Polymarket says hackers compromised a third-party vendor and used it to inject malicious code into the prediction market’s website, leading to theft from some users. The company said it removed the affected dependency and will refund impacted users. Blockchain tracking cited in the report says about $3 million in pUSD was stolen from at least 11 victims, then bridged from Polygon to Ethereum and swapped into about 1,893 ETH.
Why it matters: Users who connected wallets to Polymarket may have been exposed to a website-based theft campaign even if Polymarket itself was not directly breached. Affected users should watch for official notification, review wallet activity, and be cautious of follow-up phishing or refund scams tied to the incident.
Bill Toulas
2026.06.26
98% relevant
This article reports the same Polymarket incident and adds details that the malicious JavaScript was injected into the frontend through a vendor dependency, that fewer than 15 accounts were affected, and that the stolen funds were bridged from Polygon to Ethereum and swapped into about 1,893 ETH.
Eduard Kovacs
2026.06.26
100% relevant
This article appears to be the first tracked item here establishing the Polymarket incident as a distinct third-party compromise and crypto theft event.
← Back to all stories