. The company subsequently rotated credentials and migrated to more secure key management systems. That incident did not affect user funds or core smart contracts.

Although both incidents involved different attack vectors, they each targeted infrastructure outside the core prediction market system.

Reputational Challenges

The latest breach comes as Polymarket faces additional scrutiny. A recent report from the Wall Street Journal alleged the platform paid college age content creators between $2,000 and $3,000 per month to post staged betting videos on dummy versions of its site, with claims that none of the over 1,100 clips were linked to real blockchain activity.

Separately, earlier this month a trader claimed to have lost $500,000 after a dispute over rule changes in a market related to Strategy and its Bitcoin sales, adding further controversy around the platform’s operations.#crypto#cryptonews https://coinsignals.net https://t.me/coinsignalpublic