
A malicious script was injected into Polymarket's frontend by a third-party vendor, leading to the theft of over $2.9 million from users' wallets. The platform has assured full refunds and contained t
Polymarket recently fell victim to a significant security incident where attackers exploited a malicious script injected into its frontend through a compromised third-party vendor, resulting in an estimated loss of $2.94 million across multiple user accounts. Blockchain analyst Specter highlighted that this attack appeared to facilitate a phishing scheme.
The platform quickly responded by containing the compromise and removing the affected dependency. Polymarket also announced plans to fully refund all users impacted by the theft. While the company did not provide further details, it emphasized the safety of its contracts and user funds, stating that permissions tied to compromised keys had been revoked following a previous $600,000 exploit.
This breach marks the 89th reported crypto security incident in the second quarter, according to DefiLlama data. June saw a total loss of $74.9 million across 29 incidents, surpassing May’s $60.5 million but falling short of April's record-breaking $644 million.
Of note, private key compromises were identified as the leading attack vector over the past month, accounting for 43% of reported exploit losses. Fake proof exploits and reverse MEV honeypots followed closely behind at 10% each. Polymarket currently holds over $450 million in total value locked (TVL), a significant increase from its $112 million TVL one year ago.
The incident underscores the ongoing challenges faced by decentralized finance platforms and prediction marketplaces, where security remains paramount despite increasing popularity among first-time crypto users. As Polymarket works to restore user trust, traders should remain vigilant about potential vulnerabilities in third-party integrations and continuously monitor for updates from the platform.
For context, this attack is part of a broader trend in the cryptocurrency space, with DefiLlama tracking over 89 reported incidents during Q2. Notable recent exploits include $36 million from Humanity Protocol and $4.7 million from Secret Network bridge attacks.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.