HackMyIP
← Back to News
2026-06-26 BleepingComputer

Polymarket Hit by $3M Frontend Supply-Chain Attack

Supply ChainPhishingIncident Response

Polymarket, one of the world's largest crypto-based prediction markets and currently valued at $9 billion, has announced it will fully reimburse customers who lost an estimated $3 million in a frontend supply-chain attack. Hackers injected malicious JavaScript into the platform's website through a compromised third-party vendor, tricking unsuspecting users into approving fraudulent transactions on the official domain. While Polymarket's backend servers and core infrastructure remained uncompromised, the tainted script was served directly from the legitimate Polymarket URL — making the attack particularly dangerous for users who verified the address before signing transactions.

According to blockchain intelligence firm PeckShield, the attackers stole approximately $3 million worth of ParyonUSD from fewer than 15 user wallets. The stolen funds were bridged from Polygon to Ethereum and swapped into roughly 1,893 ETH. On-chain analytics platform Bubblemaps corroborated the scope of the incident and published a list of affected accounts alongside the attacker-controlled wallets. The exact injection vector — whether through a compromised CDN, a hijacked analytics tag, or a tampered JavaScript dependency — has not been publicly disclosed, though Polymarket confirmed the breach originated with a frontend vendor rather than its own codebase.

The incident underscores how third-party JavaScript dependencies remain a critical weak link for web3 platforms handling billions in trading volume. Organizations can audit their own perimeter exposure by running an SSL/TLS checker to verify certificate integrity and chain of trust. Users who interacted with Polymarket during the attack window should review and revoke outstanding token approvals, rotate any reused credentials via a password checker, and perform a broader privacy checkup across connected wallets and browser sessions. Polymarket's reimbursement commitment is a welcome step, but the broader lesson for both operators and traders is unchanged: trust in the URL does not equate to trust in the code the browser actually executes.

Source: BleepingComputer →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →