Polymarket confirmed Friday that a compromised vendor let attackers inject malicious code into the frontend, draining about $3 million from fewer than 15 accounts. π¦ They promise full refunds for every user hit. πΉ
The Incident Details π
Specter first spotted the breach and posted about the phishing campaign hitting over 11 wallets holding PUSD. At that point losses sat near $2.94 million. PeckShield quickly verified the amount and noted the stolen funds moved from Polygon to Ethereum turning into 1,893 ETH. Polymarket Traders acknowledged the hit via X.
βThis morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. Weβve contained it and removed the affected dependency. Weβre contacting impacted users and refunding them in full.β
William LeGate confirmed the refunds after the fix. GoPlus Security called it a supply chain attack affecting around 15 accounts for $3 million total, matching Bubblemaps findings after they tracked everything.
Patterns From Before π€
This marks the second strike on Polymarket inside a month. Last time an admin wallet lost roughly $700,000 likely via exposed private keys. ZachXBT first guessed $520,000 before Bubblemaps traced higher amounts across addresses. Josh Stevens later confirmed a 6-year-old key leaked from internal config, prompting a full rotation to better key management tools. Neither event touched core contracts or user funds directly. The latest front-end breach arrives while the platform already faces other scrutiny including a Wall Street Journal report on paid staged bet videos and a trader dispute over a $500,000 market resolution shift.
Just another echo from the void by iconofsin.eth π