Polymarket states that as a result of the invasion of a third-party supplier, the front end of the platform website was implanted with a malicious code, resulting in the theft of funds from a small number of users. The company stated that the relevant issues had been addressed and that the affected users would be paid in full.

About $3 million stolen.

According to a note released by Polymarket on platform X, the attackers used front-end page loopholes to steal. According to Bubblemaps, the chain-based analyst, the loss was approximately $3 million, with less than 15 accounts affected.

The attackers seem to have mainly moved pUSD from the user's wallet. This is the United States dollar stabilization currency used on the Polymark platform, supported by USDC, which is used mainly for the settlement of on-site transactions. The stolen funds were subsequently converted into ETH and assembled at an Etheraf address.

  • Estimated losses of approximately $3 million
  • Less than 15 affected accounts
  • Stolen assets mainly pUSD were replaced by ETH

The company says the front end is cleared.

Polymarket states that the front-end loophole has been controlled and removed and that the Platform is advancing the compensation process. The company did not publicly state which supplier was the subject of the invasion, nor did it further respond to the relevant details.

The attack did not directly target the core agreement, but entered the front end of the site through external service links. The incident showed that even if the core system itself had not been breached, the outer supply chain could still be an entry point.

Second security incident in two months.

It's the second time in almost two months that Polymark has a security problem. Last month, a wallet on the platform, which was used to award and supplement user incentives to employees, was also attacked, resulting in a loss of approximately $700,000 for the company.

At that time, there was general agreement that the previous incident was more likely to be related to private key leaks and did not affect the platform ' s infrastructure. By contrast, the event had a direct impact on the user-end page and some user funds, and had once again exposed the risks associated with third-party dependence on services.