Polymarket disclosed Thursday that attackers had stolen funds from fewer than 15 users by compromising a third-party vendor and injecting malicious code into the platform's front-end. Blockchain intelligence firm Bubblemaps estimates the haul at approximately $3 million. The company said it identified and removed the malicious code, patched the vulnerability, and committed to full reimbursement.

The attack targeted users who interacted with the compromised interface. According to security platform PeckShield, attackers drained pUSD balances directly. pUSD is Polymarket's proprietary dollar-pegged stablecoin, backed by USDC, which the platform rolled out in April as part of a broader exchange redesign.

Blockchain data shows the stolen funds were converted to ETH and held across several Ethereum wallets. Those wallets have since begun moving the assets, complicating recovery efforts.

Perimeter, not protocol

The breach is a front-end compromise, not a flaw in Polymarket's underlying smart contracts. That distinction matters. A user facing a malicious interface has no way to verify what transaction they're actually signing. The attacker controls what appears on screen. In this case, users likely approved token transfers thinking they were performing legitimate actions. Once signed, the blockchain executes exactly what was requested, regardless of the user's intent.

This is a perimeter risk. The core protocol was never touched. But perimeter risks hit users directly and fast. Front-ends are software, maintained by third parties, and vulnerable to supply chain attacks. Polymarket's reliance on a vendor whose security posture it cannot fully control created the opening.

Pattern emerging

This is the second major incident at Polymarket in roughly two months. In May, a private key compromise drained $700,000 from an internal wallet used for reward distributions. Back-to-back breaches suggest recurring vulnerabilities in how the platform manages access and trust boundaries.

The May incident involved internal infrastructure. This one involved the user-facing layer. Together, they map a perimeter under stress. Polymarket has not disclosed whether the two incidents share a root cause or represent separate failures.

The commitment to reimburse affected users addresses the immediate harm but does not address the structural question: how many perimeter risks remain, and how will they be monitored? Full reimbursement is practical for a $3 million loss at this scale. It becomes harder to sustain if the pattern continues.