Polymarket said attackers stole funds from an undisclosed number of users after compromising a third-party vendor and injecting malicious code into the company's website. The platform said the incident has been contained, affected customers are being notified, and victims will be fully reimbursed. A company spokesperson confirmed the theft but did not disclose how many users were impacted.
Independent blockchain researchers described the activity as a phishing-style campaign that drained more than 11 Polymarket wallets holding PUSD, with estimated losses of about $2.94 million to $3 million. Researchers also reported that the attacker moved the stolen assets from Polygon to Ethereum and converted them into roughly 1,893 ETH, indicating a rapid effort to launder the proceeds after the website compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Blockchain security researcher Specter identified a phishing campaign targeting Polymarket users that drained more than 11 wallets holding PUSD. Reported losses were estimated at about $2.94 million, and the attacker allegedly bridged the assets from Polygon to Ethereum and converted them into 1,893 ETH.
Polymarket said attackers compromised a third-party vendor and used that access to inject malicious code into the Polymarket website for some users, resulting in stolen user funds. The company said it had contained the incident, was notifying affected customers, and would fully reimburse victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethedefiant.io
Open sourcethedefiant.io
Open sourcesecurityweek.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.