
Prediction market platform Polymarket announced on June 25 that it has contained a third-party frontend compromise that exposed users to a phishing attack. According to the company's statement, it discovered the compromised vendor earlier in the day, removed the affected dependency, and contained the incident. The platform emphasized that it is contacting impacted users and will refund them in full, with no timeline provided for the reimbursement process. Polymarket has since confirmed that attackers compromised a third-party vendor and used the access to inject malicious code into the platform's frontend, leading to the phishing attack. The company has not responded to requests for comment as of US morning hours on Saturday.
Blockchain intelligence firm AMLBot has updated the financial impact of the attack, reporting that hackers stole approximately $3.1 million in Polymarket's PUSD token from 11 user wallets. According to their latest findings, the assets were stolen from Polygon and immediately bridged to Ethereum, with the attacker subsequently exchanging the proceeds for roughly 1,893 ETH. PeckShield had initially reported the attack as a phishing campaign targeting Polymarket users, with the attacker draining approximately $2.94 million worth of PUSD from more than 11 victim wallets before bridging the stolen funds from Polygon to Ethereum. Specter Analyst had also estimated the attack drained funds from at least 11 wallets after the malicious script appeared on the platform's frontend.
According to Polymarket, the attack originated from a compromised third-party vendor that injected a malicious script into parts of the platform's frontend. The company said it has since removed the affected dependency and contained the incident, though it has not disclosed the identity of the compromised vendor or released a detailed technical postmortem. The incident appears to have affected only users who interacted with the compromised frontend during the attack window rather than the platform's underlying smart contracts. Specter Analyst identified the attack as a phishing campaign rather than a protocol exploit, with the injected script enabling attackers to steal funds from connected wallets after users interacted with the compromised interface. One victim, identified as 'Ash', shared that his wallet had been hacked and had no idea why at the time, also sharing his and the attacker's wallet addresses.
The hack arrives as Polymarket faces intensified regulatory attention from multiple fronts. A recent report indicates that U.S. Senators Adam Schiff and John Curtis have urged the CFTC to review allegations tied to deceptive advertising practices. Polymarket and Kalshi are also part of a wider legal fight over sports event contracts, with Kentucky accusing prediction market firms of offering unlicensed sports betting, while the CFTC has argued that federally regulated event contracts fall under its authority. The cases may help decide whether sports-linked prediction markets answer mainly to federal derivatives rules or state gambling laws. The growing incident count shows why platforms now face closer checks across smart contracts, wallets, login systems, frontend code and outside vendors.