Data Breaches

Polymarket Hack Losses

June 28, 2026 16:08 · 10 min read
Polymarket Hack Losses

Decentralized prediction market Polymarket has promised to fully refund users affected by a hacker attack that came to light this week. Polymarket is a cryptocurrency-based prediction market platform that enables users to trade on the likely outcomes of real-world events ranging from elections and economic indicators to sports and cultural happenings.

Incident Details

The company has shared little information about the incident. “This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. We’ve contained it & removed the affected dependency,” Polymarket said in a Thursday post on X.

It noted that impacted users will be contacted and fully refunded, but it did not clarify how many users were affected and how much cryptocurrency was stolen. Blockchain security company PeckShield reported that roughly $3 million worth of pUSD, Polymarket’s USDC-backed trading currency, was stolen via a phishing campaign.

Stolen Funds

“The attacker bridged the stolen funds from Polygon to Ethereum and swapped them into ~1,893 ETH,” PeckShield said. A blockchain analyst confirmed that the losses total nearly $3 million, with funds stolen from at least 11 victims.

It’s unclear who is behind the attack. SecurityWeek has reached out to Polymarket for confirmation of the amount stolen and the number of impacted users. This article will be updated if the company responds.

UPDATE: Polymarket told SecurityWeek it has no further comment beyond its post on X at this time.

Related Incidents

Related incidents include the $290 Million Kelp DAO Crypto Heist Blamed on North Korea, CryptoBandits Malware Doubles as a Backdoor, Abuses Tor, and Dozens of Malicious Crypto Apps Land in Apple App Store.

International Operation Targets Multimillion-Dollar Crypto Theft Schemes, and Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack are also notable incidents in the cryptocurrency space.

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning, Cisco SD-WAN Zero-Day Exploited Months Before Patching, and Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware are recent examples of cybersecurity threats.

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents, Third DraftKings Hacker Sentenced to 18 Months in Prison, and Hackers Exploiting Cisco Unified CM Vulnerability are also relevant to the current state of cybersecurity.

Dragos Unveils AI for OT Security, Chinese Framework Powers 200,000 Scam Sites, Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories, and More Klue Breach Victims Identified as Hackers Get Hacked are additional examples of cybersecurity incidents and developments.

Nebulock Raises $25 Million for AI-Native Contextual Security, Linux Foundation Unveils New Open Source Security Project Akrites, Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets, and First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild are recent cybersecurity news.

Trending topics include the Daily Briefing Newsletter, Webinar: Why Email Security Keeps Failing, and Virtual Event: 2026 Cloud Security Summit.

People on the Move include Mark Carter, Chief Information Security Officer at Socure, Mark Cravotta, Chief Operating Officer at Spektrum Labs, and Philip Martin, Chief Information Security Officer at Uber.

Expert Insights include When Information Becomes the Attack Surface – Understanding AI Agent Traps, and the work of Etay Maor.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free