Prediction market platform Polymarket has confirmed that hackers stole funds from several users after exploiting a vulnerability in its web interface. Attackers injected malicious code into the frontend, allowing them to siphon cryptocurrency directly from affected accounts.
In a statement on X, Polymarket said: “We’ve contained it & removed the affected dependency. We’re contacting impacted users & refunding them in full.” The company emphasised that all affected users will be reimbursed. Spokesperson Connor Brand acknowledged the theft but declined to provide further details about the breach or the ongoing investigation.
Scale of the attack
Hackers carried out a supply-chain attack on the frontend, compromising a third-party vendor that provided code to Polymarket’s website. The vendor’s script was replaced with a wallet-draining payload, which executed in users’ browsers.
This manipulation tricked users into approving fraudulent transactions, draining about $3 million in cryptocurrency from 11 wallets, according to blockchain monitoring firm PeckShield. While Polymarket’s smart contracts remained secure, the browser layer was compromised, highlighting a blind spot that traditional smart-contract audits cannot detect.
According to security experts, the incident is comparable to digital skimming campaigns that have stolen billions from e-commerce sites through compromised scripts.
The latest hacking incident is relatively small when compared to other historic crypto breaches. Yet it also highlights a recurring pattern: attackers exploit weaknesses outside smart contracts, much as they did in past supply-chain and frontend compromises. In 2025, Bybit lost $1.5 billion, while Ronin’s $620 million validator compromise in 2022 shows how scale and sophistication have escalated.
Security risks exposed
One victim suggested the breach may have stemmed from a virtual private server (VPS). The user, who stored a private key on a VPS purchased from Xorek Cloud, said: “I recently bought a VPS from Xorek Cloud and stored my private key on it. I’m not sure how the compromise happened, but that’s the only possible security risk I can think of.”
The latest mishap highlights the dangers of storing private keys with external services. It also emphasises the broader vulnerability of crypto platforms to targeted attacks. Experts advise that the most effective security practices this year include hardware wallets, strong authentication, careful key management, and minimising exposure to online threats. These measures can prevent more than 99 per cent of common attack vectors.
But users sometimes unknowingly approve malicious transfers. Once completed, their funds are drained instantly. Unlike banks, crypto transactions cannot be reversed. Stolen stablecoins (PUSD) were quickly swapped for ETH and bridged across chains, making recovery nearly impossible.
Meanwhile, vendor dependency audits are critical-fronted scripts, and cloud services are now prime targets. Additionally, user vigilance matters: approving transactions blindly in browser interfaces is a recurring exploit vector.
Trust and regulation
For prediction market participants, losing funds mid-bet undermines confidence in Polymarket’s reliability. Moreover, the hack also comes amid shifting crypto regulation in 2026. In the U.S., the pending Crypto Clarity Act would give the CFTC exclusive jurisdiction over digital commodity spot markets.
Meanwhile, the EU’s MiCA regime is fully enforced, requiring all crypto service providers to be licenced. Globally, FATF and OECD standards are driving stricter compliance, particularly around anti-money laundering and tax reporting.
Stay ahead of iGaming’s biggest stories with SiGMA’s Top 10 News countdown. The world’s biggest iGaming community brings you weekly insights and subscriber-only offers. Join HERE today.





