A third-party vendor supplying code to Polymarket's frontend was breached on Thursday morning, allowing attackers to inject a malicious script that siphoned roughly $3 million in crypto from users. The Polymarket Traders X account disclosed that the compromise was identified and the "affected dependency" was removed. Polymarket says it will fully reimburse affected users, though no timeline or refund mechanism has been detailed.
Security analyst Specter tracked the flow: thieves drained 11 wallets holding PUSD, Polymarket's native stablecoin, then swapped the stolen assets for Ethereum and funneled them to a single address (0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD). Each victim lost approximately $273,000 on average. The attacker's next move remains unclear.
Polymarket's statement framed this as a vendor compromise rather than a vulnerability in its own infrastructure. That distinction matters operationally: third-party dependencies are notoriously hard to audit at scale. A single compromised library or API can slip malicious code past conventional defenses. In this case, the attacker gained enough access to modify the frontend users interact with, the most sensitive vector for phishing or asset redirection.
The timing compounds an existing credibility problem. Just last month, Polymarket lost $700,000 after a private key was compromised. The company blamed an old, forgotten credential rather than a contract exploit. Two separate breaches in two months, even if unrelated in root cause, signal a platform wrestling with operational security at an unusually high frequency. Users of prediction markets rely on tight control of access and clean code paths; each incident erodes that confidence.
Front-end manipulation sits lower in the security hierarchy than smart contract bugs but directly empties wallets. A user sees their normal Polymarket interface, clicks what looks like a legitimate withdrawal or trade, and their assets vanish. Recovering stolen assets is harder than patching code. Refunds depend on Polymarket's insurance, reserves, or willingness to absorb the loss—none of which has been specified in public statements.