Polymarket hit by $2.9M theft, users to be refunded

Polymarket said it contained the compromise and removed the affected dependency after attackers injected a malicious script into its frontend.

Polymarket hit by $2.9M theft, users to be refunded

Polymarket, the popular decentralized prediction market platform, suffered a security breach that resulted in the theft of approximately $2.9 million in user funds. Attackers compromised a third-party vendor and injected a malicious script into the platform's frontend, enabling them to drain funds from connected wallets. Polymarket confirmed it has since contained the compromise and removed the affected dependency from its codebase.

Polymarket has grown into one of the most widely used prediction market platforms in the crypto space, gaining mainstream attention during major political and global events. The platform operates on the Polygon blockchain and allows users to place wagers on real-world outcomes. As with many Web3 applications, its reliance on third-party frontend dependencies created an attack surface that bad actors were able to exploit in what is known as a supply chain attack.

The incident highlights an ongoing and underappreciated vulnerability across the decentralized finance ecosystem — the use of centralized or third-party infrastructure components within otherwise decentralized platforms. Even protocols built on secure blockchain foundations remain susceptible to traditional web-based attack vectors, raising questions about the security standards applied to frontend development and vendor management within the industry.

Polymarket has stated that affected users will be refunded, though details on the timeline and reimbursement process have not yet been fully disclosed. Security researchers and the broader DeFi community will likely be watching closely to understand the full scope of the vendor compromise and how platforms respond to similar supply chain risks going forward.

Source: Cointelegraph

Read original article ↗