Hackers have stolen about $3 million from Polymarket through a compromised vendor that injected malicious code into the platform’s frontend. Polymarket confirmed on Thursday that hackers stole funds from users after a third-party vendor was compromised, allowing malicious code to be injected into the prediction market’s website. Blockchain monitoring firm PeckShield estimated the losses at about $3 million in cryptocurrency, drained from more than 11 victims.
See also: Hackers target Windows users via WhatsApp

The company said in a post that it has "contained" the incident and removed the affected dependency.
Polymarket said it is contacting victims and “is providing them with a full refund,” though it did not specify how many users were affected or who the compromised vendor was. Polymarket spokesperson Connor Brandiconfirmed to TechCrunch that the breach resulted in the theft of funds, but declined to provide further details. The company did not respond to specific questions about the incident.
On-chain data examined by blockchain analyst Spectre showed that funds were drained from victims’ wallets containing PUSD, Polymarket’s stablecoin. The stolen assets were quickly transferred from Polygon to Ethereum and converted into approximately 1,893 ETH, a common tactic used by attackers to cover their tracks and liquidate funds quickly.
The attack was a supply chain breach rather than a direct breach of Polymarket's own infrastructure. A third-party vendor's code was tampered with and the malicious script was served to some users via Polymarket's frontend.
See also: F5 – Data Breach: Hackers stole BIG-IP source code

Users who interacted with the affected interface saw their funds drained without exploiting the platform’s core smart contracts. This is not the first time Polymarket’s security has been tested this year. In May, blockchain researcher ZachXBT highlighted a separate incident in which approximately $520,000 was drained from two smart contracts on the Polygon network.
Polymarket said at the time that the losses stemmed from a compromised six-year-old private key linked to an internal operations wallet, not an exploit of the platform. The scandals come at a time of intensifying regulatory and legal pressure. A Google engineer was charged last month with insider trading after using internal search data to make more than $1 million at Polymarket.
Spain blocked the platform in May due to a lack of gambling licenses, joining France, Belgium, Poland, Italy and India in restricting access.
Polymarket has also faced structural questions about its governance. A $345 million dispute over an Iran peace deal earlier this month revealed how just nine anonymous cryptocurrency wallets control more than half of the votes used to resolve disputed outcomes on the platform. The company, founded by Shayne Coplan, became the dominant prediction market during the 2024 US presidential election and continues to grow rapidly.
See also: WordPress: Hackers exploit Burst Statistics vulnerability

The combined monthly transaction volume between Polymarket and competitor Kalshi quadrupled from under $5 billion to $24 billion between September 2025 and April 2026. Whether that growth trajectory will survive a convergence of security failures, marketing fraud, and regulatory crackdowns is the question the company now faces.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
